Recommended Free Tools
Build a dated, source-linked record that identifies the claimed trade secret, shows how it was kept secret, and distinguishes system access from acquisition, disclosure, or use. An access log can support an investigation, but by itself it does not establish that a person learned, copied, disclosed, or used a trade secret. Preserve relevant electronically stored information (ESI) through reasonable steps and plan how to protect confidential material in the litigation record.
This is a general U.S. federal framework based on the Defend Trade Secrets Act (DTSA) and the Federal Rules of Civil Procedure. State law, local rules, court orders, discovery agreements, and case-specific facts may change what is required; have counsel determine the governing law and procedure.
What the record needs to establish
Under the DTSA, information qualifies as a trade secret only if its owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known or readily ascertainable. The statute covers information in many forms, but a litigation record should identify the particular information at issue rather than rely on a broad label such as a customer database, formula, or source code. See 18 U.S.C. § 1839.
Misappropriation is not synonymous with access. The DTSA addresses acquisition by improper means, as well as disclosure or use under specified circumstances involving knowledge that the information was a trade secret and was acquired through improper means or subject to a duty to maintain secrecy or limit use. It excludes lawful means such as independent derivation and reverse engineering from improper means. See 18 U.S.C. § 1839.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
- Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
- Rugged Double-Layer Waterproof* Design - Protects the crypto drive against knocks, drops, break-in and submerging in water. The electronics are shielded by a hardended inner case. The rubberised silicone outer casing provides a final layer of protection
- Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
- Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
- Identity: What specific information is claimed to be secret, and which version or portion is at issue?
- Secrecy measures: What steps were taken to restrict access or use, and how did those steps work in practice?
- Event: What evidence supports acquisition, disclosure, or use, separately from the fact that an account could access a system?
- Knowledge or duty: What evidence bears on what the person knew about the information, its source, or an obligation to keep it confidential or limit its use?
- Alternative explanations: Is there evidence of ordinary authorized work, independent development, lawful reverse engineering, or another explanation?
Keep each proposition tied to its own evidence. Do not describe an inference from a login as direct proof of what a person saw or did.
Define the asserted secret and document secrecy controls
Assign a stable identifier to each asserted secret or coherent set of information. Create a controlled description detailed enough to distinguish it from public information, general skill or knowledge, and independently developed material. Use the same identifier and description consistently in pleadings, discovery responses, declarations, and expert work. Counsel should assess how much detail can safely appear in public filings.
Preserve dated evidence of the measures used to protect the information. Depending on the facts, that may include confidentiality labels, access-control policies, role permissions, training records, nondisclosure agreements, limited-use agreements, and records showing how permissions were granted and enforced. No single label, policy, or contract is specified by the DTSA as sufficient on its own; the question is whether the measures were reasonable in context.
Rank #2
- Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
- Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
- Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
- Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
- SuperSpeed USB 3.0 - Transfer all your confidential files and folders faster than ever before. Works on both PC & Mac
Map people, accounts, systems, and permissions
Make a custodian and system map for the relevant period. Include likely repositories and the people or administrators who can explain them. A map helps distinguish what a named person could access from what an account, device, or automated process recorded.
- Employees, contractors, vendors, and other relevant custodians, including role changes.
- Named accounts, shared accounts, service accounts, and devices, with access grants and revocations, dates, and approvers where available.
- Repositories and platforms such as file shares, collaboration tools, source-code or design systems, cloud storage, removable media, and relevant backups.
- Audit logs and other records that may show viewing, downloading, printing, exporting, sharing, or later activity.
State the limits of attribution. A record may identify an account without establishing who used it, or a device without showing which person was present. Document what supports person-to-account attribution and what remains uncertain.
Preserve and collect ESI with its context
Identify potentially relevant ESI early, including systems with short retention windows, cloud services, devices, communications, audit logs, document histories, and third-party records within the party’s control. Work with counsel to assess the scope and proportionality of preservation and collection for the matter.
Rank #3
- Certified to FIPS 197 - U.S. Government Approved High Level Information Security Standard.
- Protection against brute force password attacks - Data is automatically erased after 6 unsuccessful access attempts. The data of the USB flash drive type c encryption with dual connectors is destroyed and the cryptographic drive is reset.
- Durable dual-layer waterproof design* — Protects the crypto reader from bumps, drops, run-in and immersion in water. The electronics are protected by a hardened internal case. Rubberized silicone outer case provides a final layer of protection.
- Auto-Lock —The cryptographic key automatically encrypts all data and locks when removed from a PC/Mac or when screen protection or "computer lock" is enabled.
- Secure Entry —Data on these flash drives cannot be accessed without the correct alphanumeric password of 8 to 16 characters. A password indication option is available for this flash drive. The hint cannot match the password.
For each source, record its owner or administrator, retention schedule, time zone and clock configuration if known, collection method, collection date, collector, and custody transfers. Preserve unaltered source material where feasible. Keep working copies and document filtering, conversion, export, or other transformations so the path from source to exhibit can be explained. Record gaps and whether missing information may be restored or replaced.
Federal Rule of Civil Procedure 37(e) concerns ESI that should have been preserved in anticipation or conduct of litigation, was lost because reasonable steps were not taken, and cannot be restored or replaced through additional discovery. A court may order measures no greater than necessary to cure prejudice. The more severe listed measures, including an adverse inference or case-ending measures, require a finding that a party acted with the intent to deprive another party of the information’s use in litigation. Loss does not automatically produce an adverse inference.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsThe committee note to the 2015 amendment explains: “This rule recognizes that ‘reasonable steps’ to preserve suffice; it does not call for perfection.” Reasonable preservation is not a guarantee that every source will be collected or every event logged. The note also emphasizes familiarity with client information systems, proportionality, and considering whether a lower-cost preservation approach can be substantially as effective.
Rank #4
- FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
- Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
- Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
- New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
- Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed
Build an auditable event chronology
Use one row per event or factual proposition, and preserve a reference to the underlying native record. A chronology should make it possible for another reviewer to understand what happened, when, how the record was obtained, and how strong the inference is.
- Asserted-secret identifier and relevant version.
- Person, account, device, and role, with attribution evidence and limitations.
- Event date and time, including time zone and any known clock uncertainty.
- Source system and location of the native record.
- Event type, such as a permission change, view, download, transfer, external share, disclosure, or later use.
- Evidence bearing on knowledge, confidentiality obligations, limited-use duties, or notice.
- Corroborating and contrary evidence, including plausible alternative explanations.
- Preservation and collection status, plus the custodian, witness, or exhibit needed to authenticate or explain the record.
Do not combine distinct events into a single conclusion. For example, record a permission grant as a permission grant, a download as a download, and evidence of subsequent use as a separate proposition. A technical event may support an inference, but the chronology should show what it does and does not prove.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Track gaps and competing explanations
Maintain a gap log alongside the chronology. Note missing logs, expired retention periods, shared credentials, clock drift, incomplete attribution, or sources that have not yet been collected. Flag evidence that could support an innocent or lawful explanation, including routine business access, independent development, or lawful reverse engineering.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- FIPS 140-3 Level 3 (Pending) Certified Military-Grade Security
- OS/Device Independent
- XTS-AES Hardware Encryption
- Enforced Alphanumeric PIN
- Multi-PIN (Admin and User) Option
This is useful for both investigation and presentation. Counsel can prioritize additional discovery, consider whether missing information can be restored or replaced, and avoid presenting an inference as direct proof. For a responding party, the same disciplined review can identify records that contextualize access and correct an incomplete account.
Protect the secret during discovery
Plan confidentiality protections with counsel before producing or filing sensitive material. Options may include a protective order, access tiers, redactions, secure transfer, restricted access, and sealing where authorized by the court and applicable rules. Consider how to handle unrelated personal, privileged, or third-party information that appears in a forensic collection.
DTSA § 1835 directs courts to take appropriate action to preserve the confidentiality of trade secrets in proceedings under the chapter, consistent with applicable procedural and evidence rules. The statute does not prescribe one universal protective-order form. A DTSA seizure application is an extraordinary remedy subject to specific statutory findings and safeguards, not a routine substitute for preservation or discovery planning. See 18 U.S.C. § 1836.
Choose documentation methods by what they can show
No particular tool or collection method is mandated for every trade-secret dispute. Compare available methods against the case’s needs rather than treating a product or technical standard as universally required.
- Coverage: Which systems, users, dates, and event types does the method capture?
- Attribution: Does it identify a person, an account, a device, or only a process?
- Integrity and reproducibility: Can the collection and any transformations be explained and, where appropriate, repeated?
- Retention and recoverability: What may be overwritten, and can missing material be restored or replaced?
- Confidentiality: Can unrelated personal, privileged, or third-party information be protected?
- Proportionality and cost: Is the approach adequate in light of the dispute’s importance, resources, and available alternatives?
These are practical questions for planning and review, not a statutory checklist. Rule 37(e) and its committee note focus on reasonable preservation steps, proportionality, and restoration or replacement.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




