Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a trade-secret case, build a dated, source-linked record that identifies the information claimed as secret, the measures used to protect it, and the evidence for each alleged act of acquisition, disclosure, or use. An access log can help establish that an account reached a file or system; by itself, it does not establish what a person learned, whether information was copied or used, or whether the person acted with the knowledge or duty relevant to a misappropriation claim.

This guide uses the U.S. federal Defend Trade Secrets Act (DTSA) and Federal Rules of Civil Procedure as its baseline. State law, local rules, court orders, discovery agreements, and case facts may change the procedure. Have counsel identify the governing law and forum-specific requirements before applying this framework to a live matter.

Start by defining what information you claim is a trade secret

Give each asserted secret—or coherent set of information—a stable identifier. Describe it precisely enough that the parties, court, and any experts can distinguish it from public information, general skill or knowledge, and independently developed material. Keep the description consistent across pleadings, discovery responses, declarations, and expert work; record dated versions when the description changes.

Under the DTSA definition, information can take many forms, but it must derive independent economic value from not being generally known or readily ascertainable, and its owner must have taken reasonable measures to keep it secret. The statute does not make any one label, contract, or security control sufficient in every case. Document the measures actually used and how they operated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Integral 16GB Crypto-197 256-Bit Hardware Encrypted 3.0 USB Secure Flash Memory Drive - Certified to FIPS 197, Brute-Force Password Attack Protection & Rugged Double-Layer Waterproof Design
  • Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
  • Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
  • Rugged Double-Layer Waterproof* Design - Protects the crypto drive against knocks, drops, break-in and submerging in water. The electronics are shielded by a hardended inner case. The rubberised silicone outer casing provides a final layer of protection
  • Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
  • Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password

Record the secrecy controls in force

  • Preserve dated versions of access-control policies, confidentiality labels, role permissions, and training materials.
  • Collect relevant nondisclosure and limited-use agreements, along with records showing when they were signed and what information or duties they covered.
  • Document how permissions were granted, reviewed, changed, and revoked, including approvers and effective dates.
  • Where a measure existed on paper, look for evidence of its implementation in practice.

Avoid unnecessarily identifying the secret in public filings. Coordinate with counsel on a sufficiently particular description and on confidentiality protections before filing sensitive material.

Separate access from acquisition, disclosure, and use

The DTSA treats acquisition, disclosure, and use as distinct forms of misappropriation, with knowledge and duty conditions relevant to the statutory definition. Organize evidence around the particular proposition it supports rather than treating a technical event as proof of the whole claim.

Record or event What it may support What it does not establish by itself
Permission record or login event An account had permission or accessed a system at a recorded time. Which person used the account, what they saw or understood, or whether they copied or used the information.
Download, export, print, or transfer record A recorded operation involving a file or data, subject to the system’s logging and attribution limits. That the named person performed the operation, retained or understood the material, or used it improperly.
External sharing or communication record A possible disclosure path or communication involving identified recipients or content. That the communication contained the asserted secret, was unauthorized, or satisfies every element of a claim.
Later product, process, or business record A possible connection between information and later conduct, when supported by reliable comparison and context. That the result came from the alleged secret rather than independent development, lawful reverse engineering, or another explanation.

For each allegation, identify the evidence, its source, its attribution limits, and any contrary evidence. A login may be associated with a person, a shared credential, a service account, or a device; state which is supported and how strongly.

Rank #2
Integral 8GB Courier-197 256-Bit Hardware Encrypted 3.0 USB Secure Flash Memory Drive - Certified to FIPS 197, Brute-Force Password Attack Protection & Super USB3.0 Transfer Speeds
  • Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
  • Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
  • Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
  • Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
  • SuperSpeed USB 3.0 - Transfer all your confidential files and folders faster than ever before. Works on both PC & Mac

Preserve relevant electronic records early

Federal Rule of Civil Procedure 37(e) addresses electronically stored information (ESI) that should have been preserved in anticipation or conduct of litigation, was lost because reasonable steps were not taken, and cannot be restored or replaced through additional discovery. The rule is not a guarantee that every record will be retained. Its 2015 committee note explains: “This rule recognizes that ‘reasonable steps’ to preserve suffice; it does not call for perfection.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Map likely people, systems, and retention risks

  • Identify relevant employees, contractors, vendors, shared accounts, and likely custodians.
  • Map repositories and services that may hold relevant material: collaboration platforms, source-code or design systems, cloud storage, removable media, endpoints, and backups.
  • Record relevant role changes, access grants, and revocations with dates and approvers.
  • Ask system owners about retention schedules, log availability, deletion routines, time zones, and clock configuration where known.
  • Consider potentially relevant communications, audit logs, document histories, download and export records, endpoint data, and third-party records that are available and within the party’s control.

These are practical sources to assess, not an exhaustive list expressly required by Rule 37(e). Counsel should tailor preservation and collection to the matter’s needs and proportionality.

Document preservation and collection decisions

Keep a record of preservation notices or holds, the systems and custodians covered, steps taken to suspend routine deletion where appropriate, collection dates, and known gaps. For each collection, note the source owner or administrator, method, collector, custody transfers, filtering or conversion, and whether an unaltered source was retained. Preserve context and native records where reasonably available; document how working copies were created and changed.

Rank #3
Integral 4GB Crypto-197 256-Bit 3.0 USB Flash Drive Encrypted - FIPS 197 Certified, Brute Force Password Attack Protection & Waterproof Double Layer Design
  • Certified to FIPS 197 - U.S. Government Approved High Level Information Security Standard.
  • Protection against brute force password attacks - Data is automatically erased after 6 unsuccessful access attempts. The data of the USB flash drive type c encryption with dual connectors is destroyed and the cryptographic drive is reset.
  • Durable dual-layer waterproof design* — Protects the crypto reader from bumps, drops, run-in and immersion in water. The electronics are protected by a hardened internal case. Rubberized silicone outer case provides a final layer of protection.
  • Auto-Lock —The cryptographic key automatically encrypts all data and locks when removed from a PC/Mac or when screen protection or "computer lock" is enabled.
  • Secure Entry —Data on these flash drives cannot be accessed without the correct alphanumeric password of 8 to 16 characters. A password indication option is available for this flash drive. The hint cannot match the password.

If information may be missing, note whether it can be restored or replaced through another source. Rule 37(e) does not make every negligent loss an automatic basis for an adverse inference. A court may order measures no greater than necessary to cure prejudice; the rule’s severe measures, including an adverse inference or case-ending relief, require a finding that the party acted with intent to deprive another party of the information’s use in litigation.

Build an auditable chronology

Use one row per event or factual proposition, and retain a link to the underlying source record or exhibit. A useful chronology records:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • the asserted-secret identifier and version;
  • the relevant person, account, device, and role, distinguishing an identified person from an account or service;
  • event date and time, including time zone;
  • source system and native record location;
  • event type, such as permission grant, view, download, transfer, external sharing, disclosure, or later use;
  • the basis for attribution and its limitations;
  • evidence relevant to knowledge, confidentiality or limited-use duties, or notice;
  • corroborating and contrary evidence;
  • preservation and collection status; and
  • the exhibit, custodian, or witness needed to authenticate or explain the record.

This is a practical organization method, not a statutory checklist. Preserve the underlying records and explain any transformations or exports so that the chronology can be checked against its sources.

Rank #4
Sale
Kingston IronKey Vault Privacy 50 16GB Encrypted USB
  • FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
  • Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
  • Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
  • New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
  • Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed

Track gaps and alternative explanations

Maintain a separate gap log so that uncertainty is visible rather than silently converted into a factual conclusion. Flag missing logs, short retention windows, shared credentials, clock drift, incomplete attribution, and records that may be recoverable from another source.

Also record plausible explanations raised by the evidence, including routine business access, independent development, and lawful reverse engineering. The DTSA excludes reverse engineering, independent derivation, and other lawful means from “improper means.” Counsel can use the gap and alternative-explanation record to prioritize discovery and assess what the available evidence does—and does not—support.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect the alleged secret during discovery

Plan with counsel for protective-order terms, access tiers, secure transfer and storage, redaction, and sealing where authorized. Consider how to handle forensic collections that contain personal, privileged, third-party, or otherwise irrelevant material as well as potentially relevant evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Kingston Ironkey Keypad 200 16GB Encrypted USB | Alphanumeric Keypad | Multi-Pin Access | XTS-AES 256-bit | FIPS 140-3 Level 3 Certified | Brute Force & BadUSB Protection | IKKP200/16GB,Blue
  • FIPS 140-3 Level 3 (Pending) Certified Military-Grade Security
  • OS/Device Independent
  • XTS-AES Hardware Encryption
  • Enforced Alphanumeric PIN
  • Multi-PIN (Admin and User) Option

DTSA § 1835 directs courts to take appropriate action to preserve confidentiality in proceedings under the chapter, consistent with applicable procedural and evidence rules. It does not prescribe one universal protective-order form. A DTSA seizure application is an extraordinary remedy subject to specific statutory findings and safeguards, not a routine replacement for preservation and discovery planning.

Choose documentation and collection methods by fit

No single tool or collection method is established as mandatory for every trade-secret dispute. Compare proposed approaches against the needs and risks of the actual matter:

  • Coverage: Which systems, users, dates, and event types can the method capture?
  • Attribution: Does the result identify a person, an account, or only a device or process?
  • Integrity and reproducibility: Can the method and any transformations be explained and repeated?
  • Retention and recoverability: What may be overwritten, and can missing material be restored or replaced?
  • Confidentiality: Can unrelated personal, privileged, or third-party information be protected?
  • Proportionality and cost: Is the approach adequate in light of the dispute’s importance and the parties’ resources?

The Rule 37(e) committee note emphasizes reasonable steps, proportionality, and the possibility that less costly preservation may be substantially as effective as more costly approaches. Counsel and qualified technical professionals should assess the method for the relevant systems and evidence.

Use this as a U.S. federal baseline, not case-specific legal advice

The framework here relies on 18 U.S.C. §§ 1836 and 1839 and Federal Rule of Civil Procedure 37, including the committee note to the 2015 amendment. The cited statutory pages indicate laws in effect during September 2026. Before acting in a live dispute, verify the current statute and procedural rules, the governing state law, applicable local rules, and any case-specific orders or agreements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.