In transit
Encryption
Protects data as it travels. The receiving service can still process the original audio.
Pre-Inference Audio Security
Sensitive information starts in speech. LeakShield detects and sanitizes it in the audio, upstream of downstream speech-to-text (STT) and AI systems.
Raw audio → LeakShield → Sanitized audio → STT → AI
The security boundary
Protect the audio before a downstream provider transcribes it.
Without LeakShield
Microphone
Spoken secret
Raw audio
Secret included
STT
Transcribes secret
Transcript
Secret in text
AI
Secret in context
With LeakShield
Microphone
Spoken secret
LeakShield
Security boundary
Sanitized audio
Detected secret masked
STT
Sanitized input
AI
Sensitive segment absent
Integration example · Built with Pipecat
A voice-agent proof of concept with synthetic credentials. Follow the audio from microphone to downstream STT, then ask the agent what it heard.
The synthetic secret reaches STT in the raw audio, enters the transcript, and can be recalled by the agent.
LeakShield masks the secret in the audio. Downstream STT receives sanitized speech, so the agent cannot recall that secret from this turn.
The secret wasn’t removed from the AI afterwards.
It never reached it.
Complementary controls · Different boundaries
What a system keeps and what it receives are different questions. Keep your existing controls; protect the spoken input too.
In transit
Protects data as it travels. The receiving service can still process the original audio.
After processing
Limits what remains after processing. Sensitive content may still be present during inference.
After STT
Protects downstream text and storage. The STT service may already have received the original speech.
Before downstream STT
Sanitizes detected sensitive speech in the audio before it reaches downstream STT and AI systems.
How it works
Identify credentials, personal information, and other policy-defined sensitive content in incoming speech.
Locate detected content in the audio and mask the corresponding segments while preserving surrounding speech.
Return sanitized audio and redaction metadata for your application to pass to downstream systems.
Evaluate detection coverage with your own audio, languages, and sensitive-data policy before production use.
Developer experience
Place LeakShield between your voice application and downstream speech processing. The audio boundary is designed to be independent of your STT provider or voice framework.
Start with the Pipecat example. Validate audio formats, failure handling, and turn timing for your stack.
Explore the integration example (opens in a new tab)audio = voice_app.audio
result = LeakShield.sanitize(audio)
stt.send(result.sanitized_audio)
audit.record(result.redaction_metadata)The current API is asynchronous: submit → poll → download. This illustrates the integration boundary, not a synchronous SDK call. See the GitHub example for the working flow.
Ecosystem & partners

LeakShield pairs with FlexVertex to connect upstream audio sanitization with graph intelligence. FlexVertex ingests sanitized media and audit logs, preserving entity relationships across graph, document, and vector dimensions.
Explore FlexVertex integration (opens in a new tab)Access
Evaluate the API with your audio and explore the Pipecat example.
Request beta access (email)Discuss your workload, audio formats, latency needs, and integration requirements.
Discuss your workload (email)Explore VPC, on-premise, or embedded use with your security and engineering teams.
Talk about deployment (email)Request API / beta access
Tell us what you’re building and where sensitive speech enters your system.
Beta requests open your email app. Enterprise calls are scheduled through Cal.com.