How to prove a trade secret existed

The instinct is that the hard part of a trade secret case is proving someone took the secret. In practice the claims that fail most often fail earlier, on proving the secret existed in a defined form and that reasonable steps were taken to protect it. Both burdens sit with the holder, and both are questions about what existed and when.

Records a company produced on its own systems answer those questions weakly, because the other side will argue they were written to fit the litigation. A record made at the time, dated by a party with no stake in the outcome, does not carry that weakness.

The three conditions, and what evidences each

Article 2(1) of Directive (EU) 2016/943 sets three conditions, mirrored closely by the UK Trade Secrets (Enforcement, etc.) Regulations 2018 and by the US Defend Trade Secrets Act. All three must hold.

ConditionWhat it meansWhat evidences it
It is secretNot generally known or readily accessible to people who deal with this kind of informationA dated record of the document, showing it existed in that form before any disclosure
It has commercial value because it is secretThe advantage comes from others not having itBusiness records, not something a timestamp addresses
Reasonable steps were taken to keep it secretAgreements, access restrictions, classification, exit proceduresDated records of each measure, plus logs of who was given access and when

The middle row is worth noticing: commercial value is a business question, and no evidential tool speaks to it. Recording addresses the first and third conditions, which is where holders lose.

The element most services ignore

Certificate services address the first condition. They date the document, which shows the information existed in that form before whatever happened next. That is real and it is useful.

The third condition is different in kind. Reasonable steps is not a property of a document; it is an account of how a holder behaved, assessed against what was reasonable in the circumstances. Some competitors claim that maintaining a certified inventory satisfies the requirement. It does not. A court weighs the whole picture, and an inventory is one input to it.

What does help is dating the measures themselves. The confidentiality agreement, the access-control policy, the classification marking, each recorded when it was made rather than described afterwards. Beyond that, access logs are evidence of an access restriction in operation: a dated record of who was granted access to which document and when they opened it is the measure and its proof at once.

The disclosure problem

A trade secret that is never shown to anyone is easy to protect and worth less than one that is. Investors, partners, licensees, contractors and acquirers all need to see something, and every disclosure is a point where evidence goes missing. Six months later the argument is about what was in the version they received, and neither side has a record.

Provlyn shares from a vault rather than by sending copies. Each recipient opens the material through a controlled link, each view is logged against a timestamp, and access can be withdrawn. Each recipient can be issued an individually watermarked copy, so a document that surfaces where it should not identifies who it was given to.

This is where an issuance-only service stops and the practical problem starts. Our post on proving what was disclosed under an NDA goes into the evidential position in more detail.

How the record is made

One automated sequence, each step taking the output of the one before it. The document is hashed with SHA-256. That hash is timestamped under RFC 3161 by an accredited trust service provider. The timestamped hash is anchored to the Bitcoin blockchain through OpenTimestamps. Only the hash travels, so the secret itself stays where it is, which matters more here than anywhere else: a trade secret stops being one the moment it stops being secret.

eIDAS qualification is a separate option on top of that sequence. With it, the timestamp carries the presumption under Article 41(2) that the date and time are accurate and the data intact. Without it the record is still valid and still checkable, but you would have to argue for its accuracy rather than having the burden sit with the party disputing it. A blockchain anchor alone does not carry that presumption, a distinction set out in blockchain timestamps compared with qualified timestamps.

Every certificate can be checked without us, using SHA-256, OpenSSL, the European Commission's trusted lists and any OpenTimestamps client. Our timestamp validator is open source and checks any provider's timestamp, not only ours.

Record your first deposit →

Questions

What makes information a trade secret?

Three conditions, set out in Article 2(1) of Directive (EU) 2016/943 and mirrored closely in UK and US law. The information must be secret, meaning not generally known or readily accessible to people who normally deal with that kind of information. It must have commercial value because it is secret. And it must have been subject to reasonable steps, taken by the person lawfully controlling it, to keep it secret. All three have to hold. Information that is valuable and confidential but protected by nothing is not a trade secret.

How do you prove a trade secret existed on a particular date?

By recording it before the dispute rather than describing it afterwards. The document defining the secret is hashed with SHA-256, the hash is timestamped by an accredited trust service provider under RFC 3161, and the result is anchored to the Bitcoin blockchain. The certificate shows that a document with that exact fingerprint existed on that date. The document itself stays private, because only the hash leaves your systems. What this settles is the definition and the date, which is the point a holder is usually weakest on.

What counts as reasonable steps to keep information secret?

There is no fixed list. Courts assess what the holder did against what was reasonable in the circumstances, looking at things like confidentiality agreements, access restrictions, marking documents as confidential, exit procedures and controls on who could reach what. The burden sits with the holder, and it is evidential: describing a general practice after the fact is weaker than producing dated records of the measures as they were applied. No single tool satisfies this element on its own, and any service claiming otherwise is overstating what it does.

Does timestamping a document satisfy the reasonable steps requirement?

No, and it is worth being plain about that. Reasonable steps is assessed across the whole picture of how the holder protected the information. A dated record is evidence supporting that picture, and a strong one, but it does not replace confidentiality agreements, access controls or the practices around them. Where a record does more work is in dating those measures too: an agreement, an access policy or a confidentiality classification, each recorded when it was made, is evidence of the measures rather than an account of them.

How do I share a trade secret without losing its protected status?

Controlled disclosure under an agreement does not by itself end secrecy, since the information stays outside general knowledge. The evidential difficulty is showing precisely what was disclosed, to whom and when. Sharing from an access-controlled vault records each view against a timestamp, and issuing each recipient an individually watermarked copy means a leaked document identifies the recipient it was given to. That converts what would otherwise be a dispute about recollection into a dated record.

What should a company record?

The document that defines the secret with enough particularity to distinguish it from general industry knowledge, which is the thing courts look for. Alongside it, the measures protecting it: the confidentiality agreement, the access-control policy, the classification marking. Recording the definition without the measures leaves the second element unevidenced, and recording the measures without a defined secret leaves the first. Both matter, and each deposit produces its own certificate.

What does a dated record not establish?

It does not establish that the information qualifies as a trade secret, which is a legal question for a court, nor that anyone misappropriated it, nor who created it. A record establishes that a specific document existed in a specific form on a specific date and has not changed since. That is the foundation the other questions are argued on, not a substitute for arguing them.

Should something be patented or kept as a trade secret?

That is a question for patent counsel, and it turns on whether the method can be reverse-engineered, how long the advantage would last and whether disclosure is acceptable. What matters evidentially is that the decision is one-way in one direction: a patent application publishes, and once published the information is no longer secret. A dated record made before that point preserves evidence of what existed while it was still confidential, which is useful whichever route is taken.

Where to go next. Read what happens when an employee leaves, or how a trade secret claim collapses in practice. If the secret is code, see proving you wrote your source code. Otherwise, check pricing or read how to verify a record without us.

This page gives general information about evidence in trade secret disputes. It is not legal advice. For a specific matter, consult a qualified lawyer in the relevant jurisdiction.