Acquisition, disclosure or use — each proved differently, and mostly from artefacts with a short and unattended lifespan.
Start a conversation with the IP Concierge, already scoped to misappropriation evidence. Pick a starting point, or describe the matter directly.
Misappropriation has to be shown, and the showing is largely forensic. Broadly, it means acquiring the information by improper means, or disclosing or using it without consent by someone who owed a duty of confidence. Each route has a different evidentiary shape: acquisition tends to live in device and access artefacts, disclosure in communications, and use in the comparison between the secret and what the defendant built. The material that answers these questions is unusually perishable, not because anyone destroys it deliberately but because reimaging a returned laptop and closing a departed employee's mailbox are routine tasks that happen on a schedule. By the time a suspicion becomes a decision to investigate, the record is often already gone.
The sources, roughly in order of how often they decide matters.
Records of what was connected and when, frequently surviving on the endpoint even where the device itself is long gone.
Consumer storage clients, personal webmail and shared links, which is where most modern exfiltration happens.
Rules quietly configured, and the ordinary pattern of sending work to a personal address.
Unusual volume, unusual breadth, or access to material outside the person’s normal work, especially in the final weeks.
Evidence of cleanup, which often proves more than what was deleted would have.
Whether the defendant’s code, design or process actually reflects the secret — including the tell-tale carry-over of errors and idiosyncrasies.
What competent forensic work looks like here.
Liability, and the credibility of everyone involved.
Pull the departing employee’s devices out of the reimaging queue, suspend deletion of their mailbox and accounts, and capture badge, VPN and file access logs now. None of this is reversible later, all of it takes an afternoon, and every part of it is routinely destroyed by people doing their jobs correctly.
Preserve, before investigating and well before deciding whether to act. Take the laptop and phone out of the reimaging queue and have them forensically imaged; suspend automatic deletion on the mailbox and accounts rather than closing them; and pull badge, VPN, file access and email logs for the preceding several months. Examining the device yourself before it is imaged is the common own goal — it alters timestamps and hands the other side an argument about the integrity of the evidence.
It proves acquisition, which is often enough to matter and is not the whole claim. Employees copy files for entirely mundane reasons, including working from home and keeping portfolio material, and defendants say so credibly. What strengthens the inference is pattern rather than the act: breadth beyond the person’s role, timing that tracks the resignation, material of no conceivable personal use, and deletion activity afterward.
On its own evidence, and it is a complete defense when it holds. The question is whether the defendant’s development record — dated design documents, version control history, test results, procurement — shows a path to the result that does not require the secret. A rich contemporaneous record is very persuasive. A thin one, or one that begins abruptly after the hire, is where the comparison analysis does its work: independent developers do not reproduce another organization’s mistakes.
That raises exposure for the new employer and a set of practical questions best put to counsel immediately, because the sensible responses — quarantine, forensic examination, sometimes voluntary disclosure — are time-sensitive and interact with privilege. On the technical side, the useful work is establishing precisely what arrived, where it went, and whether it was actually used or merely sat unopened in a folder. Those are very different findings and they are distinguishable from the artefacts.
Describe the departure and what you suspect. The Institute will help you triage what is at risk of being lost.