# Keeping source code inside your cloud account

> Canonical: https://stratamend.com/keeping-source-code-inside-your-cloud-account/
> Last updated: 2026-10-08

Published 10 September 2026 by Stratamend.

The first question security teams ask us is where their source code goes. For a bank or an insurer, the codebase of a core system is a sensitive asset, and the answer “to a third-party SaaS” ends many conversations before they start. That is why we are designing Stratamend to run inside the customer’s own cloud account.

## The deployment model

In this model, the components that read and modify code run in the customer’s environment: the Atlas indexer, the test harness, the orchestrator and the agent workers. Repositories are cloned from the customer’s own source control. Build and test runs happen on the customer’s infrastructure. Nothing about the codebase needs to be stored by us.

The agents still need a model. Claude Code can call Claude through Amazon Bedrock or Google Cloud Vertex AI instead of Anthropic’s API directly. In that setup, model requests go to the cloud provider in the region the customer selects, under the customer’s existing cloud agreements, billing and access controls.

## Configuration

Switching Claude Code to a cloud provider is a matter of environment configuration. For Bedrock:

```
export CLAUDE_CODE_USE_BEDROCK=1
export AWS_REGION=ap-southeast-1
```

For Vertex AI:

```
export CLAUDE_CODE_USE_VERTEX=1
export CLOUD_ML_REGION=asia-southeast1
export ANTHROPIC_VERTEX_PROJECT_ID=your-project-id
```

Credentials come from the cloud provider’s normal mechanisms, such as IAM roles or workload identity, rather than long-lived API keys. Model availability differs by provider and region, so this needs checking per deployment.

## Network boundaries

Agent workers should have no general internet access. Outbound traffic is limited to the model endpoint, the source control system and an internal package mirror. That limits what a misbehaving agent could exfiltrate and makes the environment easier to reason about for a security review.

## Data minimization

Running in the customer’s cloud does not remove the need for care. Golden-master inputs derived from production data should be masked or synthesized before agents see them. Test databases contain test data. Logs record what agents did without copying sensitive payloads. For organizations in Singapore, this also supports their obligations under the Personal Data Protection Act.

## What we see

Our access to a customer deployment is limited to what is needed to operate it, and the customer controls it. Operational telemetry, such as health and error rates, can be shared without source code. Where a design partner wants us to look at a specific failure, they decide what to share.

This model makes onboarding slower than signing up for a SaaS product. For the systems we are focused on, we think that is the right trade-off.

