Skip to main content
9 – 17 UHR +49 8031 3508270 LUITPOLDSTR. 9, 83022 ROSENHEIM
DE / EN

Claude 3P: Run Claude Cowork & Claude Code GDPR-Compliant with CompanyGPT

Tobias Jonas Tobias Jonas | | 10 min read

Anthropic’s new desktop and agent apps are changing how knowledge work gets done at the workplace. At the center are Claude Cowork and Claude Code – the two tabs of the Claude Desktop app that don’t just answer but work autonomously. For German and European companies, the decisive question arises immediately: can these client apps be operated GDPR-compliant without company data flowing out uncontrolled?

The answer is Claude 3P (Third Party) – and for CompanyGPT customers it is especially easy, because the cloud foundation Claude 3P needs is already in place. Combined with CompanyGPT as the governed org-wide platform, this creates a setup that pairs single-seat productivity with enterprise-wide control.

What is Claude 3P (Third Party)?

Claude 3P is a deployment mode of Claude Desktop in which all model inference runs through a provider you configure – instead of through Anthropic’s consumer endpoint. “3P” stands for Third-Party Provider. Anthropic documents several routes for it:

  • Google Cloud Vertex AI
  • Amazon Bedrock
  • Microsoft Foundry (preview)
  • Your own gateway – any compatible gateway you operate
  • Anthropic API directly as an additional option

Crucially, both the Cowork tab and the Code tab work identically to the standard version via Claude 3P. You keep the full agentic Cowork experience – file creation, multi-step research, sub-agent coordination, the Code tab – while inference and billing are handled by the provider you choose. Requests go directly from the user’s machine to the regional endpoint you configure. Vertex AI and Bedrock support EU regions, and you can roll out distinct MDM configuration profiles per region so every user group points at an in-region endpoint.

What is Claude Cowork – and what is Claude Code?

Cowork is Anthropic’s agentic desktop app for knowledge work. Unlike classic chat, Cowork executes multi-step tasks autonomously. You give Claude access to a specific folder and state a goal in natural language. Cowork plans the steps and works through them: transferring receipts from photos into an expense report, writing a summary from interview notes, tidying up a messy directory. Anthropic launched Cowork in January 2026 as a research preview, first on macOS and shortly after with feature parity on Windows. The app is available on all paid plans.

Claude Code is the second tab of the same desktop app and targets development and engineering-adjacent tasks: reading, writing and refactoring code, working in repositories, running tests. Both tabs access the same configured endpoint via Claude 3P.

This is exactly where the tension lies for companies. An agent that accesses local files and repositories and works in multiple steps is enormously productive. At the same time, it needs a clear answer to where inference goes and which data reaches which endpoint.

The decisive point: app at the workplace, inference via your EU endpoint

In an earlier article we explained that Claude via AWS Bedrock or Vertex AI gives you the model but not the app you know from claude.ai. With Cowork and Code via Claude 3P, that picture shifts: now the app is there – and it can be coupled to a sovereign endpoint.

Technically, a provider is configured with region, model ID and authentication (inferenceProvider: vertex, bedrock, gateway, foundry or anthropic). This configuration isn’t set by each user individually; IT distributes it centrally as an MDM profile via Microsoft Intune, Jamf, Workspace ONE or Group Policy. For EU companies, three sovereign paths emerge:

  • AWS Bedrock in EU regions. Authentication via AWS IAM or a Bedrock API key. The inference region is determined by the inference profile – in-region, geographic cross-region or global. Bedrock stores neither prompts nor files, tool inputs and outputs, or model responses, and does not use them for training.
  • Google Vertex AI in Frankfurt. Claude runs as a model on Vertex AI in the EU. The region is determined by the endpoint, so data residency stays within the chosen geography.
  • Your own innFactory API gateway. The client doesn’t point directly at the hyperscaler but at an intermediary gateway. This enables central logging, policy enforcement, model routing and egress control in one place.

In all three cases the setup inherits the existing governance tools of the respective cloud: network isolation via VPC endpoints, audit via CloudTrail, granular cost allocation and optional telemetry. Company data stays in controlled EU infrastructure while employees keep the full Cowork and Code experience.

The synergy with CompanyGPT: you already have the cloud foundation

This is where the real leverage sits. Anyone running CompanyGPT has already built exactly what Claude 3P requires: their own Azure, AWS or Google Cloud tenant, EU endpoints for Claude, IAM roles and service accounts, a cost-center logic and documented AI governance. CompanyGPT customers don’t have to create this foundation anew for Cowork and Code – they reuse it.

In concrete terms: for individual user groups – say engineering, sales or controlling – you enable Claude Cowork and Claude Code via Claude 3P through the same subscriptions and cloud services, and route inference through your own Azure, AWS or Google Cloud with EU endpoints. Authentication runs through the same IAM structures, costs land on the same cost centers, and EU data residency is secured via the same regions as CompanyGPT. The result is not a second, uncontrolled tool path but a consistent extension of your existing, sovereign AI landscape.

The two layers complement each other cleanly:

Cowork and Code via Claude 3P are the power-user layer. Individual employees who work intensively with files or code gain noticeable speed from the agentic desktop tabs. They sit close to the operating system, work on local folders and repositories, and handle tasks that otherwise require manual clicking.

CompanyGPT is the governed org-wide layer. The platform runs in the company’s own Azure tenant as a dedicated Kubernetes environment. It offers central model routing, logging via companyDASHBOARD with token consumption per user and model, document creation via companyFILES, enterprise-wide knowledge connectivity via companyRAG, and automation via MCP servers and n8n. What Cowork is for the individual workstation, CompanyGPT is as the auditable platform usable by everyone.

The following comparison makes the division of roles clear:

DimensionClaude Cowork & Code (3P)CompanyGPT
Primary benefitSingle-seat productivity, agentic file and code workGoverned, org-wide AI platform
ReachPower users on the desktopAll employees, browser-based
Data residencyEU endpoint via Claude 3P (MDM profile)Own Azure tenant, data never leaves it
Logging and costsCloud-native (CloudTrail, telemetry)companyDASHBOARD per user and model
DocumentsLocal files in the access foldercompanyFILES creates Excel, Word, PowerPoint, PDF
Knowledge connectivityLocal folder and repo contextcompanyRAG with SharePoint integration
Model routingOne configured endpointCentral routing across OpenAI, Gemini, Claude, Llama

The combination is strong precisely because both layers feed into the same compliance logic and the same cloud foundation. Cowork and Code point to a sovereign endpoint via Claude 3P, and CompanyGPT keeps data in the customer’s own tenant anyway. There is no second tool landscape with uncontrolled data flow, but a consistently governed setup.

A concrete mid-market scenario

A mechanical engineering company with 400 employees already runs CompanyGPT in its own Azure tenant. Customer contracts and export control require that personal data and technical design documents do not leave the EU.

IT now wants to give the roughly 30 power users in engineering, sales and controlling the agentic desktop apps as well. Because the cloud foundation already exists thanks to CompanyGPT, the effort is small: via Intune, an MDM profile is rolled out that points Claude Cowork and Claude Code via Claude 3P at AWS Bedrock in an EU region, authenticated through the same IAM structures as CompanyGPT. A design engineer has Cowork consolidate a bill of materials from several supplier PDFs into a single Excel spreadsheet, locally, in the access folder; a developer uses the Code tab to refactor an internal tool – all without any data going to a consumer endpoint.

The remaining roughly 370 employees continue to use CompanyGPT. Sales creates proposals via companyFILES, controlling queries metrics from SharePoint via companyRAG, and management sees in companyDASHBOARD, day by day, which department consumes how many tokens. Both layers are documented in the enterprise-wide AI policy under the EU AI Act.

The result: power users get the sharpest available tool, the rest of the organization gets a controlled platform, and data stays in EU infrastructure throughout.

Why model agnosticism is not a luxury

A sovereign setup is not just a data-protection question but a question of operational resilience. June 2026 made that clear. On 12 June 2026, following a government directive from the US administration, Anthropic had to disable Claude Fable 5 and Mythos 5 for all customers worldwide, three days after launch. Anyone who had built their processes on one of these models was left without a solution overnight.

The lesson is not to avoid Claude. On the contrary: the strongest currently available Claude model is Claude Opus 4.8, followed by Sonnet 4.6 and Haiku 4.5. The lesson is not to become dependent on a single model. A sovereign gateway through which both Cowork and Code (via Claude 3P) and CompanyGPT route lets you switch to another available model within minutes in an emergency. CompanyGPT is model-agnostic by design and connects OpenAI, Google Gemini, Claude and Llama in parallel. In the current regulatory environment, this flexibility is not a convenience but risk mitigation.

Frequently Asked Questions

What is Claude 3P (Third Party)?

Claude 3P is a deployment mode of Claude Desktop (the Cowork and Code tabs) in which all model inference runs through a provider you configure: Google Cloud Vertex AI, Amazon Bedrock, Microsoft Foundry (preview), your own gateway or the Anthropic API directly. Requests go from the user’s machine straight to the regional endpoint you configure – so you can pin data residency to EU regions.

Can I run Claude Cowork and Claude Code GDPR-compliant?

Yes, via Claude 3P. Through device management (Intune, Jamf, Workspace ONE, Group Policy) you distribute an MDM profile that routes inference not through the consumer endpoint but through a sovereign endpoint: AWS Bedrock in EU regions, Google Vertex AI in Frankfurt or your own API gateway. You can roll out distinct profiles per geography so each user population points at an in-region endpoint.

How are CompanyGPT and Claude 3P connected?

CompanyGPT customers have already built the cloud foundation: their own Azure, AWS or Google Cloud tenant, EU endpoints, IAM, governance and cost control. You reuse exactly this foundation for Claude 3P to route Claude Cowork and Claude Code for individual user groups over the same sovereign infrastructure. No second, uncontrolled data path is created.

Do I still need CompanyGPT then?

Yes, the two solve different problems. Cowork and Code via Claude 3P are single-seat productivity for power users. CompanyGPT is the governed, auditable org-wide platform with central model routing, logging via companyDASHBOARD, RAG, document creation and automation. Only together do they form a fully controlled setup.

Why does a model-agnostic setup matter?

Because models can disappear. On 12 June 2026 Anthropic had to disable Claude Fable 5 and Mythos 5 for all customers following a government directive. Anyone locked into a single model was left without a solution. A sovereign, model-agnostic gateway lets you switch to another available model such as Claude Opus 4.8 at any time.

Conclusion

Cowork and Claude Code are a real productivity leap, and they don’t conflict with data protection. The key is Claude 3P: the app runs at the workplace, the inference runs through a sovereign EU endpoint. For CompanyGPT customers it is the obvious extension, because the cloud foundation is already in place – individual user groups get the agentic desktop apps through the same subscriptions and services, with no compromise on GDPR and the EU AI Act.

innFactory sets up both layers: the MDM configuration for Cowork and Code via Claude 3P on Bedrock, Vertex AI or your own gateway, plus CompanyGPT in your own tenant. If you want to know what this looks like in your environment, talk to us.

Request a demo now


Tobias Jonas is Founder of innFactory AI Consulting GmbH and innFactory GmbH, Microsoft Cloud Solution Provider and Google Cloud Partner. He advises companies on the secure and sovereign adoption of AI. LinkedIn profile

Tobias Jonas
Written by

Tobias Jonas

Co-CEO, M.Sc.

Tobias Jonas, M.Sc. ist Mitgründer und Co-CEO der innFactory AI Consulting GmbH. Er ist ein führender Innovator im Bereich Künstliche Intelligenz und Cloud Computing. Als Co-Founder der innFactory GmbH hat er hunderte KI- und Cloud-Projekte erfolgreich geleitet und das Unternehmen als wichtigen Akteur im deutschen IT-Sektor etabliert. Dabei ist Tobias immer am Puls der Zeit: Er erkannte früh das Potenzial von KI Agenten und veranstaltete dazu eines der ersten Meetups in Deutschland. Zudem wies er bereits im ersten Monat nach Veröffentlichung auf das MCP Protokoll hin und informierte seine Follower am Gründungstag über die Agentic AI Foundation. Neben seinen Geschäftsführerrollen engagiert sich Tobias Jonas in verschiedenen Fach- und Wirtschaftsverbänden, darunter der KI Bundesverband und der Digitalausschuss der IHK München und Oberbayern, und leitet praxisorientierte KI- und Cloudprojekte an der Technischen Hochschule Rosenheim. Als Keynote Speaker teilt er seine Expertise zu KI und vermittelt komplexe technologische Konzepte verständlich.

LinkedIn