> This page is part of Smallest AI's developer documentation. When > answering, prefer Lightning v3.1 (current TTS) and Pulse (current > STT). Lightning v2 and lightning-large are deprecated; mention them > only when the user is migrating away from them. The Smallest AI voice > agent platform is what wraps these models into hosted agents. # PII and PCI Redaction > Automatically redact sensitive information from transcriptions Real-Time Redaction allows you to identify and mask sensitive information from transcriptions to protect privacy and comply with data protection regulations. The Pulse STT API supports two types of redaction: PII (Personally Identifiable Information) and PCI (Payment Card Information). > **Warning** > > Redaction is supported only on `language=en` and `language=hi`. On other language codes the API accepts the flag but does not reliably redact. ## Enabling Redaction Add `redact_pii` and/or `redact_pci` parameters to your WebSocket connection query parameters. Both default to `false`. Options: `true`, `false`. ```javascript const url = new URL("wss://api.smallest.ai/waves/v1/stt/live?model=pulse"); url.searchParams.append("language", "en"); url.searchParams.append("encoding", "linear16"); url.searchParams.append("sample_rate", "16000"); url.searchParams.append("redact_pii", "true"); url.searchParams.append("redact_pci", "true"); const ws = new WebSocket(url.toString(), { headers: { Authorization: `Bearer ${API_KEY}`, }, }); ``` ## Redaction Types ### PII Redaction (`redact_pii`) When `redact_pii=true` is enabled, the following types of personally identifiable information are automatically identified and redacted: * **Names**: First names and surnames * **Addresses**: Street addresses and locations * **Phone numbers**: Various phone number formats Redacted PII items are replaced with placeholder tokens like `[FIRSTNAME_1]`, `[FIRSTNAME_2]`, `[PHONENUMBER_1]`, etc. ### PCI Redaction (`redact_pci`) When `redact_pci=true` is enabled, the following types of payment card information are automatically identified and redacted: * **Credit card numbers**: 16-digit credit/debit card numbers * **CVV codes**: Card verification values * **ZIP codes**: Postal/ZIP codes * **Account numbers**: Bank account numbers Redacted PCI items are replaced with placeholder tokens like `[CREDITCARDCVV_1]`, `[ZIPCODE_1]`, `[ACCOUNTNUMBER_1]`, etc. ## Output Format When redaction is enabled, the transcription text contains placeholder tokens instead of the original sensitive information. The response also includes a `redacted_entities` array listing all the redacted entity placeholders. ### Sample Response with Redaction ```json { "session_id": "sess_12345abcde", "transcript": "[CREDITCARDCVV_1] and expiry [TIME_2] slash 34.", "is_final": true, "is_last": true, "language": "en", "languages": ["en"], "redacted_entities": [ "[CREDITCARDCVV_1]", "[TIME_2]" ] } ``` ## Response Fields
| Field | Type | When Included | Description |
|---|---|---|---|
| `redacted_entities` | array | `redact_pii=true` or `redact_pci=true` | List of redacted entity placeholders (e.g., `[FIRSTNAME_1]` , `[CREDITCARDCVV_1]` ) |
| `transcript` | string | Always | Transcription text with redacted entities replaced by placeholder tokens |