Copyright registration for software with trade secrets: preparing the source-code deposit

Alex Solo
byAlex Solo12 min read

When a software company gets ready to register copyright in a program, one of the biggest practical questions is not whether code exists, but what exactly should be deposited with the U.S. Copyright Office without handing over more confidential material than necessary. Founders and engineering leads often mix up three separate ideas: the government deposit for copyright registration, a private source code escrow arrangement, and internal repository access. They are not the same thing, and treating them as interchangeable can create avoidable risk.

For most teams, the right starting point is to identify the exact version being registered, decide whether the deposit will follow the ordinary source code route or a confidential material route, and prepare redactions in a way the Copyright Office actually recognizes. Choose the permitted deposit for the actual program; neither an excerpt nor a full repository is always right. This article focuses on the federal electronic deposit rules for computer programs and the practical handover steps that help a business prepare its registration packet. It is general information only and is not legal advice.

Choosing the deposit route for confidential software

First check whether electronic submission is available. The Copyright Office's electronic-copy guidance covers unpublished works and works published only in electronic form, with certain exceptions for works published in hardcopy formats. A program outside those routes may require a hardcopy deposit; an online application does not itself settle the deposit-format question.

The core decision is whether your deposit can be submitted using the standard source code excerpt, or whether you need one of the special options for trade secret or other confidential material.

For a new computer program, the ordinary electronic deposit is generally the first 25 and last 25 pages of the source code, or equivalent units if the program is not naturally organized into pages. If the program has no clear beginning or end, the applicant decides which portions reasonably represent the first and last 25 pages.

There is an important size limit: for a program of 50 pages or less, the ordinary deposit is the entire source code. The regulation also provides a separate entire-source-code route for short programs containing trade secrets, with permitted blocking and the requirements described below. Do not assume an excerpt-only approach fits every program. That baseline matters because the confidential material routes have specific formats. They are not permission to strip out everything sensitive or to replace the deposit with a general summary.

Just as important, a Copyright Office deposit is not the same as a private source code escrow deposit. An escrow arrangement is a private commercial tool that may control release conditions between parties such as a vendor and customer. A copyright deposit is part of a federal registration process. Sending material to one does not satisfy the function of the other.

A common internal mistake is for a product team to assume that because code is proprietary, the safest approach is to upload an entire repository under a confidentiality label. That is usually the wrong instinct. The registration rules are built around limited identifying material, and when confidential material is involved, the Office provides specific deposit options instead of asking for a full codebase by default.

What counts as source code, object code, and equivalent units?

The Copyright Office distinguishes between source code and object code.

Source code is the code as actually written by the author in a programming language. Object code is generally the compiled machine-readable representation of that program, such as hexadecimal, octal, or binary output.

That distinction matters because some deposit options require source code, some allow a combination of object code and source code, and object code alone has its own separate rule.

If your program is not laid out in pages, the Office leaves the determination of equivalent units to the applicant. The Office gives a rule of thumb that 40 lines of code may be treated as a page, so the first 1000 and last 1000 lines may be acceptable as the ordinary new-program deposit. That 40-line approach is a practical guide, not a strict statutory formula.

For engineering teams, this is usually a formatting task as much as a legal one. Someone needs to export the selected code into a readable deposit file, preserve line breaks consistently, and avoid accidental omission of the part containing the copyright notice if the program includes one. If the codebase is split across many modules, the team should decide how the selected excerpt will be assembled so the deposit reflects one coherent version rather than a random mix from different branches.

For example, imagine a SaaS company preparing a deposit from a monorepo that includes backend services, deployment scripts, mobile code, and archived experiments. The practical question is not which files are most impressive. It is which files correspond to the version of the computer program being registered and how to convert that version into the required pages or equivalent units in a consistent way.

What are the accepted confidential material deposit options?

When a program contains trade secret or other confidential material, the Copyright Office allows specific alternatives.

For a program containing confidential material, the electronic copy may consist of:

  • the first 10 and last 10 pages of source code, with no blocked-out portions; or
  • the first 25 and last 25 pages of object code together with 10 or more consecutive pages of source code with no blocked-out portions; or
  • the first 25 and last 25 pages of source code with the portions containing trade secrets blocked out; or
  • for programs of 50 pages or fewer, or equivalent units, the entire source code with trade-secret portions blocked out. For this and the other blocked-out route, the blocked portions must be proportionately less than what remains, and an appreciable amount of original computer code must remain visible.

These are the specified trade-secret identifying-material routes for the programs covered by the regulation, not a license to invent a custom extract. If a business wants to protect confidential material while still making a deposit, it should work within one of these structures rather than inventing a custom partial extract and hoping it will be accepted.

The combined object-code-and-source-code option can be useful where the business wants to limit disclosure of readable source code but still provide the required identifying material. The blocked-out source code option can work where the opening and closing pages are the right deposit but particular algorithms, logic, credentials, or implementation details need to be obscured.

What the rules do not say is just as important. They do not say that the first 10 and last 10 source pages may be submitted under that route with further redactions added automatically. They also do not say that all code can be removed so long as headings remain. If you choose a blocked-out route, the blocked material must still leave enough unblocked material to satisfy the proportionality rule discussed below.

A simple example helps. Suppose a startup has a payment optimization engine and the most sensitive logic appears in several functions inside the last 25 pages of the chosen excerpt. The team may be able to use the first 25 and last 25 pages of source code with those confidential portions blocked out. By contrast, if the team wants to use the first 10 and last 10 source pages route, it should not assume that this automatically authorizes further redactions beyond what that route itself states.

How much can you redact, and how should deletions be shown?

The Copyright Office says that in any copy option where portions of code are blocked out, the blocked-out portions must be proportionately less than the material remaining. The computer-program deposit regulation also requires the deposit to reveal an appreciable amount of original computer code. A numerical comparison alone is not enough: the remaining material must still reveal original code.

That requirement is easy to overlook when a team starts with a heavily sensitive code sample. If most of the selected pages would be blacked out, you probably need to revisit the deposit choice rather than pushing forward with a document that is mostly redaction bars.

The Office recommends two methods for blocking out or deleting confidential material:

  • replace deleted characters with XXXXXs or blank spaces; or
  • delete the characters and the lines on which they appear, then insert a statement at each deletion showing the location and amount deleted because of trade secret or confidential material.

The second method can be especially useful when a larger segment is removed, because it shows where the deletion occurred and how much text was omitted. That can make the deposit easier to follow than a page crowded with scattered masking.

The Office also allows applicants facing hardship with those methods to propose another method for consideration. That is not automatic approval for any redaction style your team prefers. It simply means alternatives may be considered.

Two practical points often help here. First, prepare a redaction log for internal use, even if it is not part of the deposit itself. The log can record which files, line ranges, and reasons were used for each deletion. Second, keep the deposited copy distinct from your unredacted internal archive, so no one accidentally uploads the wrong file at the final step.

Businesses should also avoid overpromising internally about what the deposit does for secrecy. A blocked-out deposit may reduce unnecessary disclosure, but it does not mean the government is acting as your NDA counterparty, and it should not be described inside the company as guaranteed trade secret protection. Separate confidentiality controls, access restrictions, and contracts still matter.

How do revised programs change the deposit?

A revised program follows a different path from a new program, so version selection matters.

For a revised computer program where the revisions occur throughout the entire program, the first 25 pages and last 25 pages will generally suffice. If the revisions do not occur in the first 25 and last 25 pages, the electronic copy should consist of any 50 pages representative of the revised material. The copy should include the portion containing the copyright notice, if any.

Where confidential material is involved and the revisions are not contained in the first 25 and last 25 pages, the electronic copy may consist of either 20 pages of source code representative of the revised material with no blocked-out portions, or 50 representative pages with trade-secret portions blocked out. For the blocked-out route, those portions must be proportionately less than what remains, and the deposit must reveal an appreciable amount of original computer code.

This is where engineering handover discipline matters. The team preparing the deposit should identify:

  • the exact release, branch, or commit representing the version being registered;
  • whether the changes appear throughout the program or in limited locations;
  • which selected pages actually show the revised material; and
  • whether any chosen pages contain confidential content requiring a permitted confidential route.

For example, assume version 4.2 of a platform adds changes across authentication, reporting, and API throttling in many modules. If those revisions are spread throughout the program, the first 25 and last 25 pages may work for the revised-program deposit. If instead the meaningful revisions are concentrated in a scheduler module and a billing service that do not appear in the first or last 25 pages, a representative 50-page selection of revised material may be more accurate.

If confidential revisions are outside the start and end portions, the 20-page representative source code route or the 50-page blocked-out representative route may become the better fit. The point is to match the deposit to the actual location of the revised material rather than forcing a familiar template.

What should the engineering handover package contain before anyone files?

Before the registration packet is handed to an independent U.S. professional, the business should be able to explain exactly what has been selected and why. This is usually where avoidable errors are caught.

A practical handover package often includes:

  • the product name and internal version tag;
  • whether the submission is for a new program or a revised program;
  • the selected deposit route, such as ordinary first 25 and last 25 source pages, confidential first 10 and last 10 source pages, or a revised-program representative selection;
  • the files or modules used to generate the deposit pages or equivalent units;
  • the locations of any changes being relied on for a revised program;
  • confirmation that the portion displaying a copyright notice, if any, has been included;
  • a copy of the deposited file in the exact form intended for upload; and
  • an internal record of any redactions or deletions applied.

This package should not claim more than the team actually knows. For example, the engineering lead can identify contributors and collect the company's ownership records for the selected files, but should not casually label third-party licensed components as the company's own code. The same goes for eligibility questions. The handover can describe what version is being deposited and where revisions appear, without declaring that all human authorship issues, open source license questions, or IP assignment issues have already been resolved.

That restraint matters because the deposit is only one part of the larger registration picture. If a company acquired code from contractors, inherited modules from a prior venture, or combined internal code with significant third-party materials, the filing strategy may need a separate legal assessment.

Frequently Asked Questions

Do we need to deposit our full repository?

Do not assume that either a full repository or an excerpt is always correct. The ordinary short-program rule requires the entire source code for programs of 50 pages or less; longer programs and trade-secret material have specific deposit options. Select the route for the actual program before exporting files.

Can we just blank out every sensitive function?

No. If you use a blocked-out option, the blocked portions must be proportionately less than the material remaining. An appreciable amount of original computer code must remain visible.

Can we use 40 lines per page for every codebase?

The Copyright Office gives 40 lines of code as a rule of thumb for equivalent units. It is practical guidance, not a rigid formula, so the applicant still needs a sensible and consistent approach.

What if our code has no obvious beginning or end?

The applicant may determine which portions reasonably represent the first 25 and last 25 pages. That decision should be documented internally so the handover package is clear and consistent.

Does a confidential deposit guarantee trade secret protection?

No. A confidential-material deposit route may help limit what is submitted, but it is not a guarantee of trade secret status, NDA protection, or any broader secrecy outcome.

Key Takeaways

  • Check electronic-copy eligibility first. For a new program, the ordinary identifying-material deposit is generally the first and last 25 source-code pages or equivalent units; for programs of 50 pages or less it is the entire source code. Include the copyright notice portion, if any.
  • When confidential material is involved, use one of the specific Copyright Office routes rather than uploading a full repository or inventing a custom extract.
  • Blocked-out code must be proportionately less than the material remaining, and deletions should be shown using an accepted method such as XXXXXs, blank spaces, or a deletion statement.
  • Revised programs have different deposit rules, so the selected pages must accurately reflect where the revisions appear.
  • A Copyright Office deposit is different from private source code escrow, and neither should be treated as a substitute for the other.
  • Before filing, prepare a clean handover showing the exact version, deposit route, selected pages, and any redactions used.

For support organising ownership records or preparing IP assignment, confidentiality and software licensing documents, get started through the Sprintlaw platform. Sprintlaw Tech LLC is not a law firm and does not provide legal advice or Copyright Office filing services. A qualified independent US attorney should assess deposit eligibility and filing strategy. Call (888) 449-8437 or email team@sprintlaw.com.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw's co-founder and a legal technology leader. He holds law and media degrees from the University of Sydney and has been recognized by Australasian Lawyer, Lawyers Weekly and the Sydney Young Entrepreneur Awards for his work building Sprintlaw and improving access to business legal support.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Keep reading

Related Articles

Shipping GPLv3 Software: Prepare The Matching Source-Code Handover

Shipping GPLv3 Software: Prepare The Matching Source-Code Handover

Shipping GPLv3 software in object-code form usually means choosing the right Section 6 source-delivery route and preparing the exact Corresponding Source for that release, not just posting a generic repository link.

Oct 9, 2026
Read more
Repairing Equipment With Embedded Software: The Limits On Temporary Copies

Repairing Equipment With Embedded Software: The Limits On Temporary Copies

Federal copyright law can allow narrow temporary software copies during equipment maintenance or repair, but section 117(c) has strict conditions on activation, use, access, and immediate destruction.

Oct 8, 2026
Read more
Special handling for copyright registration: when expedited processing fits

Special handling for copyright registration: when expedited processing fits

Assess Copyright Office special handling grounds, request documentation and timing limits before relying on expedited registration processing.

Oct 8, 2026
Read more
Training materials: client rights, source files and reusable content

Training materials: client rights, source files and reusable content

Separate copyright, editable project files and reusable materials when commissioning a corporate course; agree client permissions, source-file delivery and creator rights.

Oct 8, 2026
Read more
Using A Certification Mark: Put The Approved Claim And Permission In Writing

Using A Certification Mark: Put The Approved Claim And Permission In Writing

If you want to use someone else’s certification mark, do not assume a logo file or supplier certificate is enough. The key is to confirm what is actually certified, whether your business has permission, and which products, services, channels, and claims are approved.

Oct 7, 2026
Read more
Missed A US Patent Maintenance Fee? Check Whether Reinstatement Is Needed

Missed A US Patent Maintenance Fee? Check Whether Reinstatement Is Needed

Missing a US patent maintenance fee does not always mean the patent has expired. The first step is to confirm whether the patent is still in a payment or grace window or whether a separate reinstatement petition may be needed.

Oct 7, 2026
Read more
Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.