Source code is among the most sensitive materials a company will ever produce in litigation, and disputes under the Defend Trade Secrets Act (DTSA) frequently turn on how—and how safely—the opposing side gains access to it. The governing tools are Federal Rule of Civil Procedure 34, which authorizes inspection and testing of electronically stored information and tangible things, and 18 U.S.C. § 1836, which supplies the DTSA's civil framework, including its civil-seizure and confidentiality safeguards. This article explains what these authorities require in practice and how a neutral structures a workable inspection protocol.
Rule 34 as the Engine of Inspection
A source-code inspection begins with Rule 34, which allows a party to request to "inspect, copy, test, or sample" designated documents, electronically stored information, or "designated tangible things" in the responding party's possession, custody, or control. Source code, whether treated as ESI or as material stored on a designated device, falls squarely within this reach.
The request must be specific and workable. Rule 34(b)(1) requires that a request "describe with reasonable particularity each item or category of items to be inspected" and "specify a reasonable time, place, and manner for the inspection and for performing the related acts." For source code, this is where the protocol lives: the time, place, and manner terms are the levers through which a court or neutral confines review to a secured environment.
The Advisory Committee recognized long ago that computerized data may require the producing party's own tools to render it usable, noting that "when the data can as a practical matter be made usable by the discovering party only through respondent's devices, respondent may be required to use his devices to translate the data into usable form." That principle supports the common practice of the producing party supplying a controlled review computer.
Protection Against Undue Burden and Disclosure
Rule 34's 1970 revision eliminated the general "good cause" requirement, but the drafters were explicit that sensitivity is still protected elsewhere. The Advisory Committee noted that "Protection may be afforded to claims of privacy or secrecy or of undue burden or expense under what is now Rule 26(c)."
The Committee specifically addressed the risk of exposing a source when a party checks the electronic material itself, observing that "if the discovering party needs to check the electronic source itself, the court may protect respondent with respect to preservation of his records, confidentiality of nondiscoverable matters, and costs." This is the doctrinal foundation for the secured, air-gapped, log-monitored inspection protocols routine in code cases.
In practice, a neutral uses these provisions to build guardrails: a standalone non-networked review machine, restrictions on copying and printing, designation of qualified reviewers bound by a protective order, and cost allocation where the burden of enabling inspection is significant.
The DTSA's Confidentiality Architecture
The DTSA reinforces these protections with its own confidentiality-focused mechanisms. Under 18 U.S.C. § 1836(b), an owner of a misappropriated trade secret "may bring a civil action" where the trade secret relates to a product or service used in interstate or foreign commerce, and the district courts have original jurisdiction over such actions.
Where extraordinary circumstances justify civil seizure, the statute imposes strict handling rules directly relevant to code. Section 1836(b)(2)(D) requires that "Any materials seized under this paragraph shall be taken into the custody of the court," that the court "secure the seized material from physical and electronic access," and, if a storage medium is involved, that the court "prohibit the medium from being connected to a network or the Internet without the consent of both parties."
The statute also demands minimization: the court must "take appropriate measures to protect the confidentiality of seized materials that are unrelated to the trade secret information" ordered seized. These principles—court custody, network isolation, and segregation of unrelated data—translate naturally into inspection protocols even outside the seizure context.
The Special Master and Neutral Expert Role
The DTSA expressly contemplates neutral involvement in handling sensitive materials. Section 1836(b)(2)(D)(iv) provides that "The court may appoint a special master to locate and isolate all misappropriated trade secret information and to facilitate the return of unrelated property and data," and requires that the special master "agree to be bound by a non-disclosure agreement approved by the court."
The statute similarly allows for a neutral technical expert during a seizure, providing that the court "may allow a technical expert who is unaffiliated with the applicant and who is bound by a court-approved non-disclosure agreement to participate" where doing so "will aid the efficient execution of and minimize the burden of the seizure." Notably, the court "may not permit the applicant or any agent of the applicant to participate in the seizure."
These provisions signal a legislative preference for insulating the requesting party from raw access. In source-code disputes, a neutral or court-appointed expert can perform the isolation and filtering that both sides distrust one another to do—identifying responsive code while returning or protecting everything unrelated.
Building a Practical Protocol
Drawing these authorities together, a defensible source-code inspection protocol combines Rule 34's manner-of-inspection controls with the DTSA's confidentiality safeguards. The party seeking inspection should frame requests with reasonable particularity and propose a reasonable time, place, and manner, while the producing party may condition access on secure-environment terms grounded in the protection against disclosure of confidential and nondiscoverable matter.
Where the risk is acute, the statutory model of court custody, network isolation, segregation of unrelated data, and a court-approved non-disclosure agreement supplies a template even absent a seizure order. The burden of justifying access rests with the requesting party, while the producing party bears the burden of substantiating its confidentiality and burden objections.
Because the DTSA also creates "a cause of action" for damage from a "wrongful or excessive seizure," and authorizes security to be posted for such damages, parties have strong incentives to negotiate proportionate, well-bounded inspection terms rather than litigate over-broad access. A neutral's task is to translate these statutory and rule-based protections into an operational protocol that permits meaningful technical review without turning discovery into a second misappropriation.
This article is provided for general informational purposes only and does not constitute legal advice. Engagement of Daniel Garrie as a neutral is administered exclusively through JAMS.