CloudTrustMate

Claude for the modern enterprise.

Give every employee Claude — without giving up control.

Deploy Claude Desktop and Claude Code across your entire organization. Enterprise SSO, per-user quotas, full audit trails, and zero data leakage — all running inside your own AWS account.

Go Live In Under a Day
SOC2 ready architecture
· AWS PRIVATELINK READY
# Nothing for employees to install
MDM pushes claude_desktop_config.json
+ policy + a personal gateway key
✔ Claude Desktop & Claude Code ready
# Admin approves access once
> Users → Pending Approvals → Approve
✔ Quota & model policy applied instantly
AWS Premier Tier Partner

Consulting Partner of the Year 2025

Transformation Partner Visionary Award 2024

AWS Partner Tier Advanced Consulting Partner

Well-Architected Partner Program Member

We are Workmates Core2cloud

An AWS Premier Tier Services Partner that works exclusively with AWS. We help enterprises deploy, govern, and scale AI infrastructure — from cloud migration to managed Claude deployments in your VPC. CloudTrustMate is our enterprise Claude governance platform.

Enterprises struggle to adopt AI at scale.

Authentication

Giving 500+ employees secure access without distributing API keys.

Observability

No visibility into token consumption, latency, or per-user activity.

Governance

No quotas, no model restrictions, no audit trail for compliance.

ROI Evaluation

No per-team cost attribution to measure or justify AI investment.

Features

Everything your org needs.

Two Clients, One Governed Backend

Claude Desktop for chat, Claude Code for engineering — both sharing the same gateway, quota pool, auth, and observability, with zero setup on the employee's machine.

Claude Desktop
  • • Full chat UI with artifacts
  • • File uploads & prompt caching
Claude Code
  • • Terminal + Git integration
  • • Custom skills & MCP servers, auto-synced

Quota & Cost Control

Per-user token limits, team pools, warn/block enforcement with Redis-backed counters.

Engineering38M / 50M
Marketing21M / 25M

Skills & MCP Registry

Bundle custom skills and MCP servers into distributable plugins, managed from the admin dashboard. Publish a skill once — every employee's next session installs it automatically, no re-push required.

AWS Bedrock GitHub Linear PostgreSQL + more
New

Bedrock Guardrails, Pre-Wired

Content policies applied at the gateway, per user or team. Assign more than one guardrail and they're merged automatically into a single resolved policy.

PII Redaction India Aadhaar / PAN + custom policies
New

Teams, Not Just Users

Group employees into teams with their own budget, model access, and guardrail policy — assign once, every member inherits it, admin/pending groups are protected from accidental deletion.

New

One Policy Engine, Org to User

Set cost limits and model access at the org level, override per team, override again per user — the most specific policy always wins, resolved live on every request.

One Dashboard, Every Control

Everything an admin needs, in one place — no separate tools to stitch together.

Model Catalog & Access Live Logs Notifications System Health

Onboard a User in Two Clicks

Add User Bulk Import (CSV) Approve
Users & Approval Workflow
Security

Your data never leaves your AWS account.

All inference happens in your Bedrock deployment. Conversations are never shared with Anthropic or any third party.

Cognito SSO

Google Workspace and other OIDC/SAML identity providers, via Cognito Hosted UI.

IAM Least Privilege

Only bedrock:InvokeModel* granted.

TLS 1.3 + KMS

Encrypted in transit and at rest.

Zero Training

Bedrock never uses your data for training.

Security Architecture
Observability

See everything. Miss nothing.

Real-time token usage, per-user breakdowns, model latency, and cost attribution — all in a built-in admin dashboard.

Admin Dashboard — Real-time Metrics
Dashboard — Top Consumers & Gateway Health API Keys — Per-user Budgets
Tokens
Input / Output
Latency
P50 / P95 / P99
TTFT
Avg / Max
Cache
Read / Write
Throttles
Rate / Count
Cost
Per user / team
Use Cases

Built for every team.

Engineering

  • Code review with security feedback
  • Root cause from log files
  • Auto-generate API docs
  • Bulk refactor via CLI

Data & Analytics

  • Natural language to SQL
  • CSV analysis → exec summaries
  • Chart code generation
  • Anomaly detection

Customer Support

  • Auto-triage by urgency
  • Search 10k+ KB articles
  • Draft replies from past tickets
  • Flag VIP escalations

Legal & Compliance

  • Highlight non-standard clauses
  • Draft GDPR/CCPA docs
  • Summarize audit evidence
  • Auto-redact PII
AI Governance

Enterprise AI Governance
Built on Five Pillars.

Who can use it? What can they do? How do you prove it? How do you control cost? How do you stop it if something goes wrong? — We answer all five.

01

Access

Who can use what

02

Usage

What they can do

03

Audit

How you prove it

04

Financial

How you control cost

05

Operational

How you stop it

Access Governance

Role-based model access per user or team, Cognito SSO gating who can sign in, and every new signup held at $0 budget until an admin explicitly approves it.

Usage Governance

Daily, weekly, and monthly cost limits with org → team → user inheritance, soft-warn or hard-block enforcement, and Bedrock Guardrails (PII redaction, content filtering) applied per user or team.

Audit & Compliance

Structured, searchable logs per user, team, and model — exported to AWS CloudWatch via OpenTelemetry, plus Bedrock Model Invocation Logging for AWS-level audit. Real, queryable evidence for your SOC2/ISO 27001/GDPR/HIPAA reporting, not a black box.

Financial Governance

Hard budget caps enforced at the gateway, per-user and per-team cost attribution, and real-time spend broken down by user, team, and model — right in the dashboard.

Operational Governance

Suspend any user's access with one click, change a team or user's allowed models instantly with no redeploy, and admin/pending groups are protected from accidental deletion.

Per-User Governance & Spend Dashboard
Migration

Migrate to Claude with Zero Friction

Already using another AI provider? We handle the full migration to Claude on AWS Bedrock — preserving your workflows, integrations, and governance policies.

OpenAI / ChatGPT
Claude

OpenAI → Claude

  • GPT-4 / GPT-4o to Claude Sonnet / Opus
  • OpenAI API calls repointed at our gateway, no app rewrite for the caller
  • Custom GPTs to MCP-based skills
  • ChatGPT Enterprise to Claude Desktop
  • Data stays in your AWS — no third-party SaaS
Gemini / Copilot / Others
Claude

Other LLMs → Claude

  • Gemini / Copilot workflows to Claude Code
  • Prompt libraries & system prompts ported
  • Existing integrations rewired to MCP servers
  • User onboarding with zero downtime
  • Full governance & observability from day one
GCP / Vertex AI
AWS

Vertex AI / Gemini → AWS Claude

  • Gemini on Vertex AI to Claude on Bedrock
  • Prompt libraries & workflows ported
  • Existing integrations rewired to MCP servers
  • Data stays in your AWS account, not a second cloud
Azure
AWS

Azure AI → AWS Claude

  • Azure OpenAI Service to Claude on Bedrock
  • GPT-4 Turbo deployments to Sonnet/Opus
  • Azure AI Studio workflows to MCP skills
  • Copilot integrations to Claude Code
  • Azure AD auth to Cognito SSO with zero downtime
01

Audit

Map current AI usage, prompts, integrations, and spend.

02

Plan

Design Claude deployment with equivalent workflows.

03

Migrate

Provision AWS infra once, stage the MDM package, roll out — no installs, no employee CLI.

04

Optimize

Tune quotas, caching, and model selection for cost & quality.

Comparison

CloudTrustMate vs. DIY

Aspect AWS Guidance (DIY) CloudTrustMate
Access Control Basic IdP group yes/no Role-based, per-team, per-model, admin-approval gated
Quotas Not included Per-user, per-team, hierarchical, real-time
Guardrails Manual Bedrock setup Pre-configured presets, assign per user/team, auto-merged
Audit Raw CloudWatch logs Structured, searchable, exported to CloudWatch automatically
Cost Attribution AWS Cost Explorer (delayed) Real-time, per-user and per-team, in the dashboard
Admin Dashboard Not included Built-in — users, teams, guardrails, skills/MCP registry, policy, live logs
Kill Switch Manual IAM changes One-click from dashboard
Model Access Blanket account-level access Per-user/team allow-list, changes apply instantly
Trusted By

Our Customers

ARJAVA
J&F
Quickplay
Pricing

Simple, transparent pricing.

Starting from

$15,000

USD

Please contact us for detailed pricing tailored to your organization's needs.

info@cloudworkmates.com

Ready to deploy? It takes 10 minutes.

Join enterprise teams who've reclaimed control over their AI infrastructure.

Email Us