Trade Secret Controls Investors Should Review in Indian Startups
Indian startups often describe their moat as technology, but the practical asset may be know-how that is not registered anywhere. Pricing logic, source-code architecture, customer implementation playbooks, model-training methods, manufacturing steps, vendor terms and sales intelligence can carry much of the value behind the product.
For investors, the question is not whether the company uses the phrase trade secret. The question is whether the business can prove that valuable confidential know-how was identified, restricted, shared on enforceable terms and protected when people or partners left.
Why This Matters
Trade secret weakness usually appears late in diligence. A founder says the company owns the product. The data room contains a standard NDA and a few employment templates. But repository logs, consultant contracts, shared drives, customer pilots and employee exits may show a looser reality.
India does not use a single trade secret registration system for startup diligence. Protection is usually built through contract rights, confidentiality practice, copyright where code or documentation is involved, electronic records, access logs and targeted remedies. The Indian Contract Act, 1872 matters because NDAs, employment terms, consulting contracts, founder undertakings, warranties and indemnities are contractual promises. The Copyright Act, 1957 and its Chapter IV ownership provisions matter where software, product documents, technical drawings or written manuals are copyright works. The Information Technology Act, 2000 is relevant to electronic records and computer-related access issues.
The investor risk is practical. If sensitive know-how has been widely shared, poorly marked or held by founders, contractors or affiliates outside the company, the startup may struggle to stop leakage, complete an acquisition, satisfy enterprise customers or support valuation in the next round.
What Counsel Should Review
Start with the know-how inventory. Counsel should ask the company to list the confidential assets that drive value: code architecture, algorithms, internal tools, training materials, product roadmaps, pricing models, customer lists, partner terms, manufacturing steps and implementation playbooks. Each item should be mapped to the business unit, creator group, storage location, access population and revenue relevance.
Next, test the contract stack against that inventory. Founder agreements, employment contracts, consultant terms, agency statements of work, vendor documents, customer pilot terms, investor disclosures and joint-development arrangements should be reviewed for confidentiality scope, permitted use, assignment, return or deletion duties, survival periods, audit rights and remedies. Generic NDA language is helpful only if it actually covers the material that creates value.
Access governance is the second track. Investors should ask whether sensitive folders and repositories are role-based, whether external collaborators have time-limited access, whether production credentials are separated from development access, and whether the company can show when rights were granted and revoked. A strong clause with weak access records is still a diligence issue.
Employee and contractor exits need special attention. The company should have a checklist for account closure, device return, repository removal, deletion certification, reminder notices and investigation of unusual downloads. If a founder, engineer, sales lead or agency left with critical know-how, counsel should identify whether the company has confirmatory undertakings or a realistic remediation plan.
Finally, connect trade secret controls to deal documents. Subscription, share purchase or asset purchase documents should not rely on a broad statement that all confidential information is protected. Disclosure schedules should identify sensitive know-how, unresolved contributors, third-party restrictions, prior leaks, former personnel with access, customer-specific limits and any closing actions needed before funds move.
Typical Timeline and Cost Range
A focused review for one product line can often be completed in 7 to 14 business days once contracts, access lists, repository records and exit files are ready. A wider review across multiple products, contractors, agencies and recent departures may take 3 to 5 weeks.
The efficient sequence is triage first, remediation second. Investors should identify the high-value know-how, test whether the company controls it, then decide which gaps require confirmatory assignments, revised confidentiality terms, access cleanup, escrow, closing conditions or specific indemnity support.
Common Mistakes
- Treating an NDA as the whole control system. Confidentiality terms should match the specific know-how, sharing channels and people who handled it.
- Ignoring access evidence. Investors need logs, repository permissions, drive records and exit files, not only signed templates.
- Leaving contractor-created know-how outside the company. Agencies and freelancers often touch valuable material, so their terms and delivery records need close review.
How KAS & Co. Can Help
KAS & Co. helps investors and Indian technology companies review trade secret controls, confidentiality terms, access records, contractor exposure, employee exits and closing remediation before funding or acquisition. For a focused trade secret control review, contact KAS & Co..
FAQs
1. Are trade secrets registered in India?
No. Startup trade secret protection is usually built through contracts, access controls, evidence of confidentiality practice, copyright where applicable and remedies based on the facts.
2. What should an investor request first?
Ask for a know-how inventory, NDAs, employment and contractor agreements, repository and folder access lists, customer pilot terms, exit checklists and any prior leak or dispute records.
3. Can weak trade secret controls be fixed before closing?
Many gaps can be improved through confirmatory undertakings, revised contractor terms, access cleanup, deletion certificates and targeted disclosures. Core leakage or ownership gaps may need closing conditions.
4. How is this different from source code ownership review?
Source code ownership asks who owns and can transfer the code. Trade secret control review asks whether valuable confidential know-how has been identified, restricted, monitored and protected from leakage.
Sources
Topics
Need legal advice on this topic?
KAS & Co. provides strategic legal counsel across technology law, data privacy, IP and commercial advisory.
Schedule a Consultation