Your Anthropic account
The AI works in your own Anthropic account, under your agreement with Anthropic, which bills that usage to you.
Security
Label2Prod needs access to your issues and your code. This page says exactly what it reads, what it writes, where your code is worked on, and what stays under your control.
At a glance
The AI works in your own Anthropic account, under your agreement with Anthropic, which bills that usage to you.
Every attempt gets a fresh sandbox that holds no keys or tokens and is deleted when the attempt ends.
It reads only the issues you label and pushes only to its own branches. It will not change your pipeline settings, secrets or key files.
Label2Prod never merges. Your reviewers approve every change, under your own branch protection.
Credentials are encrypted with AES-256-GCM, and row-level security keeps each organization’s data apart.
Every update is a new Jira comment and every revision a new commit. Nothing is edited or rewritten.
Architecture
Label2Prod coordinates. The AI works in a sandbox in your Anthropic account. Only people merge.
Jira Cloud
Your issues
Label2Prod · Frankfurt, Germany
Coordinates, never merges
GitLab
Your code
Your Anthropic account
A sandbox for each attempt
The details
autofix/.autofix/, commits on them, merge requests, and a verification status on those commits.read:jira-work, write:jira-work, manage:jira-webhook and offline_access. Connect with a service account, so comments do not carry a person’s name and access does not end when someone leaves.api scope, which lets Label2Prod push branches and open merge requests. Keep your default branch protected: with protection on, a Developer token cannot push or merge to it.The AI work runs under your Anthropic account and your own agreement with Anthropic, which bills that usage to you. Each attempt stops at a fixed spend ceiling on your key, and you set the monthly limit in the Anthropic Console. Label2Prod does not use your code or issues to train AI models.
The Label2Prod application and its database are hosted in Frankfurt, Germany. Anthropic processes the work of each fix in its own regions, under your account. The full list of providers and what each receives is in the privacy policy.
Sandbox copies of your code are deleted when each attempt ends. Your connections and fix history are kept while your organization exists, so you can see past fixes. Write to hello@label2prod.com to have your organization’s data deleted. What Label2Prod already wrote to Jira or GitLab stays there, under your control.
Found a security issue? Write to hello@label2prod.com. We read every report and reply as soon as we can. Our security.txt has the same contact.
Label2Prod is free for early-access teams, and you don’t need to be a developer. Connect Jira and GitLab, add the label, and approve the tested result.