What happened
Applied Systems sells Epic, a management platform that insurance agencies and brokerages use to run sales, policies, billing, and their general ledger. Epic also ships a software development kit that lets customers connect other tools to it.
Access to that development kit is not open. Applied licenses it to its customers, and every license bars the customer from handing it to a third party unless that third party is providing technical services to the customer, signs its own agreement with Applied, and takes on the same confidentiality obligations.
Comulate wanted to build a product that integrated with Epic, which meant it needed exactly the access those terms were written to prevent. So it created a company called PBC Consulting and held PBC out as an insurance agency. PBC signed the license agreements in its own name and obtained Epic and the development kit.
Applied eventually noticed usage patterns that did not look like an insurance agency at work. It traced the activity to PBC, and traced PBC to Comulate. It then sued both for trade secret misappropriation, breach of contract, breach of the implied covenant of good faith and fair dealing, fraudulent misrepresentation, fraudulent inducement, conspiracy, violations of the Computer Fraud and Abuse Act, and unjust enrichment.
What the court did with it
Judge Shah granted the motion to dismiss in part and denied it in part. Surviving the motion:
- Trade secret misappropriation
- Breach of contract, on the theory that the defendants used the access to develop competing products
- Breach of the implied covenant of good faith and fair dealing
- Declaratory judgment
- The Computer Fraud and Abuse Act claim
- Fraud claims framed around obtaining access to Epic
Dismissed without prejudice: breach of confidentiality, unjust enrichment, conspiracy, and the fraud claims framed around the acquisition of the confidential information itself.
That last split is the part worth sitting with. The same course of conduct produced a durable claim and a dismissed one depending on which moment the pleading pointed at. Fraud in getting through the door held up. Fraud described as taking what was inside did not, at least as pleaded.
Why this matters if you run a company
Two things made this case possible, and neither of them is a legal theory.
The license said who could have the keys. Applied had written terms restricting third-party access to its development kit, with specific conditions and a specific approval path. That is what turned Comulate's workaround into a breach rather than an aggressive but lawful business decision. A company that licenses its product broadly, with no restriction on who may be handed the technical interfaces, has far less to work with when someone does this to it.
Somebody was watching how the product was used. Applied did not learn about this from a whistleblower or a press release. It noticed anomalous usage and followed it. Access controls tell you who is supposed to be inside. Monitoring is what tells you who actually is. Without the second, the first is a document nobody ever consults.
There is also a plain lesson about diligence on the other side of the transaction. Applied signed license agreements with an entity that was not what it said it was. Depending on the product and the sensitivity of what a license opens up, some verification of who a new customer actually is may be worth the friction it adds to a sale.
Where the case stands
This is a ruling on a motion to dismiss. The court accepted the allegations in the complaint as true and drew reasonable inferences in Applied's favor, which is what that standard requires. Nothing here is a finding that Comulate did any of it. The dismissed claims were dismissed without prejudice, so Applied may replead them.
What the decision does tell you is which theories are viable enough to make a defendant litigate them, and that is usually the question that governs what a case costs and how it resolves.
Trade secret and unauthorized access cases are evidence races, and they are won or lost in the first days. If you suspect someone has reached your systems or confidential information under false pretenses, or your company has been accused of it, contact Patrick Austermuehle at patrick@auster.law or 630-430-0993. Say that it is urgent and it will be treated that way. More on the firm's work in trade secret litigation.
This note is general information about a published decision, not legal advice, and reading it does not create an attorney-client relationship. Outcomes depend on facts this summary does not cover.
More from the Report
- Two new obligations for Illinois businesses, with two different deadlinesAugust 3, 2026 · Legislative
- The bank sold the collateral cheap, and the personal guarantees evaporatedJuly 30, 2026 · Rule 23 order
- A narrow arbitration clause still swallowed an LLC member's statutory claimsJuly 28, 2026 · Published opinion