Moterra Official Anthropic partner
About us
Get a quote
All writing
Security and compliance

Claude Cowork for business: private deployment in your own cloud

Amanda Uzialaite Amanda Uzialaite 27 August 2026 7 min read
Private Claude by Moterra: read scope, write approval gates, identity and logs inside your own cloud account

Anthropic has published its guidance on using Claude Cowork safely. It is a clear document and worth reading.

It is written for one person on a Pro plan. If you are deciding whether agentic AI enters a 200 person regulated business, you need the next layer: where data is processed, what your auditor sees, and who sets the rules the agent operates under.

That layer is what Moterra builds.

What does Claude Cowork actually do?

Cowork gives Claude the ability to act, not just answer. It reads files, browses the web, runs code, and works inside your connected applications.

Anthropic groups those capabilities in two:

Read tools Claude sees things: a document, an inbox, a database result, a report.
Write tools Claude does things: sends an email, updates a record, runs a command, submits a form.

Read capability is where most of the day-to-day value sits. Write capability is where the leverage is, and where governance earns its place. A business deployment should let you tune both, per workflow, rather than accept a single default.

What does a private deployment give you?

A private Claude deployment in your own cloud gives you the five things a regulated business needs before rollout.

What you need What you get
Data residency Prompts, files and outputs processed in your own cloud tenant, in your chosen region
Audit evidence Logs are yours. You answer a regulator directly, without a vendor request
Access control Connectors inherit the permissions already in place. No new logins, no new SSO maps
Network control Private endpoints, your own KMS keys, AES-256 at rest and TLS 1.3 in transit
Contractual simplicity Moterra operates as a data processor under a DPA covering UK GDPR and EU GDPR

This is the foundation. On top of it sits configuration, and that is the part most deployments skip.

How do you govern what an agent reads and does?

By setting a trust boundary and enforcing it in the deployment rather than in a user settings menu.

Anthropic makes a useful point about agent risk: consequential mistakes need two conditions present together. The agent can read content from outside your trusted sources, and the agent can take an action that matters. Narrow either one and the risk drops sharply.

That is a design instruction, and it is straightforward to act on:

01 Document the trust boundary Which systems, mailboxes and sites are trusted sources. Which are not.
02 Broad read, deliberate write Most valuable agent work is reading and synthesising. Write access is granted per workflow.
03 Approval gates on consequential actions Sending, publishing, paying, deleting. Set as policy, not per user.
04 Scheduled work gets its own permissions Unattended tasks run without a human present, so they get a tighter scope by default.
05 Logs into your existing SOC Activity your security team already monitors, in the tool they already use.
06 Connectors vetted like production software A connector with write access to your CRM is exactly that.
07 One department, one workflow first Prove the pattern, then extend it.

Moterra AI Bridge is the layer that makes these enforceable: admin console, MDM profiles, plugin management and agent controls around Cowork.

How does Moterra deploy Private Claude Cowork?

Private Claude by Moterra runs inside your own AWS or Azure tenant. Same Anthropic product, same models, same interface. What changes is where it runs.

Your data, prompts and files stay in your tenant. Encrypted with AES-256 at rest and TLS 1.3 in transit, accessed through private endpoints with your own KMS keys.
Models delivered via AWS Bedrock or Azure AI Foundry. No data flows back to Anthropic and nothing reaches any training pipeline. Guaranteed by architecture, not policy.
Connectors to SharePoint, Teams, Salesforce, Slack, Jira and Google Workspace read and write while inheriting the permissions already in place. No new logins, no new SSO maps.
Moterra operates strictly as a data processor under a DPA meeting UK GDPR and EU GDPR.
Live in one to two weeks, with a usage dashboard tracking adoption, cost and time saved from day one.

Moterra is an official Anthropic partner and an AWS Partner with GenAI Competency. AWS customers can procure through AWS Marketplace and consolidate with existing AWS spend and committed-use credits.

ISO 27001 and ISO 42001 certified across both the AWS and Anthropic layers, so the deployment stack is certified end to end. AWS and Anthropic hold SOC 2 Type II reports, and Moterra’s setup has been independently validated by cyber security specialists. Your deployment is defensible under UK GDPR, EU GDPR, EU DORA and UK operational resilience requirements.

What does this look like in practice?

Ask your SharePoint and your operations database a question in plain English. Get an answer that cites its sources. The answer never leaves your cloud account.

That is the demo, and it runs on your systems, not a sandbox. Most teams reaching this page have already tried a general purpose assistant and found it could not see their actual data. The pattern is rarely about the model.

Get a quote or book a call to see it running in your environment.

Frequently asked questions

Is Claude Cowork safe to use with confidential business data?

In a private deployment, yes. Your data, prompts and files never leave your cloud tenant. Encryption uses AES-256 at rest and TLS 1.3 in transit, through private endpoints with your own KMS keys, and connectors inherit the access permissions already in place rather than creating new ones.

Where is Cowork data processed?

In a Moterra deployment, inside your own AWS or Azure environment, in the region you select. Anthropic's standard product runs sessions on Anthropic's infrastructure.

Will our data be used to train Claude?

No. Models are delivered via AWS Bedrock or Azure AI Foundry inside your own tenant, with no data flowing back to Anthropic. Your prompts, files and outputs never reach a training pipeline. This is guaranteed by architecture, not policy.

Can Claude Cowork run in Azure rather than AWS?

Yes. Moterra deploys the same architecture in AWS or Azure.

Does Claude Cowork meet GDPR and DORA requirements?

Your deployment is defensible end to end under UK GDPR, EU GDPR, EU DORA and UK operational resilience requirements. The stack is ISO 27001 and ISO 42001 certified across the AWS and Anthropic layers, and Moterra operates as a data processor under a DPA covering both UK and EU GDPR.

How do you control what the agent is allowed to do?

Read scopes and write permissions are configured per workflow, with approval gates on consequential actions such as sending, publishing or deleting. Agent identity comes from your existing identity provider, so permissions follow your existing joiner and leaver process.

What is the difference between this and the Claude Cowork my team already uses?

It is the same Anthropic product, running privately in your cloud. Same models, same interface, same capabilities. What changes is where it runs: your AWS or Azure tenant, your encryption keys, your governance.

How long does deployment take?

Standard deployment is typically live within one to two weeks. Doing it yourself usually takes three to six months across MDM setup, identity integration, MCP plugin development and admin tooling.

Next step

See Cowork answer a question from your own SharePoint.

Bring the hardest questions to the first call. Thirty minutes with a specialist, and a quote for your environment.

Get a quote See the deployment
Amanda Uzialaite Amanda Uzialaite CMO at Moterra. Writes about deploying AI inside regulated companies.

Latest writing

All articles
AI deployment Claude Cowork on 3P vs Claude Enterprise: what is the difference? One runs on Anthropic servers, one inside your own AWS. The difference decides whether your security team can sign it off. Security and compliance Adopting AI in UK legal practice: preserving attorney-client privilege Competitive pressure demands AI adoption, yet professional duty demands privilege. How private infrastructure resolves it. AI deployment AI map simplified: understanding AI, ML, DL and GenAI What sits inside what, in plain language, for people making a decision rather than building a model.
Moterra Moterra Official Anthropic partner

We bridge cutting-edge AI with enterprise-grade infrastructure, giving businesses safe, reliable tools to work smarter.

ISO 27001 / 42001 SOC 2 Type II GDPR · DORA
© 2026 Moterra. All rights reserved. Privacy PolicyTerms and Conditions
Build your Private Claude Cowork plan. Pick users, support, and MCP plugins. We show the monthly cost, Year 1 TCO, and how it compares to Enterprise editions of Claude, ChatGPT and M365 Copilot. Get this quote straight to your inbox when you are done.
Configure
Number of Claude Cowork and Code users {{ usersLabel }}
5 500+
Support tier
MCP plugins 4+ get 20% off the plugin total
Setup fee {{ setupLabel }} {{ setupTag }}
Commitment
Your quote {{ monthlyHeadline }} {{ effectiveLine }}
{{ managedLabel }} {{ managedPrice }} Priority support {{ supportPrice }} {{ pluginsLabel }} {{ pluginsPrice }} Monthly recurring {{ monthlyTotal }} Infrastructure costs + tokens (via AWS/Azure), est. {{ awsPrice }} One-time setup {{ setupPrice }} Year 1 total {{ yearOneTotal }}
Vs. alternatives — per user / month
Private Claude by Moterra {{ effectivePerUser }} in your cloud (AWS or Azure) {{ moterraCatch }}
Claude Enterprise {{ claudePrice }} shared cloud {{ claudeSaving }} + tokens billed separately, often €50-200+/user with usage · 20-seat minimum
ChatGPT Enterprise {{ gptPrice }} shared cloud {{ gptSaving }} price not published, quote-only · ~150-seat minimum · annual prepay
M365 Copilot Enterprise {{ copilotPrice }} plus M365 licence required {{ copilotSaving }} + existing M365 E3/E5 licence required · annual prepay

Indicative figures. Moterra includes private deployment in your own AWS; others are shared-cloud SaaS. Final quote confirmed in writing by your Moterra account manager.

Book a demo

Thirty minutes, and the hardest questions first.

Tell us where you are and a Moterra specialist will confirm a time within one working day.

Goes straight to your sales team · no marketing list · no follow-up sequence

{{ qfInboxText }}

Get your quote by email

We'll send it to you and loop in our team.

Turnstile
Verification failed, please reload the page and try again. Please fill in company, name and work email. Something went wrong. Please try again or email sales@moterra.ai directly.

{{ qfSalesDoneText }}

Talk to sales

Leave your details and we'll reach out with your exact setup already in hand.

Turnstile
Verification failed, please reload the page and try again. Please fill in company, name and work email. Something went wrong. Please try again or email sales@moterra.ai directly.