OUR SERVICES

Software Trade Secret Disputes

When source code, algorithms, or customer data walk out the door: how software trade secret litigation works, from misappropriation claims to injunctive relief, and the CFAA and unfair competition claims that travel with them.

Most software trade secret cases do not start with a hacker. They start with a departure: an engineer downloads the repositories the week before resigning, a founder leaves with the architecture in his head and the roadmap on her laptop, a vendor’s team quietly reuses what it learned on your project. Within months, a competitor knows too much, and the question becomes what you can prove and how fast.

Speed defines trade secret litigation more than most intellectual property disputes. Trade secret rights require no registration and arise the moment you have valuable information and protect it. But the remedies that matter, restraining orders and preliminary injunctions, are won or lost in the first days of the dispute. The companies that win are almost always the ones whose protection program was in place before anyone left.

What counts as a software trade secret

Trade secret law protects confidential information that derives independent economic value from not being generally known. It also requires that you take reasonable measures (the state statutes say reasonable efforts) to keep the information secret. For a software company, that reaches further than most people expect: source code and other proprietary code, algorithms, system architecture, training data and model configurations, build and deployment know-how, customer lists and pricing, and the negative knowledge of what you tried that failed. In plain English, misappropriation means acquiring a trade secret through improper means, such as theft, hacking, or breach of a confidentiality obligation. Misappropriation also means using or disclosing one that you know or should know was obtained that way.

Trade secret law also covers exactly what copyright law, the other intellectual property regime that protects software, refuses to protect. Copyright excludes ideas, processes, systems, and methods of operation. Trade secret law protects precisely those things, so long as they stay secret. The two intellectual property regimes are designed to be layered, and the same stolen code often supports both claims.

Distribution does not automatically destroy secrecy. The standard playbook to maintain secrecy is to keep source code confidential while shipping only object code under a license that forbids copying, reverse engineering, and disclosure. That playbook preserves trade secret rights in the source even while you sell the product widely. What destroys secrecy is publication, sloppy handling, or disclosure without obligations attached.

The two laws that do the work: the Defend Trade Secrets Act and state trade secret law

Software trade secret misappropriation cases are usually pleaded under two parallel statutes. The federal Defend Trade Secrets Act (DTSA) gives you a federal forum for trade secret misappropriation connected to interstate commerce. It comes with a three-year clock that runs from discovery. State law in most states follows the Uniform Trade Secrets Act. North Carolina wrote its own Trade Secrets Protection Act, which adds a plaintiff-friendly wrinkle worth knowing. Showing that the defendant knew of the secret and had a specific opportunity to acquire or use it makes out a prima facie case. That shifts the burden to the defendant to prove independent development, reverse engineering, or another lawful source. The regimes largely track each other, and courts analyze the claims together. Federal law supplements rather than displaces state law, so both typically appear in the same complaint. Trade secret cases with enough at stake are also natural candidates for the North Carolina Business Court. A party may designate a trade secret dispute as a complex business case, and designation is mandatory when at least five million dollars is in controversy.

The DTSA brings a few tools worth knowing. It codifies the sealing of trade secrets in court filings, so suing does not mean disclosing. Its reach extends in the right case to a foreign defendant’s overseas sales of products built on stolen secrets. In extraordinary circumstances it authorizes an ex parte seizure of property to stop a secret from being disseminated before the other side even gets notice. And it carries a trap for employers. Exemplary damages and attorneys’ fees against an employee or contractor are available only if that person’s confidentiality agreement included the DTSA’s whistleblower immunity notice. The statute counts contractors and consultants as employees for this purpose, and courts have enforced the forfeiture as early as the pleading stage. Compensatory damages and injunctions survive the omission; the enhanced remedies do not. If your agreements are missing the notice, fixing them costs a paragraph; missing it costs the double-damages remedy in the case where you need it most.

“Reasonable measures” decides trade secret cases

Whether information qualifies as a trade secret at all usually turns on how you treated it before the dispute. Courts inventory your protections, and cases have been lost over an unsigned non-disclosure agreement (NDA), customer data stored on personal devices with the company’s blessing, files shared with a contractor under no agreement, and the absence of any policy against downloading from shared drives. The measures courts look for to maintain secrecy are concrete:

  • Confidentiality agreements with everyone who touches the secrets: employees, contractors, vendors, and partners, signed at the start of the relationship, with the DTSA immunity notice included.
  • Access controls that match reality. Need-to-know permissions on repositories and data, multi-factor authentication, encryption, and logging that shows who opened what and when.
  • Label source code and sensitive documents confidential, consistently but selectively. Marking everything is as damaging as marking nothing.
  • Device and download policies. Prohibit moving company data to personal devices and accounts, and enforce it. This single gap appears in a remarkable share of losing cases.
  • Deliberate onboarding and offboarding. Confidentiality obligations acknowledged on day one. On departure, immediate access shutoff, return and certified deletion of data, an exit interview about where the person is going, and a reminder letter of continuing obligations.
  • An AI-tool policy. Free and consumer-tier AI tools commonly reserve the right to use and disclose what users type into them. That sits at odds with the secrecy trade secret law requires. At least one court has dismissed a trade secret claim where the plaintiff built her claimed secrets by feeding them into a public chatbot. The twin operational risks are shadow AI and false comfort. Shadow AI means employees pasting code into unauthorized tools. False comfort means treating an enterprise tier’s no-training commitment as if it cured internal misuse. Enterprise-tier tools under a written, enforced policy reduce the risk substantially; nothing eliminates it.

None of this is bureaucracy for its own sake. Every item on the list is evidence, and in a trade secret case your program is the first thing the other side attacks.

When someone leaves with source code: the first two weeks and injunctive relief

A departure with your code is an emergency with a checklist. Preserve everything: the departing employee’s computer, email, badge and access logs, and repository activity. Have software experts review all of it through forensic analysis before the trail goes cold. Suspicious downloads in the final weeks are the most common smoking gun in a source code theft case. Move quickly on injunctive relief. Courts can issue temporary restraining orders and preliminary injunctions to stop use or disclosure, order devices preserved or returned, and in some states appoint oversight of the former employee’s new role.

Know the limits. Under federal law, a DTSA injunction cannot simply bar someone from taking a new job. Its restrictions on employment must rest on evidence of threatened misappropriation rather than just on what the person knows. The statute also defers to state law limits on restraints of trade. Some courts will infer threatened misappropriation where the new role makes use of the secrets inevitable, the so-called inevitable disclosure doctrine. Others reject that doctrine entirely, and North Carolina courts have applied it only narrowly, if at all. Non-compete law varies just as widely by state. The claims that travel with the trade secret count usually include breach of the confidentiality agreement, breach of fiduciary duty, and tortious interference, though North Carolina cabins the last two. An ordinary at-will employee usually owes no independently actionable duty of loyalty. A competitor’s mere hiring of your people, without more, is not tortious interference. Together the claim stack frames the leverage for the negotiated resolutions that end most founder and developer departures.

One more requirement shapes the case early. You must ultimately identify each alleged trade secret with sufficient particularity. Catchall phrases and bare category lists, a laundry list of “algorithms, software, and processes,” are inadequate. Appellate courts have vacated eight- and nine-figure verdicts where damages were not tied to the specific secrets actually proven. Under the federal statute, how much detail is required, and when, is usually a question for summary judgment or trial rather than a pleading hurdle. That is no comfort. In litigation the plaintiff bears the burden of showing its information was not readily ascertainable. The cases are won by the party that can name its secrets precisely from day one. Treat the identification as a litigation-readiness item, not a litigation task.

Where the CFAA fits in software trade secret litigation

The Computer Fraud and Abuse Act is the federal anti-hacking statute, and it adds a civil claim when someone accesses your software systems without authorization. Its reach narrowed in Van Buren v. United States. An employee who was authorized to access a system but misused what they found no longer violates the CFAA. Policy violations are not hacking.

The claim still earns its place in the right facts: a former employee who logs in after access was cut off, use of a borrowed or stolen password, an outsider in your systems. The information taken does not have to be a trade secret. In most circuits, including the Fourth Circuit that governs North Carolina’s federal courts, the costs of investigating and responding to the intrusion count toward the statute’s loss threshold. But some courts limit loss to technological harm, and the costs of chasing a competitor’s later use of the information generally do not qualify. Think of the CFAA as situational reinforcement for the access-based fact pattern, not the backbone of a departing-employee case.

Unfair competition claims that stick, and ones that don’t

Trade secret suits usually carry state-law companions, and choosing them well matters. Claims built on deception, passing off someone’s product as your own, fraud, abuse of a confidential relationship, stand on their own. North Carolina adds real teeth. Trade secret misappropriation that satisfies the Unfair and Deceptive Trade Practices Act’s three-part test violates that statute too, and a UDTPA violation carries mandatory treble damages. Two cautions come with the prize. A UDTPA claim built solely on the misappropriation rises and falls with it. A plaintiff generally must elect between UDTPA trebling and the trade secret statute’s punitive damages rather than stacking them.

The other trap is preemption. Federal copyright law displaces state claims that merely repackage copying, and courts routinely dismiss unfair-competition and unjust-enrichment counts pleaded that way. Trade secret claims themselves are safe, because secrecy is an element copyright does not require. Every federal circuit to consider the question has held they survive. The lesson for pleading is to build each state claim around conduct with its own wrongful element, not around the copying.

Remedies for trade secret misappropriation

A successful trade secret plaintiff can recover its actual losses (its actual damages) plus the defendant’s unjust enrichment, or a reasonable royalty. It can also recover exemplary damages up to twice the award under the federal statute for willful and malicious misappropriation (North Carolina frames its enhancement as punitive damages instead). The plaintiff can recover attorneys’ fees as well, subject to the immunity-notice requirement for employee defendants. Unjust enrichment can be measured by the development costs the defendant avoided by stealing rather than building. That theory has supported nine-figure combined awards in software cases. Injunctions can run as long as the information would have remained secret. Criminal exposure exists too. Trade secret theft is a federal crime, and the penalties for organizations scale with the value of what was taken.

The through-line of trade secret litigation is that the decisive work happens before the dispute. The reasonable steps described above are what turn a bad week into a winnable case: the agreements, the access logs, the marking, the exit protocol, and the ability to name your secrets with particularity. If you are staring at a suspicious download report, or building the protection program you wish you already had, that is worth a conversation with experienced software counsel now, while the options are all still open.

Frequently Asked Questions

No. Source code qualifies only if it derives value from secrecy and you take reasonable measures to protect it: confidentiality agreements, access controls, marking, and consistent handling. Code you have published, shared without obligations, or left unprotected does not qualify, and courts have rejected claims where the protection program was thin. Shipping object code under a restrictive license while holding source code confidential preserves secrecy.

Preserve the evidence immediately, including the employee’s devices, access logs, and repository activity, and have software experts build a forensic picture before it degrades. Courts can enter restraining orders and preliminary injunctions against use or disclosure. Typical claims include DTSA and state trade secret misappropriation, breach of the confidentiality agreement, breach of the duty of loyalty, and, where access itself was unauthorized, the CFAA. The strength of your position will track the strength of your paper and your logs.

Not just because of what they know. Trade secret injunctions restrict use and disclosure of the secrets, and under the DTSA, employment restrictions require evidence of threatened misappropriation. Some courts will find threatened misappropriation where the new job makes use of the secrets inevitable; others reject that doctrine. Enforceable non-compete and non-solicitation agreements, where your state allows them, do that work better than trade secret law alone.

Yes, in the right case. The Supreme Court held that people authorized to access a system do not violate the CFAA by misusing what they find, so insider-misuse cases usually will not support the claim. It remains available where access itself was unauthorized: logins after termination, stolen or borrowed credentials, or outside intrusion. Investigation costs can satisfy the loss requirement.

Possibly. Consumer and free tools often reserve the right to use and even disclose inputs, which undercuts the secrecy element; a federal court has dismissed a trade secret claim where the plaintiff had developed her claimed secrets through a public chatbot and so disclosed them voluntarily. The facts matter: a single contained incident under an enterprise agreement with no-training commitments is a very different case from routine use of unauthorized tools. Respond like any inadvertent disclosure: contain it, document it, and tighten the policy. Prevention here is a written AI-use policy plus enterprise tooling.