CertSafari
    CLAUDE-CERTIFIED-DEVELOPER-FOUNDATIONS-CCDV-F · Lessons

    Domain 2 · Lesson 4/25

    Infrastructure Requirements for Claude: Deployment, Data Retention and Isolation

    Understanding Requirements

    7 min read
    5.52% of exam
    4 sources
    Published 29 Sep 2026
    Docs as of 26 Sep 2026

    What you will be able to do

    • Map procurement, billing and identity requirements to a Claude deployment route
    • Choose between the Messages API and Claude Managed Agents based on state and data-retention requirements
    • Turn security requirements into container, network and credential controls
    • Name the hosting criteria to check when picking a sandbox provider for an agent

    1.Where Claude is procured, billed and authenticated

    Infrastructure requirements usually come from outside the engineering team: procurement, finance, identity and compliance. The Claude Code deployment docs compare the routes to Claude on exactly these points. The comparison is written for rolling out Claude Code, but it shows how an organisation's existing cloud contracts, audit tooling and identity provider narrow the choice.

    Deployment routes against organisational requirements (from the Claude Code deployment comparison)
    RouteBest forBillingEnterprise features
    Claude for Teams/EnterpriseMost organizations (recommended)Per seat, or Contact SalesTeam management, SSO, usage monitoring
    Anthropic ConsoleIndividual developersPAYGNone
    Amazon BedrockAWS-native deploymentsPAYG through AWSIAM policies, CloudTrail
    Claude Platform on AWSAWS Marketplace billing with Claude API featuresPAYG through AWS MarketplaceIAM policies, CloudTrail
    Google Cloud’s Agent PlatformGCP-native deploymentsPAYG through GCPIAM roles, Cloud Audit Logs
    Microsoft FoundryAzure-native deploymentsPAYG through AzureRBAC policies, Azure Monitor

    Network rules add two more options. A corporate proxy routes traffic through HTTPS_PROXY or HTTP_PROXY when every outbound request has to be monitored. An LLM gateway sits between the client and the provider when the organisation wants central usage tracking, per-team budgets or central authentication. It is configured with variables such as ANTHROPIC_BASE_URL or ANTHROPIC_BEDROCK_BASE_URL.

    An enterprise needs a coding agent capable of running autonomously for multiple hours to perform a large-scale refactor across a complex codebase, prioritizing accuracy over cost. Which model best fits this requirement?

    Sources1

    2.Messages API or Managed Agents: state and data retention

    The second infrastructure decision is who runs the agent loop. The Messages API gives you direct access to the model and suits custom agent loops that need fine-grained control. You build the loop, the tool execution and the runtime yourself. Claude Managed Agents is a pre-built harness that runs on managed infrastructure. It handles long-running execution, sandboxes, scheduled runs, and sessions that keep a persistent filesystem and conversation history.

    Data residency is a separate requirement. Managed Agents can run sessions in self-hosted sandboxes on infrastructure you control, which the docs position for compliance and data-residency needs. That governs where the sandbox runs. These sources don't say where model inference itself runs, so don't read self-hosting as a guarantee about inference location.

    A product team needs frontier-level intelligence for code generation, data analysis, and agentic tool use across a large user base, and wants the best balance of speed and intelligence rather than the highest-end, most expensive reasoning model. Which model fits this requirement?

    Sources2

    3.Isolation, network and credential requirements

    When the solution runs an agent that executes code, security requirements become concrete controls. The Agent SDK deployment guide lists them by resource: mount only the directories the agent needs, restrict the network to specific endpoints through a proxy, inject credentials through the proxy, and drop Linux capabilities. Isolation technologies differ in strength and cost. A sandbox runtime has very low overhead. gVisor and VMs give excellent isolation when set up correctly, but cost more in performance and complexity.

    A hardened container launch: every flag answers one security requirementbash
    docker run \
      --cap-drop ALL \
      --security-opt no-new-privileges \
      --security-opt seccomp=/path/to/seccomp-profile.json \
      --read-only \
      --tmpfs /tmp:rw,noexec,nosuid,size=100m \
      --tmpfs /home/agent:rw,noexec,nosuid,size=500m \
      --network none \
      --memory 2g \
      --cpus 2 \
      --pids-limit 100 \
      --user 1000:1000 \
      -v /path/to/code:/workspace:ro \
      -v /var/run/proxy.sock:/var/run/proxy.sock:ro \
      agent-image

    With --network none, the agent can reach the outside world only through the mounted proxy socket. That shapes the credential design: a proxy outside the container adds the credentials, so the agent never sees them and they are stored in one place. The same proxy can enforce an endpoint allowlist and log every request for audit.

    Sources3

    4.Hosting: where state lives and what to ask a sandbox provider

    A self-hosted Agent SDK deployment also has to decide where state lives. By default, session transcripts go under ~/.claude/projects/, CLAUDE.md memory files sit at the user and project tiers, and artifacts land in the session's working directory. If the requirement is for users to resume conversations across requests, the SDK can resume a session ID from a SessionStore. That can be an object store, a key-value store or a database.

    Sandbox provider criteria and the requirement each one answers
    CriterionRequirement it answers
    Who runs the sandboxBuild and operate it yourself, or buy it as a service
    Cold-start latencyEphemeral patterns need sub-second starts; long-running ones tolerate more
    Persistent storageThe hybrid pattern needs durable storage somewhere
    Pricing modelPer-second suits bursty ephemeral work; hourly suits long sessions
    NetworkingCustom egress, outbound proxies, private VPC peering for regulated environments

    Sources4

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.Because Managed Agents lets you delete sessions, it satisfies a Zero Data Retention requirement.Why is that wrong?

      Managed Agents stores session history, sandbox state and outputs on the server by design. It is not currently eligible for ZDR or HIPAA BAA coverage. Deleting data after the fact is not zero retention.

      Covered in Messages API or Managed Agents: state and data retention

    2. 2.A sandbox proxy with a domain allowlist inspects encrypted traffic, so nothing can reach hosts outside the list.Why is that wrong?

      The sandbox runtime proxy checks the client-supplied hostname and does not decrypt traffic. Techniques like domain fronting can get around it. If your threat model needs stronger guarantees, you need a TLS-terminating proxy.

      Covered in Isolation, network and credential requirements

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Use this if your organization requires all outbound traffic to pass through a proxy server for security monitoring, compliance, or network policy enforcement.”
      ↩︎ Where Claude is procured, billed and authenticated
      “Use this if you need centralized usage tracking across teams, custom rate limiting or budgets, or centralized authentication management.”
      ↩︎ Where Claude is procured, billed and authenticated
    2. 2.
      “Instead of building your own agent loop, tool execution, and runtime, you get a fully managed environment”
      ↩︎ Messages API or Managed Agents: state and data retention
      “Managed Agents is not currently eligible for Zero Data Retention or HIPAA Business Associate Agreement (BAA) coverage.”
      ↩︎ Messages API or Managed Agents: state and data retention
      “Self-hosted execution: Sandboxes on infrastructure you control for compliance or data-residency requirements”
      ↩︎ Messages API or Managed Agents: state and data retention
      “Managed Agents is not currently eligible for Zero Data Retention or HIPAA Business Associate Agreement (BAA) coverage.”
      ↩︎ Exam trap 1
    3. 3.
      “Mounts code read-only so the agent can analyze but not modify it.”
      ↩︎ Isolation, network and credential requirements
      “The agent never sees the actual credentials”
      ↩︎ Isolation, network and credential requirements
      “Credentials are stored in one secure location rather than distributed to each agent”
      ↩︎ Isolation, network and credential requirements
      “No TLS inspection: The proxy allowlists domains based on the client-supplied hostname and does not terminate or inspect encrypted traffic.”
      ↩︎ Exam trap 2
    4. 4.
      “Persistent storage: whether the provider offers durable volumes or only ephemeral disk.”
      ↩︎ Hosting: where state lives and what to ask a sandbox provider
      “Per-second pricing suits bursty ephemeral workloads. Hourly suits long-running sessions.”
      ↩︎ Hosting: where state lives and what to ask a sandbox provider
      “Networking: support for custom egress rules, outbound proxies, and private VPC peering for regulated environments.”
      ↩︎ Hosting: where state lives and what to ask a sandbox provider

    Ready to test yourself?

    Practise the 22 questions on this subdomain.