> ## Documentation Index
> Fetch the complete documentation index at: https://docs.invoca.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Transcription Redaction Overview

> Standard Redaction automatically removes sensitive PCI and PII data from call recordings and transcripts in real time, before anything is written to disk.

Some of the most powerful features in your Invoca account — such as Signal AI — use call recordings and transcripts to give you actionable insights based on the real words and phrases spoken during your calls. At the same time, not all information should live in your account.

To help protect sensitive data, Invoca automatically applies Standard Redaction to both call recordings and transcripts. This ensures personal and financial information is never stored in your account, supporting your compliance efforts and safeguarding caller privacy. You can also configure your account to automatically delete call recordings after a retention period of your choice.

Standard Redaction is enabled by default across all networks, except those that have purchased the Advanced Redaction feature. It automatically removes sensitive information such as credit card numbers, expiration dates, CVV codes, Social Security numbers, and passwords from the audio recording and transcription of recorded calls.

## How redaction works

When a call is recorded in Invoca, sensitive data is automatically redacted from both the audio recording and the transcript (if transcription is enabled) before any data is stored or processed further.

With redaction enabled, Invoca's AI detects and removes sensitive words, phrases, and numbers in memory, in real time, before any data is written to disk. This means:

* Unredacted audio and text never touch Invoca servers or Invoca's transcription partners.
* Redaction is applied consistently to both recordings and transcripts.

**Fields included in Standard Redaction:**

* **PII (Personally Identifiable Information):** date of birth, driver's license number, Social Security number, passport number, and passwords.
* **PCI (Payment Card Industry data):** credit card number, expiration date, CVV, bank account number, and routing number.

Standard Redaction is mandatory for all customers and deployed across all networks. Redaction currently can't be disabled or customized to capture partial entities or additional data types — for that level of control, see [Advanced Redaction](/s/article/advanced-redaction).

Redaction is available in the USA and UK networks, and is applied to English, French, and Spanish conversations.

## Compliance requirements

Redaction at Invoca is SOC 2 Type 2 certified, ISO 27001 compliant, HIPAA compliant, PCI DSS certified, and adheres to GDPR. Visit [Invoca's data privacy and security page](https://www.invoca.com/data-privacy-security-compliance) for a more in-depth overview of Invoca's security, compliance, and data privacy policies.

### PCI DSS and Invoca's role in protecting your data

The Payment Card Industry Data Security Standard (PCI DSS) is a global standard designed to protect credit card information and prevent fraud. Any company that handles payment and cardholder data — whether storing, processing, or transmitting it — must follow PCI DSS rules. This applies to major credit card brands like Visa, Mastercard, American Express, Discover, and JCB.

Invoca is PCI certified, meaning we meet and adhere to the strict security standards required by PCI DSS. Every year, an approved auditor checks our security systems to confirm we're protecting customer data at all levels, from our infrastructure to our services.

This certification covers all aspects of credit card processing, including phone calls where customers may share their payment details. If these calls are recorded or transcribed, the system handling them must be PCI certified — otherwise, neither the system nor the businesses using it are compliant with PCI DSS.

## Viewing redaction settings in your network

**Redaction settings are defined at the network level, not the profile level.**

To see which fields are being redacted in your network:

1. Click **Settings** in the left menu bar.
2. Click **Redaction**.
3. You'll see a read-only page displaying all fields currently redacted.

## Have more questions?

If you have more questions about how Invoca's redaction works, see [Redaction FAQs](/s/article/redaction-faqs), or [submit a support request](https://support.invoca.com/s/) if you don't find the answer there.


## Related topics

- [Advanced Redaction](/s/article/advanced-redaction.md)
- [Transcripts: Foreign Language Support Guide](/s/article/transcripts-foreign-language-support.md)
- [Call Recording: Disabling & Management](/s/article/call-recording-disabling-management.md)
- [Transcription and Phrase Spotting Overview](/s/article/transcription-phrase-spotting-overview.md)
- [Redaction FAQs](/s/article/redaction-faqs.md)
