Deepgram Data HandlingSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: deepgram-data-handling description: 'Implement audio data handling best practices for Deepgram integrations. Use when managing audio file storage, implementing data retention, or ensuring GDPR/HIPAA compliance for transcription data. Trigger: "deepgram data", "audio storage", "transcription data", "deepgram GDPR", "deepgram HIPAA", "deepgram privacy", "PII redaction". ' allowed-tools: Read, Write, Edit, Bash(aws:*), Bash(gcloud:*) version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - deepgram - data - compliance - privacy compatibility: Designed for Claude Code --- # Deepgram Data Handling ## Prerequisites - Data classification, consent/legal basis, approved retention/deletion policy, storage boundary, and named data owner. - A redaction/logging policy and an incident route for recording or transcript exposure. ## Examples Process a licensed development fixture through the approved region/storage route, verify its retention/deletion behavior, and record only a correlation ID and policy result. Do not put recordings, transcripts, participant identifiers, or storage URLs into test logs; on accidental exposure, restrict access and follow the data incident procedure. ## Overview Best practices for handling audio and transcript data with Deepgram. Covers Deepgram's built-in `redact` parameter for PII, secure audio upload with encryption, transcript storage patterns, data retention policies, and GDPR/HIPAA compliance workflows. ## Data Privacy Quick Reference | Deepgram Feature | What It Does | Enable | |-------------------|-------------|--------| | `redact: ['pci']` | Masks credit card numbers in transcript | Query param | | `redact: ['ssn']` | Masks Social Security numbers | Query param | | `redact: ['numbers']` | Masks all numeric sequences | Query param | | Data retention | Deepgram does NOT store audio or transcripts | Default behavior | **Deepgram's data policy:** Audio is processed in real-time and not stored. Transcripts are not retained unless you use Deepgram's optional storage features. ## Instructions ### Step 1: Deepgram Built-in PII Redaction ```typescript import { createClient } from '@deepgram/sdk'; const deepgram = createClient(process.env.DEEPGRAM_API_KEY!); // Deepgram redacts PII directly during transcription const { result } = await deepgram.listen.prerecorded.transcribeUrl( { url: audioUrl }, { model: 'nova-3', smart_format: true, redact: ['pci', 'ssn'], // Credit cards + SSNs -> [REDACTED] } ); // Output: "My card is [REDACTED] and SSN is [REDACTED]" console.log(result.results.channels[0].alternatives[0].transcript); // For maximum privacy, redact all numbers: // redact: ['pci', 'ssn', 'numbers'] ``` ### Step 2: Application-Level PII Redaction ```typescript // Additional redaction patterns beyond Deepgram's built-in const piiPatterns: Array<{ name: string; pattern: RegExp; replacement: string }> = [ { name: 'email', pattern: /\b[\w.-]+@[\w.-]+\.\w{2,}\b/g, replacement: '[EMAIL]' }, { name: 'phone', pattern: /\b(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}\b/g, replacement: '[PHONE]' }, { name: 'dob', pattern: /\b(0[1-9]|1[0-2])\/.-\/.-\d{2}\b/g, replacement: '[DOB]' }, { name: 'address', pattern: /\b\d{1,5}\s[\w\s]+(?:Street|St|Avenue|Ave|Road|Rd|Drive|Dr|Lane|Ln|Boulevard|Blvd)\b/gi, replacement: '[ADDRESS]' }, ]; function redactPII(text: string): { redacted: string; found: string[] } { let redacted = text; const found: string[] = []; for (const { name, pattern, replacement } of piiPatterns) { const matches = text.match(pattern); if (matches) { found.push(`${name}: ${matches.length} occurrence(s)`); redacted = redacted.replace(pattern, replacement); } } return { redacted, found }; } // Usage after Deepgram transcription: const transcript = result.results.channels[0].alternatives[0].transcript; const { redacted, found } = redactPII(transcript); if (found.length > 0) console.log('PII found and redacted:', found); ``` ### Step 3: Secure Audio Upload and Storage ```typescript import { S3Client, PutObjectCommand, GetObjectCommand } from '@aws-sdk/client-s3'; import { getSignedUrl } from '@aws-sdk/s3-request-presigner'; import { createHash, randomUUID } from 'crypto'; import { readFileSync } from 'fs'; const s3 = new S3Client({ region: process.env.AWS_REGION ?? 'us-east-1' }); const BUCKET = process.env.AUDIO_BUCKET!; async function uploadAudio(filePath: string, metadata: Record<string, string> = {}) { const audio = readFileSync(filePath); const checksum = createHash('sha256').update(audio).digest('hex'); const key = `audio/${randomUUID()}-${checksum.substring(0, 8)}.wav`; await s3.send(new PutObjectCommand({ Bucket: BUCKET, Key: key, Body: audio, ContentType: 'audio/wav', ServerSideEncryption: 'aws:kms', // Encrypt at rest Metadata: { ...metadata, checksum, uploadedAt: new Date().toISOString(), }, })); // Generate presigned URL for Deepgram to fetch (expires in 1 hour) const presignedUrl = await getSignedUrl(s3, new GetObjectCommand({ Bucket: BUCKET, Key: key }), { expiresIn: 3600 } ); return { key, checksum, presignedUrl }; } // Upload -> Get presigned URL -> Send to Deepgram const { presignedUrl } = await uploadAudio('./recording.wav', { source: 'call-center' }); const { result } = await deepgram.listen.prerecorded.transcribeUrl( { url: presignedUrl }, { model: 'nova-3', smart_format: true, redact: ['pci', 'ssn'] } ); ``` ### Step 4: Transcript Storage Pattern ```typescript interface StoredTranscript { id: string; audioKey: string; // S3 reference requestId: string; // Deepgram request_id transcript: string; // Redacted text confidence: number; duration: number; // Audio duration in seconds model: string; speakers: number; utterances?: Array<{ speaker: number;
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__deepgram-data-handling.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Deepgram Data Handling skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Deepgram Data Handling safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Deepgram Data Handling access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Deepgram Data Handling work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.