Skip to content

Trade Secret Investigations

Forensic investigation of trade-secret misappropriation and departing-employee matters — establishing what left, how it left, and who moved it, on a record that holds up at the preliminary-injunction stage and beyond.

What we do

  • Departing-employee examination

    Reconstructing the final weeks of access from workstation, mobile, cloud, and email artifacts — USB attachment history, mass downloads, personal-cloud syncing, forwarding to personal accounts, and file access immediately preceding resignation.

  • Exfiltration reconstruction

    Establishing the path data actually took, and distinguishing deliberate removal from routine business use. The distinction usually decides the motion, and it is a question about artifacts rather than intent.

  • Rapid preservation

    Forensically sound imaging of departing-employee devices and accounts before they are reissued, wiped, or reassigned — the window that most often determines whether the evidence survives at all.

  • Source code and technical comparison

    Structured comparison of code, designs, and technical documents to identify copying, derivation, and the fingerprints that survive superficial modification.

  • Injunction and testimony support

    Methodology reports and declarations built for the compressed preliminary-injunction timeline, with the same examiner available to testify to the findings.

Frequently asked questions

How do you prove trade-secret misappropriation forensically?

Forensic proof generally rests on three linked showings: that the protected material existed and was treated as confidential, that the accused party accessed or removed it, and that the removal falls outside ordinary business use. The artifacts that carry those showings are things like USB device history, cloud-sync and upload logs, email forwarding to personal accounts, mass file access shortly before departure, and the presence of the material on a destination system. No single artifact is usually decisive; the pattern across several is.

What digital evidence shows data exfiltration by a departing employee?

Common indicators include registry and system records of external storage attachment, anomalous volumes of file access or copying in the days before resignation, personal cloud-storage clients installed or synced late in employment, documents emailed or forwarded to personal accounts, printing spikes, and deletion or wiping activity after notice was given. Each has innocent explanations in isolation, which is why the examination looks at sequence and volume rather than treating any one artifact as proof.

How quickly does forensic preservation need to happen?

Immediately, and ideally before the device is reissued. Departing-employee laptops are frequently wiped and redeployed within days, and cloud and endpoint logs commonly age out on retention windows measured in weeks. Every day of delay narrows what can be recovered, and a preservation gap becomes the other side's argument. The duty to preserve attaches when litigation is reasonably anticipated, which is generally earlier than a filed complaint.

What is the role of forensics in a DTSA claim?

The Defend Trade Secrets Act creates a federal civil cause of action for misappropriation of a trade secret related to interstate commerce. A plaintiff must show the information qualifies as a trade secret, that reasonable measures were taken to keep it secret, and that it was acquired, disclosed, or used improperly. Forensics supplies the evidentiary basis for the second and third elements — demonstrating both the access controls actually in place and the mechanics of how the information moved.

Can deleted files be recovered as evidence of theft?

Often, yes — and just as importantly, the act of deletion itself is frequently recoverable even when the content is not. File system records, journal entries, shellbags, link files, and thumbnail caches can establish that a file existed, was accessed, and was removed, along with when. Evidence of targeted deletion after a preservation duty attached is independently significant, since it can support a spoliation argument regardless of whether the underlying content is restored.

Do you work for both plaintiffs and defendants in these matters?

Yes. The same examination that establishes misappropriation can also demonstrate its absence — that files were accessed in the ordinary course, that a device shows no exfiltration path, or that an accusation rests on artifacts that do not support the inference drawn from them. We run conflicts before any engagement, and we do not take a matter where we are serving as a court-appointed neutral.

Ready to discuss your matter?

Submit a case