Skip to content

Manufacturing

Process recipes and setpoints: what to keep out of a data license

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Exact process recipes, setpoints and tuned process windows are often a manufacturer's most valuable trade secrets, so they usually stay out of a data license. What can travel instead are decisions, outcomes and parameters transformed into ranges or relative changes. The test: if a competitor could rebuild your process from a record, exclude it or transform it.

Key takeaways

  • Trade secret protection generally depends on keeping information secret and taking reasonable steps to protect it, so any license needs careful scope and terms.
  • Exact recipes, setpoint tables and tuned process windows belong on the keep-out list by default.
  • Outcomes, decisions and parameters converted to ranges or relative changes can often be shared after review.
  • AI training adds a specific risk: a model may reproduce rare values it saw, so exclusion matters more than contract promises.
  • Confidentiality, no-redistribution, competitor-use, audit and deletion terms work together; no single clause is enough.

Why do recipes and setpoints need special handling?#

Process recipes and setpoints need special handling because manufacturers usually protect them as trade secrets rather than patents, and that protection can weaken if the information is shared without adequate safeguards. Under the federal Defend Trade Secrets Act of 2016, information is a trade secret only if the owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known or readily ascertainable through proper means. State trade secret statutes, most of them based on the Uniform Trade Secrets Act, apply similar tests.

Reasonable does not mean absolute. Archived Justice Department guidance describes measures that are reasonable under the circumstances, with examples such as telling employees the information is secret, limiting access on a need-to-know basis, requiring confidentiality agreements and keeping documents locked. A data license may need to show the same habits: only the records the buyer needs, access limited to named teams, and confidentiality terms that match the sensitivity.

A data license is a deliberate disclosure. That does not end protection by itself, since companies license confidential information under strong terms all the time, but it raises the bar. Counsel may want to see that sensitive values were excluded where possible, that what was shared was necessary, and that the recipient is bound by terms matching the sensitivity. Keep that evidence together: the keep-out list, the transformation method, the license terms and who approved them.

The practical question for a CEO is narrower: which records can teach an AI developer how your plant makes decisions without teaching anyone how to make your product?

Keep-out versus can-share: a working table#

Process records that state exact values a competitor could copy stay out of a data license, while records of outcomes, decisions and transformed parameters can often be shared after review. The table sorts common records by what they reveal. Your counsel and process engineers should adjust it, because the right line depends on your products, customers and competitors.

Keep-out versus can-share: a working table
RecordKeep outCan often share after review
Recipes and formulationsExact ingredients, ratios, sequences and hold timesProduct family labels and whether a batch met spec
Machine setpointsExact temperatures, pressures, speeds, feeds and timings per productBanded ranges, or changes relative to a baseline
Process windowsTuned upper and lower limits that took years to findWhether a run was inside or outside its window
SPC and historian dataRaw tag values mapped to named equipment and productsNormalized series with renamed tags and shifted timestamps
Batch and lot recordsFull batch sheets with material grades and suppliersBatch outcomes, deviations and dispositions
Troubleshooting notesNotes that state the fix as an exact valueThe reasoning: symptom, options considered, decision, result
NCRs and CAPAsCorrective actions written as new setpointsDefect type, root cause category, action type, effectiveness
Maintenance recordsCalibration offsets tied to proprietary tuningFailure modes, work performed, downtime outcome

How to transform parameter data instead of deleting it#

Transforming parameter data keeps much of its teaching value while removing what a competitor could copy. AI developers usually care about patterns, decisions and outcomes more than your exact numbers, so careful transformation often costs a buyer little.

  • Band exact values into ranges wide enough that the original cannot be recovered.
  • Express changes relative to a baseline, so a record shows an increase or decrease rather than the setpoint itself.
  • Rename tags, equipment and product codes with consistent placeholders.
  • Shift or coarsen timestamps where timing would reveal a sequence.
  • Remove material grades, supplier names and lot numbers that point to a formulation.
  • Drop rare or one-off values that could identify a specific product.
  • Keep a private key that maps placeholders back to originals, held only inside your company.

Contract terms that protect process know-how#

Contract terms protect process know-how only as a second layer, after exclusion and transformation have done the heavy lifting. These are the terms counsel typically reviews when process records are in scope.

Contract terms that protect process know-how
TermWhat it doesWhat to check
ConfidentialityTreats the licensed data as confidential informationSurvival after the term; no residuals clause letting staff reuse what they remember
Permitted useLimits use to stated purposes such as training or evaluationWhich models and purposes are covered
No redistributionBars resale, sublicensing or publicationCoverage of affiliates, contractors and derived datasets
Competitor useRestricts use by or for competitors in your segmentHow a competitor is defined and how breaches are handled
Output safeguardsRequires steps to reduce the chance a model reproduces licensed recordsTesting, filtering and notice duties if reproduction is found
SecuritySets storage, access and encryption controlsWho can reach the data and where it is processed
Audit and certificationLets you verify complianceWritten certification at minimum; audit rights where practical
Deletion or returnEnds the buyer's holding of raw data at term endTreatment of copies, backups and models already trained

Memorization: the risk that is specific to AI#

Memorization is the risk that a model trained on your records later reproduces a specific value or passage from them when prompted. It matters most for rare, distinctive content, which is exactly what a unique setpoint or a recipe line looks like.

Contract terms can require buyers to test and filter outputs, but they cannot reliably pull a value back out of a trained model. That is why exclusion comes first: if a number would hurt you in a competitor's hands, it should not be in the delivered files at all.

Some manufacturers also limit their most sensitive packages to evaluation use, where records test a model rather than train it. That narrower scope can reduce exposure, though it changes what a buyer will want and should be weighed with counsel.

Who decides what goes on the keep-out list?#

The keep-out list is decided by a small group: the CEO or owner, the head of process engineering or quality, and counsel. Engineering knows which values took years to find, counsel knows how trade secret law and customer contracts apply, and the CEO decides how much risk the company will accept.

Customer contracts may override your own judgment. Where a customer co-developed a process or specified it in a quality agreement, the related records may be partly theirs or restricted, and they are usually excluded unless the customer agrees in writing. The group can apply a few decision rules record by record.

  • If a competitor could set up a line or batch from the record, keep it out.
  • If a value took long experimentation to find, keep it out or band it widely.
  • If a customer specified or co-developed the process, exclude it unless the customer agrees in writing.
  • If ranges or relative changes could be combined across runs to recover a value, widen them or drop them.
  • If the group is still unsure, start with evaluation-only scope for that record family.

Illustrative: a coatings manufacturer draws the line#

Illustrative: a fictional industrial coatings manufacturer is weighing a license of its quality and production history. Its batch records hold exact formulations, mixing sequences and cure profiles, and its historian logs oven setpoints for every line.

The team keeps formulations, mixing sequences and exact cure profiles out entirely. Oven data is renamed and expressed as changes from each line's baseline, and batch records are reduced to product family, deviation type, disposition and outcome. Deviation investigations stay in, with each fix described as an action, such as raising cure temperature, rather than the new value.

Counsel adds no-redistribution, competitor-use and deletion terms and limits the most sensitive line's data to evaluation use. A process engineer reviews the prepared sample, cannot rebuild any recipe from it, and the owner approves the scope.

How SourceX handles process data#

SourceX handles process data in the Preparation step of the SourceX five-step transaction, after Supply and Rights and before Approval and Delivery. In the SourceX Evidence Packet, the privacy record documents what was removed or transformed and release authorization records the manufacturer's approval, alongside provenance, licensing rights and permitted use.

Nothing is delivered until the manufacturer approves the final scope. The data is licensed, not sold, SourceX's dataset rights are set out in the signed supplier agreement, and customer-owned designs and export-controlled work are excluded from manufacturing packages from the start.

Frequently asked questions

Does licensing process data mean we lose trade secret protection?

Not automatically. Companies license confidential information under strong terms routinely. Risk rises when sensitive values are shared without need or without adequate terms. Excluding exact recipes, transforming parameters and binding the recipient with confidentiality and use limits all support your position. Review the specifics with counsel.

Can we license records from processes a customer specified?

Sometimes, but check the customer agreement first. Quality agreements, purchase order terms and NDAs may restrict use of process data tied to the customer's parts. Those records are usually excluded unless the customer consents in writing, or reduced to outcomes that carry no customer-specific detail.

What if an employee already pasted a recipe into a chatbot?

Treat it as a possible disclosure and tell counsel. Check the tool's terms on retention and training, request deletion where the tool allows it, and record what happened. Then tighten your AI use policy so recipes and setpoints sit on its red list.

Are ranges always safe to share?

No. A range narrow enough to point at the real value can reveal as much as the value itself, and ranges across many runs can sometimes be combined to narrow it further. Ask a process engineer to test whether the original can be recovered before anything leaves.

Can a buyer use our data to build a product that competes with us?

Only if the license allows it. Permitted-use and competitor-use terms can bar use by or for competitors in your segment, and no-redistribution terms stop the data from being passed on. Define competitors precisely, because vague definitions are hard to enforce.

Sources

  • Under 18 U.S.C. 1839(3), information qualifies as a trade secret only if the owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known to, and not readily ascertainable through proper means by, another person who can obtain economic value from its disclosure or use. Source
  • The Defend Trade Secrets Act of 2016, signed May 11, 2016, created a federal civil cause of action for trade-secret misappropriation (18 U.S.C. 1836). Source
  • DOJ guidance states that trade secret protective measures need not be absolute but must be reasonable under the circumstances, citing examples such as advising employees of the trade secret's existence, limiting access on a need-to-know basis, requiring confidentiality agreements, and keeping documents locked. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify