Built around permission, confirmation, and review.
BookBridge is a private-beta booking layer for supported local service businesses. The system is designed so assistant-initiated appointment changes are scoped, explicit, and reviewable.
Core controls
Confirmation gates
AI-initiated booking, reschedule, and cancel writes require explicit customer confirmation before the write is completed.
Request-bound consent
Confirmation records are single-use, expire quickly, and are bound to the appointment details that were shown to the customer.
Scoped, expiring credentials
API and MCP credentials are tenant-bound, audience-bound, capability-scoped, shown once, and revocable. New dashboard-issued client credentials expire after 90 days.
Audit trail
Reads, writes, account actions, denied auth attempts, webhooks, and fulfillment events are recorded for review.
Provider and integration security
- Provider credentials are encrypted at rest using envelope encryption.
- Webhook ingestion requires provider signature verification where supported.
- Duplicate webhook deliveries are deduplicated before state changes are applied.
- Browser, voice, and human-ops rails are approved private-beta pilots, not broad default automation.
Data minimization
BookBridge is intended to store scheduling logistics: business profile data, service metadata, appointment times, customer contact details needed for booking, confirmation records, billing usage, and non-sensitive audit details. Sensitive healthcare data is outside the product boundary during private beta.
Report a concern
If you find a security issue, data exposure, abuse path, or incorrect booking behavior, email hello@jtrlabs.com with enough detail for us to investigate. Please do not include customer secrets, passwords, or sensitive personal data in the report.
Read the legal policies
The Terms, Acceptable Use Policy, Privacy Policy, and Refund Policy define the formal private-beta boundaries.
Legal