Manufacturing
Process recipes and setpoints: what to keep out of a data license
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Exact process recipes, setpoints and tuned process windows are often a manufacturer's most valuable trade secrets, so they usually stay out of a data license. What can travel instead are decisions, outcomes and parameters transformed into ranges or relative changes. The test: if a competitor could rebuild your process from a record, exclude it or transform it.
Key takeaways
- Trade secret protection generally depends on keeping information secret and taking reasonable steps to protect it, so any license needs careful scope and terms.
- Exact recipes, setpoint tables and tuned process windows belong on the keep-out list by default.
- Outcomes, decisions and parameters converted to ranges or relative changes can often be shared after review.
- AI training adds a specific risk: a model may reproduce rare values it saw, so exclusion matters more than contract promises.
- Confidentiality, no-redistribution, competitor-use, audit and deletion terms work together; no single clause is enough.
Why do recipes and setpoints need special handling?#
Process recipes and setpoints need special handling because manufacturers usually protect them as trade secrets rather than patents, and that protection can weaken if the information is shared without adequate safeguards. Under the federal Defend Trade Secrets Act of 2016, information is a trade secret only if the owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known or readily ascertainable through proper means. State trade secret statutes, most of them based on the Uniform Trade Secrets Act, apply similar tests.
Reasonable does not mean absolute. Archived Justice Department guidance describes measures that are reasonable under the circumstances, with examples such as telling employees the information is secret, limiting access on a need-to-know basis, requiring confidentiality agreements and keeping documents locked. A data license may need to show the same habits: only the records the buyer needs, access limited to named teams, and confidentiality terms that match the sensitivity.
A data license is a deliberate disclosure. That does not end protection by itself, since companies license confidential information under strong terms all the time, but it raises the bar. Counsel may want to see that sensitive values were excluded where possible, that what was shared was necessary, and that the recipient is bound by terms matching the sensitivity. Keep that evidence together: the keep-out list, the transformation method, the license terms and who approved them.
The practical question for a CEO is narrower: which records can teach an AI developer how your plant makes decisions without teaching anyone how to make your product?
Keep-out versus can-share: a working table#
Process records that state exact values a competitor could copy stay out of a data license, while records of outcomes, decisions and transformed parameters can often be shared after review. The table sorts common records by what they reveal. Your counsel and process engineers should adjust it, because the right line depends on your products, customers and competitors.
| Record | Keep out | Can often share after review |
|---|---|---|
| Recipes and formulations | Exact ingredients, ratios, sequences and hold times | Product family labels and whether a batch met spec |
| Machine setpoints | Exact temperatures, pressures, speeds, feeds and timings per product | Banded ranges, or changes relative to a baseline |
| Process windows | Tuned upper and lower limits that took years to find | Whether a run was inside or outside its window |
| SPC and historian data | Raw tag values mapped to named equipment and products | Normalized series with renamed tags and shifted timestamps |
| Batch and lot records | Full batch sheets with material grades and suppliers | Batch outcomes, deviations and dispositions |
| Troubleshooting notes | Notes that state the fix as an exact value | The reasoning: symptom, options considered, decision, result |
| NCRs and CAPAs | Corrective actions written as new setpoints | Defect type, root cause category, action type, effectiveness |
| Maintenance records | Calibration offsets tied to proprietary tuning | Failure modes, work performed, downtime outcome |
How to transform parameter data instead of deleting it#
Transforming parameter data keeps much of its teaching value while removing what a competitor could copy. AI developers usually care about patterns, decisions and outcomes more than your exact numbers, so careful transformation often costs a buyer little.
- Band exact values into ranges wide enough that the original cannot be recovered.
- Express changes relative to a baseline, so a record shows an increase or decrease rather than the setpoint itself.
- Rename tags, equipment and product codes with consistent placeholders.
- Shift or coarsen timestamps where timing would reveal a sequence.
- Remove material grades, supplier names and lot numbers that point to a formulation.
- Drop rare or one-off values that could identify a specific product.
- Keep a private key that maps placeholders back to originals, held only inside your company.
Contract terms that protect process know-how#
Contract terms protect process know-how only as a second layer, after exclusion and transformation have done the heavy lifting. These are the terms counsel typically reviews when process records are in scope.
| Term | What it does | What to check |
|---|---|---|
| Confidentiality | Treats the licensed data as confidential information | Survival after the term; no residuals clause letting staff reuse what they remember |
| Permitted use | Limits use to stated purposes such as training or evaluation | Which models and purposes are covered |
| No redistribution | Bars resale, sublicensing or publication | Coverage of affiliates, contractors and derived datasets |
| Competitor use | Restricts use by or for competitors in your segment | How a competitor is defined and how breaches are handled |
| Output safeguards | Requires steps to reduce the chance a model reproduces licensed records | Testing, filtering and notice duties if reproduction is found |
| Security | Sets storage, access and encryption controls | Who can reach the data and where it is processed |
| Audit and certification | Lets you verify compliance | Written certification at minimum; audit rights where practical |
| Deletion or return | Ends the buyer's holding of raw data at term end | Treatment of copies, backups and models already trained |
Memorization: the risk that is specific to AI#
Memorization is the risk that a model trained on your records later reproduces a specific value or passage from them when prompted. It matters most for rare, distinctive content, which is exactly what a unique setpoint or a recipe line looks like.
Contract terms can require buyers to test and filter outputs, but they cannot reliably pull a value back out of a trained model. That is why exclusion comes first: if a number would hurt you in a competitor's hands, it should not be in the delivered files at all.
Some manufacturers also limit their most sensitive packages to evaluation use, where records test a model rather than train it. That narrower scope can reduce exposure, though it changes what a buyer will want and should be weighed with counsel.
Who decides what goes on the keep-out list?#
The keep-out list is decided by a small group: the CEO or owner, the head of process engineering or quality, and counsel. Engineering knows which values took years to find, counsel knows how trade secret law and customer contracts apply, and the CEO decides how much risk the company will accept.
Customer contracts may override your own judgment. Where a customer co-developed a process or specified it in a quality agreement, the related records may be partly theirs or restricted, and they are usually excluded unless the customer agrees in writing. The group can apply a few decision rules record by record.
- If a competitor could set up a line or batch from the record, keep it out.
- If a value took long experimentation to find, keep it out or band it widely.
- If a customer specified or co-developed the process, exclude it unless the customer agrees in writing.
- If ranges or relative changes could be combined across runs to recover a value, widen them or drop them.
- If the group is still unsure, start with evaluation-only scope for that record family.
Illustrative: a coatings manufacturer draws the line#
Illustrative: a fictional industrial coatings manufacturer is weighing a license of its quality and production history. Its batch records hold exact formulations, mixing sequences and cure profiles, and its historian logs oven setpoints for every line.
The team keeps formulations, mixing sequences and exact cure profiles out entirely. Oven data is renamed and expressed as changes from each line's baseline, and batch records are reduced to product family, deviation type, disposition and outcome. Deviation investigations stay in, with each fix described as an action, such as raising cure temperature, rather than the new value.
Counsel adds no-redistribution, competitor-use and deletion terms and limits the most sensitive line's data to evaluation use. A process engineer reviews the prepared sample, cannot rebuild any recipe from it, and the owner approves the scope.
How SourceX handles process data#
SourceX handles process data in the Preparation step of the SourceX five-step transaction, after Supply and Rights and before Approval and Delivery. In the SourceX Evidence Packet, the privacy record documents what was removed or transformed and release authorization records the manufacturer's approval, alongside provenance, licensing rights and permitted use.
Nothing is delivered until the manufacturer approves the final scope. The data is licensed, not sold, SourceX's dataset rights are set out in the signed supplier agreement, and customer-owned designs and export-controlled work are excluded from manufacturing packages from the start.
Frequently asked questions
Does licensing process data mean we lose trade secret protection?
Not automatically. Companies license confidential information under strong terms routinely. Risk rises when sensitive values are shared without need or without adequate terms. Excluding exact recipes, transforming parameters and binding the recipient with confidentiality and use limits all support your position. Review the specifics with counsel.
Can we license records from processes a customer specified?
Sometimes, but check the customer agreement first. Quality agreements, purchase order terms and NDAs may restrict use of process data tied to the customer's parts. Those records are usually excluded unless the customer consents in writing, or reduced to outcomes that carry no customer-specific detail.
What if an employee already pasted a recipe into a chatbot?
Treat it as a possible disclosure and tell counsel. Check the tool's terms on retention and training, request deletion where the tool allows it, and record what happened. Then tighten your AI use policy so recipes and setpoints sit on its red list.
Are ranges always safe to share?
No. A range narrow enough to point at the real value can reveal as much as the value itself, and ranges across many runs can sometimes be combined to narrow it further. Ask a process engineer to test whether the original can be recovered before anything leaves.
Can a buyer use our data to build a product that competes with us?
Only if the license allows it. Permitted-use and competitor-use terms can bar use by or for competitors in your segment, and no-redistribution terms stop the data from being passed on. Define competitors precisely, because vague definitions are hard to enforce.
Sources
- Under 18 U.S.C. 1839(3), information qualifies as a trade secret only if the owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known to, and not readily ascertainable through proper means by, another person who can obtain economic value from its disclosure or use. Source
- The Defend Trade Secrets Act of 2016, signed May 11, 2016, created a federal civil cause of action for trade-secret misappropriation (18 U.S.C. 1836). Source
- DOJ guidance states that trade secret protective measures need not be absolute but must be reasonable under the circumstances, citing examples such as advising employees of the trade secret's existence, limiting access on a need-to-know basis, requiring confidentiality agreements, and keeping documents locked. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.