Skip to content

Leadership and readiness

Which operational records count as trade secrets?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

An operational record counts as a trade secret when it has value because competitors do not know it and the company takes reasonable steps to keep it secret. Pricing logic, customer lists with buying history and specific process know-how often qualify; routine support tickets and job records usually do not. Exclude or aggregate anything that qualifies before licensing.

Key takeaways

  • Trade secret status depends on secrecy, value that comes from secrecy and reasonable protection measures, not on the record type alone.
  • Customer lists, pricing logic, cost data and specific process know-how are the operational records most likely to qualify.
  • Routine support conversations and job records are rarely trade secrets as a whole, but individual records can contain secret details.
  • Disclosing a trade secret without confidentiality protections can destroy its status, so screening happens before anything is shared.
  • Your records may also hold other companies' secrets, such as customer designs or supplier pricing, which you cannot license.

What makes a business record a trade secret?#

A business record is a trade secret when the information in it is not generally known, has economic value because it is not known, and is protected by reasonable measures to keep it secret. That is the general shape of US trade secret law under the federal Defend Trade Secrets Act of 2016 and state laws, most of which follow the Uniform Trade Secrets Act. The federal definition in 18 U.S.C. 1839(3) requires both reasonable measures to keep the information secret and independent economic value from its not being generally known or readily ascertainable through proper means.

Compilations matter for operational records. Federal jury instructions note that a compilation of public information can qualify when it is combined in a novel way, which is why a customer list built from years of buying history can be protected even if each company name is public.

The record type alone does not decide the question. A pricing spreadsheet left on an open shared drive, emailed to former employees and never marked confidential is harder to defend than one kept in a restricted folder with access logs.

Reasonable measures usually include NDAs with employees and partners, need-to-know access controls, confidentiality markings, exit procedures and a written policy that people actually follow. Counsel weighs these facts for each category of information.

Record types and how to treat them for licensing#

The table below sorts common operational records by how often they qualify and what a cautious licensing approach looks like. Every company's facts differ, so treat the middle column as a starting point for counsel's review.

Record types and how to treat them for licensing
Record typeLikely a trade secret?WhyHow to treat it for licensing
Customer lists with buying history and contactsOftenCompiled through effort, not public, directly useful to competitorsExclude, or aggregate so no customer can be identified
Pricing models, margins and bid logicOftenReveals how the company prices and where it winsExclude; strip price and margin fields from quotes and estimates
Supplier terms, rebates and cost dataOftenNegotiated, confidential and frequently under supplier NDAsExclude, and check supplier confidentiality terms
Process know-how: SOPs, setups, recipesOften, when specificExplains results competitors cannot reproduceExclude the core; generalized versions may be reviewed
Source code and architecture documentsOftenProprietary implementationExclude production code; review discussions about it
Support tickets and resolutionsRarely as a wholeRoutine problem-solving, though secrets can appear insideLicense after removing secret and personal details
Job and dispatch recordsRarelyOperational history, but together they reveal the customer baseRemove customer identifiers and aggregate locations
Quality records: NCRs and CAPAsSometimesMay expose process parameters and weaknessesReview for parameters and customer-owned specifications
Internal chat and emailMixedMay contain strategy, pricing and plansFilter by channel and topic; exclude leadership and pricing channels

Why routine records can still contain secrets#

Routine records can still contain secrets because people paste whatever they need into the tool in front of them. A support ticket is not a trade secret, but a ticket where an engineer pasted the pricing formula, or a field technician typed the supplier's net cost, carries one.

That means trade secret screening happens at the content level, not only the record-family level. Practical filters include excluding named channels and folders, searching for price, cost, margin and formula fields, and flagging attachments such as spreadsheets and drawings for manual review.

Aggregation can also create a secret. One dispatch record reveals little; the full set reveals every customer location and how often each is served. Look at what the whole package would tell a competitor, not just what each record says.

Other companies' secrets in your records#

Operational records often contain confidential information that belongs to someone else. You cannot license what you do not own, and many contracts require you to protect it.

The practical test is provenance. For each attachment and quoted document, ask who created it and under what agreement it arrived. If the answer is a customer, supplier or client under confidentiality terms, it stays out of the package unless that party agrees in writing.

  • Manufacturers: customer-owned drawings, specifications and part numbers attached to quotes, NCRs and work orders.
  • Engineering and architecture firms: client deliverables, owner requirements and project documents governed by client agreements.
  • Software companies: customer code, configuration files and data pasted into support tickets and bug reports.
  • Distributors: supplier price lists, rebate programs and allocation terms received under confidentiality.
  • Consulting firms: client strategy documents, financials and interview notes from engagements.

Does licensing records put trade secret protection at risk?#

Licensing records under a contract with confidentiality, use restrictions and security requirements is generally consistent with keeping information secret, while sharing without those protections can undermine it. The license terms that matter most are permitted use, a ban on disclosing raw records, a ban on re-identification, security obligations and deletion or return at the end of the term.

Contracts have limits, though. Once records have been used to train a model, it may be impractical to pull the information back out. That is why many companies exclude their core secrets entirely rather than relying on contract terms to protect them, and license only the operational history around them.

Reasonable measures to check before any disclosure#

Reasonable measures are the part of trade secret status a company controls, and a licensing review is a good moment to confirm they exist for the records being excluded as well as those being shared. Gaps found now can be fixed before any outside party sees anything.

The measures need not be absolute. DOJ guidance describes them as reasonable under the circumstances and gives examples such as telling employees the secret exists, limiting access on a need-to-know basis, requiring confidentiality agreements and keeping documents locked. One detail is easy to miss: 18 U.S.C. 1833(b) requires employers to give notice of whistleblower immunity in employee contracts governing trade secrets or confidential information, and an employer that omits it may lose exemplary damages and attorney fees under the DTSA against an employee who did not receive it.

  • Employee and contractor agreements include confidentiality obligations that cover the categories in question, plus the 1833(b) immunity notice where counsel advises it.
  • Access to pricing, cost and process folders is limited to people who need it, and access lists are reviewed.
  • Sensitive spreadsheets, drawings and SOPs carry confidentiality markings applied consistently.
  • Departing employees return or delete company information and confirm it in writing.
  • Partners, buyers and evaluators receive information only under an NDA with use restrictions.
  • A written policy describes what is confidential, and managers follow it in practice.

Illustrative: a contract manufacturer screens its quality system#

Illustrative: a fictional precision machining company runs Epicor for orders and a separate QMS for quality records. Leadership wants to know whether its NCRs, CAPAs and maintenance work orders could be licensed.

Counsel finds that NCRs reference customer part numbers and attach customer drawings, which belong to customers. Several CAPAs record the feeds, speeds and fixturing changes that let the shop hold tight tolerances, which is the company's own process know-how. Maintenance work orders describe machine faults and repairs and contain little of either.

The company scopes the package to maintenance work orders and NCR narratives with customer names, part numbers and drawings removed. CAPAs containing process parameters are excluded. The result is a smaller package with every trade secret decision written down.

How SourceX treats trade secrets in a package#

Trade secret screening runs through the Rights and Preparation steps of the SourceX five-step transaction. The rights review identifies the company's own secrets and third-party confidential information; preparation removes confidential details along with personal ones; the supplier approves the final scope in the Approval step.

The SourceX Evidence Packet records licensing rights and permitted use, so both sides can see what was excluded and why. Records are licensed, not sold, and the company keeps ownership.

Under the SourceX Enterprise Data Value Framework, uniqueness and domain expertise increase value and exclusivity increases price. None of that changes the screen: a record that is unique because it exposes a pricing model or a process parameter is excluded, while the surrounding operational history is assessed on its own merits.

Frequently asked questions

Are customer lists always trade secrets?

No. A list of companies anyone could find in a directory, or a list shared freely without restrictions, may not qualify. Lists that combine contacts, buying history, pricing and preferences, built over years and kept under access controls, are much more likely to qualify. Counsel assesses the facts.

Is pricing still a trade secret once it appears on customer invoices?

Individual prices shown to a customer may be known to that customer, but the overall pricing model, margins, cost structure and bid logic can remain secret if protected. Licensing invoices with prices removed is a common way to keep transaction history while protecting the model behind it.

Do we have to mark records confidential to protect them?

Marking is one reasonable measure, not the only one, and not always required. Access controls, NDAs, written policies and consistent behavior also count. What hurts most is inconsistency, such as marking some pricing files and leaving others open to everyone.

Does removing personal data also remove trade secrets?

No. De-identification targets information about people, while trade secret screening targets information about the business, such as formulas, prices and parameters. A record can be fully de-identified and still contain a secret, so the two reviews run separately, ideally with different reviewers who know what to look for.

Can employee know-how discussed in Slack be a trade secret?

Company-specific information discussed in Slack, such as a process setup or a pricing approach, can be. An employee's general skills and experience usually are not. When screening chat, focus on specific methods, numbers and plans rather than general professional discussion.

Sources

  • Under 18 U.S.C. 1839(3), information qualifies as a trade secret only if the owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known or readily ascertainable through proper means; a compilation of public information can qualify if combined in a novel way. Source
  • DOJ guidance states that trade secret protective measures need not be absolute but must be reasonable under the circumstances, citing advising employees of the secret's existence, need-to-know access, confidentiality agreements and locked documents. Source
  • 18 U.S.C. 1833(b) grants whistleblower immunity for certain confidential disclosures and requires employers to give notice of this immunity in any contract with an employee governing use of trade secrets or confidential information. Source
  • An employer that fails to provide the 1833(b) immunity notice may not recover exemplary damages or attorney fees under 18 U.S.C. 1836(b)(3)(C) or (D) against an employee who did not receive it. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify