How to Inventory Your Company's Trade Secrets

A working process for identifying, cataloguing, and documenting the trade secrets your company owns, which is what decides whether you can enforce them.

A scientist reviewing a proprietary formula on a whiteboard behind glass
Information qualifies as a trade secret only when it is both secret and valuable because it is secret. Shutterstock
Educational guide, not legal advice. This article explains general legal concepts and is not a substitute for advice from an attorney licensed in your jurisdiction. Reading it does not create an attorney–client relationship.

Quick answer: Build the inventory before you need it, because you cannot protect or enforce what you never identified. Run a cross-functional walkthrough by category (technical, customer and commercial, financial, negative know-how), test each candidate item individually for whether it has value because it is secret, and record for each one: a granular description, where it lives, who can reach it, what it cost to develop, and which measures guard it. Tier by value so protection scales. Exclude general employee skill, because over-claiming sinks otherwise good cases. Run the exercise under counsel's direction to keep the working notes privileged, and refresh it on a cadence and at every departure.

Most companies discover their trade secret inventory does not exist at the worst possible moment: an engineer has left for a competitor, and someone asks what exactly was taken. The honest answer is usually a shrug in the direction of “our processes.” That answer loses cases.

This guide is about the operational work of finding, describing, and documenting what you own. For the underlying doctrine of what legally counts, which elements apply and how courts weigh them, see what qualifies as a trade secret. The short version assumed below: information qualifies when it is secret, guarded by reasonable measures, and valuable precisely because it is not generally known or readily ascertainable (18 U.S.C. § 1839(3)).

Because both elements you will have to prove depend on an act of identification that happens long before litigation.

You cannot show reasonable measures for information you never identified. Access controls, confidentiality markings, need-to-know segmentation, and exit protocols all operate on specific things. An asset nobody catalogued is an asset nobody restricted, marked, or logged. The inventory is upstream of the entire reasonable secrecy measures checklist.

You will have to describe the secret with particularity, and vagueness is fatal. If you sue in California state court under CUTSA, Code of Civil Procedure section 2019.210 (effective January 1, 2005) requires you to “identify the trade secret with reasonable particularity” before commencing discovery relating to the trade secret. You do not get to sue first and figure out what was stolen using the defendant’s documents.

Federal practice is messier, and it is worth being precise about the split rather than repeating the folklore:

  • In Sysco Machinery Corp. v. DCS USA Corp., No. 24-1675 (4th Cir. July 9, 2025), the Fourth Circuit affirmed dismissal of a DTSA claim at the pleading stage. The complaint defined the secrets twice, and then a third way at oral argument, reaching for “proprietary and confidential information, including the Copyrighted Works, and technical, financial, operations, strategic planning, product, pricing vendor, and customer information.” Taken together, the court said, those definitions “suggest that nearly Sysco’s entire business is a trade secret.” Writing for the panel, Judge Wilkinson put it plainly: “In this case, we were forced into such a fishing expedition and emerged empty-handed.”
  • In Quintara Biosciences, Inc. v. Ruifeng Biztech, Inc., No. 23-16093 (9th Cir. Aug. 12, 2025), the Ninth Circuit went the other way on timing, holding that unlike CUTSA, the DTSA does not require a plaintiff to identify its trade secrets with particularity from the start, and that whether a plaintiff has done so is a question of fact usually resolved at summary judgment or trial. The district court had borrowed CUTSA’s section 2019.210 standard and struck nine of the eleven secrets in Quintara’s disclosure statement at the discovery stage, and that was an abuse of discretion.

Read Quintara carefully before relaxing. It moved the deadline, not the requirement: the court reaffirmed that a DTSA plaintiff must still prove its claimed secret has “sufficient particularity” to separate it from general knowledge in the trade and from the special knowledge of persons skilled in the trade. Note also what Quintara’s own list looked like: “customer database,” “marketing plan,” “design of new products,” “DNA Donor technology.” That is a category list, not an identification, and it is exactly what produced five years of procedural warfare between the 2020 complaint and the 2025 appeal. Winning the appeal is not the same as having had an inventory.

The practical takeaway is jurisdiction-independent. Somewhere between the complaint and the verdict, you will have to say precisely what you owned. Doing that work under deposition pressure, from memory, after the fact, is how vague claims get made and dismissed.

How do you run the walkthrough?

Do not send a survey asking people to “list any trade secrets.” You will get nothing, or you will get everything. Sit with each function and walk the categories out loud, because people do not recognize their own tacit knowledge as an asset.

Cover four buckets:

  • Technical. Formulations, process parameters, tolerances, tooling designs, source code and the back-end logic a user never sees, model architectures and training data curation, test rigs, manufacturing settings, the specific sequence that makes the line run faster.
  • Customer and commercial. Curated account data with non-public buying histories and purchasing cycles, negotiated terms, contact maps of who actually decides, win/loss intelligence, channel economics. Not the names. The compiled, non-public detail.
  • Financial. Bid and pricing formulas, cost and margin structures, unit economics, vendor terms, financial models, unreleased roadmaps and business plans.
  • Negative know-how. The single most under-inventoried category. Every dead end you funded is knowledge a competitor would pay to skip. The failed formulation, the supplier that could not hold tolerance, the architecture that collapsed at scale. Ask directly: “What did we try that did not work, and what would it have cost someone to learn that?”

The most useful question in the room is rarely “what is secret.” It is “what would genuinely hurt if a competitor had it Monday morning, and how did we come to know it?” Then follow the artifact: who made it, where does it sit, who else has opened it.

How do you test each item for independent economic value?

Per item. Not per category. A category cannot pass or fail the test, which is precisely why category labels collapse in court.

For each candidate, ask in order:

  1. Would a competitor pay for this, or save real time and money by having it? If nobody would pay and nobody would save, you have information, not a trade secret. Value can be actual or potential, so an unlaunched formulation counts before it earns a dollar.
  2. Is it readily ascertainable by proper means? Could someone get it from a trade directory, a public filing, your own website, or an afternoon with your product on a bench? The operative word is readily. Difficulty and cost of lawful duplication are the whole ballgame.
  3. Have we already published it? Check your own marketing, spec sheets, conference talks, job postings, GitHub, and patent filings. A patent publishes what it discloses, which extinguishes secrecy for that material. Companies routinely inventory as a secret something their own sales deck explains. If you are still choosing between the two paths, see patent vs. trade secret.
  4. What did it cost us to develop, and can we prove that? Development cost and duplication difficulty are the evidence that makes prong one concrete. “We spent two years and significant engineering payroll arriving at these parameters” is a provable sentence. “It is valuable” is not.

Record the answers, not just the verdict. The reasoning is the part that persuades later.

How granular does each entry have to be?

Granular enough that a competent engineer in your field, reading only your entry, could tell your information apart from what the field already knows.

The test is subtractive: strike everything a person skilled in the trade already knows, and see whether anything is left. If the entry survives only because it is broad, it will not survive at all.

FailsWorks
”Our manufacturing process”The specific temperature, dwell time, and pressure envelope for step 4, and why that window (not the one in the literature) prevents the defect
”Customer list”The account-level buying-cycle and margin data in the CRM’s accounts object, fields X, Y, Z, built from seven years of order history
”Our source code”The ranking heuristic in scoring/rank.py, specifically the weighting scheme and the fallback path, neither of which is observable from the product’s output
”Confidential business information”Nothing. This is the phrase that drew a dismissal in Sysco.

An entry that would be equally at home on a competitor’s inventory is not an identification.

How do you tier so protection scales?

Not everything deserves the same treatment, and pretending otherwise is self-defeating: if you mark every routine memo “Confidential,” the label stops meaning anything and a defendant will argue you had no real system.

A workable three-tier split:

  • Tier 1, crown jewels. Loss is existential. Compartmentalize so no single person holds the whole picture, restrict to named individuals, log every access, keep it out of general repositories.
  • Tier 2, material. Loss hurts and helps a rival. Need-to-know by role, marked, NDA-covered, access reviewed when roles change.
  • Tier 3, confidential but commodity. Real but replaceable. Standard NDA and access hygiene is enough.

The tier drives the measures, and the measures are what you will exhibit later. Tiering is also the honest forcing function: if an item cannot earn a tier, ask whether it belongs on the inventory at all.

What must you leave off, and why does over-claiming hurt?

The line you cannot cross is general skill, knowledge, and experience. What an employee learned how to do belongs to them and walks out with them. Only your specific confidential information carries a duty. (For that split in practice, see protecting trade secrets when employees leave.)

The failure mode is not that the over-claimed entry gets struck. It is contamination. An inventory claiming an engineer’s professional competence as company property tells a judge you do not know where your rights end, and that inference lands on your good entries too. Sysco is the cautionary shape: claim the whole business and you may be found to have identified nothing at all.

Also leave off, or mark clearly as excluded: anything published, anything disclosed in a granted patent or published application, anything readily reverse-engineered from a shipped product, and anything you received from a third party under someone else’s terms. That last one matters at hiring, where an incoming employee’s old material is a liability, not an asset.

How do you map access and location?

For each entry, record two things people always assume they know and usually do not.

Where it lives. Follow it everywhere, not to its official home: repositories and branches, the CRM object, cloud drives and the personal folders it got copied into, laptops, the BI dashboard that quietly exports it, the contract manufacturer’s inbox, the SaaS vendor holding it, the Slack thread with the formulation pasted in. Every location is a place secrecy can fail and a place a defendant will point to when arguing it was never guarded.

Who can reach it. Not who should. Pull the actual permissions. The gap between the intended access list and the real one is the single most common finding in this exercise, and closing it is often the highest-value hour in the whole project. Where third parties touch an entry, note the agreement that binds them (contractors and vendors especially), and see how to write an NDA that holds up.

This map is also what makes a departure investigable. When someone leaves, “what did they have access to, and what did they touch” should be a query, not an archaeology project.

When do you refresh it?

An inventory is a photograph of a moving thing. Stale is close to useless, because the entry you need is the one created after the last review.

  • On a cadence. Annually at minimum, semi-annually if you are building fast. Anything shipping a product or model regularly is generating new candidates continuously.
  • At every departure, before the exit interview. The inventory tells you what that person could reach, which is what turns an exit into a real offboarding instead of a handshake. Preserve their access and download logs before wiping the device.
  • At events that change the perimeter. New vendor, new integration, an acquisition, a diligence data room, a joint development deal, a major architecture change.
  • Before you raise or sell. Diligence will ask. See the IP audit before you raise.

Date every version and keep the old ones. A dated series showing the asset existed and was guarded before the departure is worth more than a pristine current document created after it.

How do you keep the inventory itself privileged?

This is the step companies skip and regret. A trade secret inventory is, by construction, a catalogue of your most valuable information plus a candid assessment of how well you are protecting it. In the wrong hands it is a roadmap and, worse, a list of your own admissions.

Practical hygiene, to discuss with counsel before you start rather than after:

  • Run the exercise at the direction of counsel, for the purpose of legal advice, and say so in the engagement and the document itself. Privilege attaches to the purpose, not to a header you paste on afterward.
  • Mark and route accordingly, and keep circulation genuinely narrow. Broad distribution undermines both the privilege claim and the secrecy claim in one move.
  • Separate the candid risk assessment from the identification. The neutral catalogue of what you own and where it lives may be something you want to produce someday. Your notes about which controls are weak are not.
  • Expect that privilege is not absolute here, that treatment varies by jurisdiction, and that a section 2019.210 statement is a disclosure you will affirmatively make. Structure the work with that endgame in mind.

What does good documentation look like two years later?

That is the only audience that matters: a judge reading it cold, after the fact, with a defendant arguing none of it was ever really secret. Judged by that standard, a good entry has six parts:

  1. A granular description that separates the information from general knowledge in the trade.
  2. Provenance and cost. How it was developed, by whom, over what period, at what investment.
  3. The value basis. Why a competitor would pay, and why it is not readily ascertainable.
  4. Location, everywhere it exists.
  5. The access list, as actually configured, with dates.
  6. The measures, tied to the tier: agreements, controls, markings, logs.

Dated, versioned, and consistent with what your systems would show if someone pulled them. The inventory is not persuasive because it is thorough. It is persuasive because it was written before anyone had a reason to lie, and because everything in it can be corroborated by an artifact that has a timestamp.

To see how courts treat identification and secrecy measures in real disputes, browse our trade secret case analysis archive. The pattern is stable: parties who can point to a contemporaneous, specific record fight about the merits, and parties who cannot fight about whether they ever had a trade secret at all.

The bottom line

The inventory is the enforcement decision, made years early and quietly. Identify per item and never per category, because the independent-economic-value test only works on specifics and because “our processes” is the phrase that draws dismissals. Test each entry against value, ready ascertainability, and your own published material. Tier so your protection scales and your markings keep their meaning. Leave out general employee skill, since over-claiming taints the entries that were good. Map where each item lives and who can actually reach it, refresh on a cadence and at every departure, and run the whole thing under counsel’s direction so the working papers stay privileged. Jurisdictions differ on when you must describe your secret with particularity, as the Fourth and Ninth Circuits made clear in 2025, but none of them excuse you from ever doing it. The only question is whether you write that description on your own schedule or on a defendant’s.

Frequently asked questions

How do you create a trade secret inventory? Run a cross-functional walkthrough, department by department, and list candidate items by category: technical, customer and commercial, financial, and negative know-how. Test each item individually against the independent-economic-value question, then record for each one what it is at a granular level, where it lives, who can reach it, what it cost to develop, and which measures protect it. Tier the results by value so protection scales, and put the whole exercise under counsel’s direction so the working notes stay privileged. Refresh it on a cadence and at every departure.

Why does a trade secret inventory matter legally? Two reasons. First, you cannot show reasonable measures for information you never identified, because there is no way to restrict, mark, or log access to an asset nobody catalogued. Second, you must eventually describe the secret with particularity. In California, Code of Civil Procedure section 2019.210 requires identification with reasonable particularity before discovery relating to the trade secret even begins. The inventory is where that description gets built, years before anyone needs it.

How specific does a trade secret description have to be? Specific enough to separate your information from general knowledge in the trade and from the knowledge of people skilled in that trade. Catchall phrases and category labels like “our processes” or “confidential business information” are the classic failure. In Sysco Machinery Corp. v. DCS USA Corp. (4th Cir. 2025), the Fourth Circuit affirmed dismissal where the complaint listed vague categories of proprietary and financial information, effectively implying the company’s entire business was a trade secret.

Can you claim an employee’s skill and experience in your inventory? No, and trying is actively harmful. General skill, training, and industry knowledge belong to the person and travel with them to their next job. If your inventory claims an engineer’s professional expertise as company property, you hand the defense an easy argument that you over-claim generally, which taints the entries that were legitimate. Draw the line at your specific confidential information: the actual parameters, the actual curated data, not the ability to do the work.

This guide is general education, not legal advice, and does not create an attorney-client relationship. How to scope an inventory, and what identification your jurisdiction requires, turns on your specific facts and your state’s version of the UTSA. Consult an attorney licensed in your jurisdiction before acting.

Frequently asked questions

How do you create a trade secret inventory?

Run a cross-functional walkthrough, department by department, and list candidate items by category: technical, customer and commercial, financial, and negative know-how. Test each item individually against the independent-economic-value question, then record for each one what it is at a granular level, where it lives, who can reach it, what it cost to develop, and which measures protect it. Tier the results by value so protection scales, and put the whole exercise under counsel's direction so the working notes stay privileged. Refresh it on a cadence and at every departure.

Why does a trade secret inventory matter legally?

Two reasons. First, you cannot show reasonable measures for information you never identified, because there is no way to restrict, mark, or log access to an asset nobody catalogued. Second, you must eventually describe the secret with particularity. In California, Code of Civil Procedure section 2019.210 requires identification with reasonable particularity before discovery relating to the trade secret even begins. The inventory is where that description gets built, years before anyone needs it.

How specific does a trade secret description have to be?

Specific enough to separate your information from general knowledge in the trade and from the knowledge of people skilled in that trade. Catchall phrases and category labels like "our processes" or "confidential business information" are the classic failure. In Sysco Machinery Corp. v. DCS USA Corp. (4th Cir. 2025), the Fourth Circuit affirmed dismissal where the complaint listed vague categories of proprietary and financial information, effectively implying the company's entire business was a trade secret.

Can you claim an employee's skill and experience in your inventory?

No, and trying is actively harmful. General skill, training, and industry knowledge belong to the person and travel with them to their next job. If your inventory claims an engineer's professional expertise as company property, you hand the defense an easy argument that you over-claim generally, which taints the entries that were legitimate. Draw the line at your specific confidential information: the actual parameters, the actual curated data, not the ability to do the work.

Lidiia Levitska
About the Author

Lidiia Levitska

International Intellectual Property Attorney

Lidiia Levitska focuses on intellectual property dispute resolution, policy, and advisory work across international institutions and government bodies. From 2021 to 2025 she served at the World Intellectual Property Organization (WIPO), managing arbitration cases and overseeing compliance with the Uniform Domain-Name Dispute-Resolution Policy (UDRP), and earlier led IP policy research as a Senior Policy Officer at the American Chamber of Commerce in Ukraine. She holds an LL.M. in International Intellectual Property Law from Chicago-Kent College of Law and an M.A. in Information Technology Law from the University of Tartu, and was admitted to the Ukrainian Bar in 2019.

More about Lidiia →