DCT
1:26-cv-00077
Kaseya US LLC v. Project Orca Inc
Key Events
Amended Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Case Name: Kaseya US LLC, et al. v. Project Orca, Inc.
- Parties & Counsel:
- Plaintiff: Kaseya US LLC (Delaware), Kaseya Limited (Ireland), and Datto, LLC (Delaware)
- Defendant: Project Orca, Inc. d/b/a Slide (Delaware)
- Plaintiff’s Counsel: Farnan LLP
- Case Identification: 1:26-cv-00077, D. Del., 07/29/2026
- Venue Allegations: Venue is alleged as proper in the District of Delaware because the Defendant is a Delaware corporation and thus resides in the district.
- Core Dispute: Plaintiffs allege that Defendant’s business continuity and disaster recovery (BCDR) products infringe on thirteen U.S. patents related to data backup, replication, restoration, and remote system management.
- Technical Context: The technology at issue is in the field of BCDR solutions, a critical market for managed service providers (MSPs) who rely on these tools to protect client data and ensure operational uptime after system failures.
- Key Procedural History: The complaint alleges that Defendant, Slide, was founded by two former executives of Plaintiff Datto, which was acquired by Plaintiff Kaseya in 2022. Several asserted patents were originally assigned to Datto, and one of the named inventors on two of those patents is now Slide's Chief Technology Officer. Slide launched its competing BCDR products in February 2025 after operating in "stealth" for two years. These facts are presented to support allegations of knowledge and willful infringement.
Case Timeline
| Date | Event |
|---|---|
| 2007-01-01 | Datto founded by Austin McChord and Michael Fass (approximate date) |
| 2009-05-20 | Priority Date for ’216, ’906, ’304, ’863 Patents |
| 2010-04-12 | Priority Date for ’862 Patent |
| 2013-05-07 | U.S. Patent No. 8,438,216 ('216 Patent) Issued |
| 2014-03-25 | U.S. Patent No. 8,682,862 ('862 Patent) Issued |
| 2014-05-30 | Priority Date for ’636, ’424, ’057 Patents |
| 2014-07-01 | U.S. Patent No. 8,769,039 ('039 Patent) Issued |
| 2014-09-30 | U.S. Patent No. 8,849,906 ('906 Patent) Issued |
| 2016-02-09 | U.S. Patent No. 9,256,499 ('499 Patent) Issued |
| 2017-02-28 | U.S. Patent No. 9,582,304 ('304 Patent) Issued |
| 2017-03-14 | U.S. Patent No. 9,594,636 ('636 Patent) Issued |
| 2017-12-01 | Datto acquired by Vista Equity Partners (approximate date) |
| 2018-03-20 | U.S. Patent No. 9,921,863 ('863 Patent) Issued |
| 2018-06-01 | Priority Date for ’442 Patent |
| 2018-07-23 | Priority Date for ’688 Patent |
| 2018-08-21 | U.S. Patent No. 10,055,424 ('424 Patent) Issued |
| 2019-12-24 | U.S. Patent No. 10,515,057 ('057 Patent) Issued |
| 2020-10-01 | Datto becomes a public company via IPO (approximate date) |
| 2020-10-06 | U.S. Patent No. 10,795,688 ('688 Patent) Issued |
| 2020-12-08 | U.S. Patent No. 10,860,442 ('442 Patent) Issued |
| 2021-08-23 | Priority Date for ’907 Patent |
| 2022-06-01 | Kaseya acquires Datto (approximate date) |
| 2023-10-03 | U.S. Patent No. 11,775,907 ('907 Patent) Issued |
| 2025-02-01 | Slide publicly launches its products (approximate date) |
| 2025-10-06 | Alleged date of Defendant's knowledge of certain patents |
| 2026-07-29 | Amended Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 8,769,039 - "Method and Apparatus of Performing Remote Computer File Exchange"
- Patent Identification: U.S. Patent No. 8,769,039, titled “Method and Apparatus of Performing Remote Computer File Exchange,” issued on July 1, 2014 (Compl. ¶23).
The Invention Explained
- Problem Addressed: The complaint characterizes the invention as addressing inefficiencies in data transfer performance, particularly in client-server applications (Compl. ¶23).
- The Patented Solution: The patent proposes a method for exchanging data between two computers by first establishing a "control channel" to optimize and negotiate the transfer, then establishing a separate "data channel" for the actual data, and finally transferring the data and control information in parallel (Compl. ¶23). This separation of control and data planes is intended to enhance performance and efficiency (Compl. ¶23).
- Technical Importance: This approach aims to improve the speed and reliability of large-scale data transfers, which is a foundational element of backup and replication systems.
Key Claims at a Glance
- The complaint asserts at least Claim 1 (Compl. ¶45).
- The essential elements of independent Claim 1 include:
- A method of exchanging data between a first computing device and a second computing device.
- Establishing a control channel between the devices to exchange control information, including initiation and termination times for data streaming.
- The control information further comprises a proposed data rate and/or a proposed data compression level.
- Negotiating a data transfer between the devices.
- Establishing a data channel between the devices to transfer data.
- Transferring data over the data channel in parallel with the control information being transferred over the control channel (Compl. ¶51).
U.S. Patent No. 9,256,499 - "Method and Apparatus of Securely Processing Data for File Backup, De-duplication, and Restoration"
- Patent Identification: U.S. Patent No. 9,256,499, titled “Method and Apparatus of Securely Processing Data for File Backup, De-duplication, and Restoration,” issued on February 9, 2016 (Compl. ¶24).
The Invention Explained
- Problem Addressed: The patent is directed to problems that arise when accessing data from a de-duplicated computer backup, including the risk of data loss, integrity loss, malicious attacks, and unauthorized access (Compl. ¶24).
- The Patented Solution: The patented solution uses "link files" to access de-duplicated data. When a user requests a file that has been de-duplicated, instead of the file itself, they retrieve a link file. This link file contains a uniform resource identifier (URI) pointing to the single source file, along with an encryption key that is itself encrypted using a "shared secret" previously exchanged between the agent and server (Compl. ¶24). This provides a secure method for reconstructing or accessing a file from its de-duplicated source.
- Technical Importance: This method provides a secure way to restore individual files from a de-duplicated backup store without exposing the raw backup data or compromising the storage system's efficiency.
Key Claims at a Glance
- The complaint asserts at least Claim 1 (Compl. ¶67).
- The essential elements of independent Claim 1 include:
- A method comprising retrieving a data file to be restored from a data storage location.
- Determining the data file is a "link file" which stores metadata comprising a URI of a repository source file and a key that is encrypted with a previously exchanged "agent and server shared secret."
- Decrypting the key from the link file using the shared secret.
- Retrieving data from the repository location using the decrypted key (Compl. ¶73).
U.S. Patent No. 9,594,636 - "Management of Data Replication and Storage Apparatuses, Methods and Systems"
- Patent Identification: U.S. Patent No. 9,594,636, “Management of Data Replication and Storage Apparatuses, Methods and Systems,” issued March 14, 2017 (Compl. ¶25).
- Technology Synopsis: The patent is directed to improving the reliability and management of computer data backups. It describes a system comprising a first filesystem host, a backup aggregator, a master server, and a second filesystem host that coordinate to capture, store, and replicate a snapshot to ensure redundancy and mitigate data loss (Compl. ¶25).
- Asserted Claims: At least Claim 1 (Compl. ¶89).
- Accused Features: The Slide Products and Services are accused of infringing by managing the storage and replication of disk images from the Slide Box (a local appliance) to the Slide Cloud (Compl. ¶97).
U.S. Patent No. 10,055,424 - "Management of Data Replication and Storage Apparatuses, Methods and Systems"
- Patent Identification: U.S. Patent No. 10,055,424, “Management of Data Replication and Storage Apparatuses, Methods and Systems,” issued August 21, 2018 (Compl. ¶26).
- Technology Synopsis: The technology is substantially similar to the '636 Patent, directed to improving the reliability of computer data backups through a coordinated system of a filesystem host, backup aggregator, master server, and second filesystem host for snapshot capture, storage, and replication (Compl. ¶26).
- Asserted Claims: At least Claim 1 (Compl. ¶115).
- Accused Features: The Slide Products and Services are accused of infringing by managing the storage and replication of data sets between the local Slide Box and the remote Slide Cloud (Compl. ¶123).
U.S. Patent No. 10,515,057 - "Management of Data Replication and Storage Apparatuses, Methods and Systems"
- Patent Identification: U.S. Patent No. 10,515,057, “Management of Data Replication and Storage Apparatuses, Methods and Systems,” issued December 24, 2019 (Compl. ¶27).
- Technology Synopsis: The technology is substantially similar to the '636 and '424 Patents, directed to a system for improving data backup reliability via a coordinated process of snapshot capture, storage, and replication across multiple devices (Compl. ¶27).
- Asserted Claims: At least Claim 1 (Compl. ¶140).
- Accused Features: The Slide Products and Services are accused of infringing by managing the replication and storage of data sets between the Slide Box and Slide Cloud (Compl. ¶148).
U.S. Patent No. 11,775,907 - "Method Facilitating Business Continuity of Enterprise Computer Network and System Associated Therewith"
- Patent Identification: U.S. Patent No. 11,775,907, “Method Facilitating Business Continuity of Enterprise Computer Network and System Associated Therewith,” issued October 3, 2023 (Compl. ¶28).
- Technology Synopsis: The patent addresses deficiencies in prior disaster recovery systems that required manual network configuration after a disaster. The invention provides a system that automatically builds a virtual recovered enterprise network and virtual machines based on predetermined network and asset configuration information (Compl. ¶28).
- Asserted Claims: At least Claim 1 (Compl. ¶164).
- Accused Features: The Slide products are accused of infringing by offering business continuity and disaster recovery services that support the restoration of a protected system as a virtual machine (Compl. ¶¶172-173).
U.S. Patent No. 10,795,688 - "System and Method for Performing an Image-Based Update"
- Patent Identification: U.S. Patent No. 10,795,688, “System and Method for Performing an Image-Based Update,” issued October 6, 2020 (Compl. ¶29).
- Technology Synopsis: The patent is directed to overcoming deficiencies of prior image-based system updates that required transmitting large, self-contained files. The invention provides a more efficient method for updates that also allows for reliable reversion to previous system versions (Compl. ¶29).
- Asserted Claims: At least Claim 11 (Compl. ¶186).
- Accused Features: The Slide products are accused of performing image-based backups and using incremental backups to update a target device (Compl. ¶194).
U.S. Patent No. 10,860,442 - "Systems, Methods, and Computer Readable Media for Business Continuity and Disaster Recovery (BCDR)"
- Patent Identification: U.S. Patent No. 10,860,442, “Systems, Methods, and Computer Readable Media for Business Continuity and Disaster Recovery (BCDR),” issued December 8, 2020 (Compl. ¶30).
- Technology Synopsis: The patent describes a method for BCDR that involves capturing successive snapshots of a recovery computer, building a target computer from a snapshot, incrementally updating the target computer, and instructing it to take over the recovery computer's functions (Compl. ¶30).
- Asserted Claims: At least Claim 12 (Compl. ¶215).
- Accused Features: The Slide products are accused of using block-level backups to replicate data from a recovery computer to a target computer (Compl. ¶223).
U.S. Patent No. 8,438,216 - "Remote Management of Virtual Machines Hosted in a Private Network"
- Patent Identification: U.S. Patent No. 8,438,216, “Remote Management of Virtual Machines Hosted in a Private Network,” issued May 7, 2013 (Compl. ¶31).
- Technology Synopsis: The patent is directed to solutions for managing a virtual machine inside a private network (which is typically firewalled) from an external, remote machine. The solution uses a communication channel between a server application outside the private network and a client application inside it (Compl. ¶31).
- Asserted Claims: At least Claim 1 (Compl. ¶245).
- Accused Features: The Slide products are accused of using the Slide Console (a remote server application) to manage virtual machines hosted on the Slide Box (a device within a private network) (Compl. ¶253).
U.S. Patent No. 8,849,906 - "Remote Management of Virtual Machines Hosted in a Private Network"
- Patent Identification: U.S. Patent No. 8,849,906, “Remote Management of Virtual Machines Hosted in a Private Network,” issued September 30, 2014 (Compl. ¶32).
- Technology Synopsis: The technology is substantially similar to the '216 Patent, providing a method to manage a virtual machine within a private, firewalled network from a remote, external machine via a communication channel between an outside server and an inside client application (Compl. ¶32).
- Asserted Claims: At least Claim 1 (Compl. ¶264).
- Accused Features: The Slide products are accused of enabling communication between the remote Slide Cloud and the Slide Box (in a private network) through a firewall to manage virtual machines (Compl. ¶272).
U.S. Patent No. 9,582,304 - "Remote Management of Virtual Machines Hosted in a Private Network"
- Patent Identification: U.S. Patent No. 9,582,304, “Remote Management of Virtual Machines Hosted in a Private Network,” issued February 28, 2017 (Compl. ¶33).
- Technology Synopsis: The technology is substantially similar to the '216 and '906 Patents, directed to the remote management of virtual machines inside a firewalled private network using a communication channel between an external server and an internal client (Compl. ¶33).
- Asserted Claims: At least Claim 1 (Compl. ¶281).
- Accused Features: The accused functionality involves the Slide Cloud communicating commands to a client application on the Slide Box within a private network, with the commands being redirected to a virtual machine host (Compl. ¶¶289-291).
U.S. Patent No. 9,921,863 - "Remote Management of Virtual Machines Hosted in a Private Network"
- Patent Identification: U.S. Patent No. 9,921,863, “Remote Management of Virtual Machines Hosted in a Private Network,” issued March 20, 2018 (Compl. ¶34).
- Technology Synopsis: The technology is substantially similar to the '216, '906, and '304 Patents, directed to the remote management of virtual machines inside a firewalled private network (Compl. ¶34).
- Asserted Claims: At least Claim 1 (Compl. ¶298).
- Accused Features: The accused functionality involves a server application (Slide Cloud) generating a command that is communicated to a client application (on the Slide Box) within a private network and executed on a virtual machine host (Compl. ¶¶306, 309).
U.S. Patent No. 8,682,862 - "Virtual Machine File-Level Restoration"
- Patent Identification: U.S. Patent No. 8,682,862, “Virtual Machine File-Level Restoration,” issued March 25, 2014 (Compl. ¶35).
- Technology Synopsis: The patent is directed to a solution for retrieving a logical data unit (e.g., a file) from a deduplicated disk-image backup without restoring the entire image. The solution involves consulting an index file, mounting the image as a virtual filesystem, and restoring only the specific data blocks that make up the requested logical data unit (Compl. ¶35).
- Asserted Claims: At least Claim 1 (Compl. ¶315).
- Accused Features: The Slide products' "File Restore" feature, which enables users to restore individual files from a ZFS snapshot (a deduplicated disk image) stored on the Slide Box (Compl. ¶323).
III. The Accused Instrumentality
Product Identification
The accused instrumentalities are the "Slide Products and Services" (Compl. ¶36). These are comprised of the Slide Console, the Slide Agent, the Slide Box, and the Slide Cloud (Compl. ¶37).
Functionality and Market Context
- The Slide platform provides a backup and disaster recovery (BCDR) solution for managed service providers (MSPs) (Compl. ¶17; Compl. ¶109). The Slide Agent is installed on a protected computer and copies data to the Slide Box, a local hardware appliance (Compl. ¶39; Compl. ¶40). The Slide Box stores these backups locally and then replicates them to the Slide Cloud for offsite storage and redundancy (Compl. ¶40; Compl. ¶41). The entire system is managed via the Slide Console, a web-based interface (Compl. ¶38). This architecture allows for various backup and recovery operations, such as full system virtualization from a local or cloud backup and individual file restores (Compl. ¶43). A diagram in the complaint illustrates this workflow, showing a protected system with a Slide Agent performing a backup to a local Slide Box, which then replicates snapshots to the Slide Cloud (Compl. p. 18).
- The complaint alleges that Slide was founded by former Datto executives to "replicate Datto's BCDR offerings" and compete directly with Plaintiffs by using their intellectual property (Compl. ¶3; Compl. ¶17).
IV. Analysis of Infringement Allegations
'039 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| A method of exchanging data between a first computing device and a second computing device, the method comprising: | The Slide Box (first device) exchanges data with the Slide Cloud (second device) when it "replicates the snapshot to the Slide Cloud for offsite storage." | ¶53 | col. 1:17-19 |
| establishing a control channel between the first computing device and the second computing device to exchange control information comprising streaming data initiation information regarding when streaming data should initiate, and streaming data termination information regarding when the streaming data should terminate, and; | A control channel is allegedly established between the Slide Box and Slide Cloud for replication. The Slide Console provides activity logs that track when replication starts and completes, which is alleged to be the control information. | ¶54; ¶55 | col. 4:1-11 |
| wherein the control information further comprises at least one of a proposed data rate and a proposed data compression level to be used during the data exchange between the first computing device and the second computing device; | The Slide Console includes a "Data Throttling" feature to set a proposed data rate for replication. Upon information and belief, a proposed data compression level is also exchanged. | ¶57 | col. 4:12-19 |
| negotiating a data transfer between the first and second computing devices; | Upon information and belief, the replication of backup data is negotiated between the Slide Box and the Slide Cloud. | ¶59 | col. 4:20-22 |
| establishing a data channel between the first and second computing devices to transfer data; and | A data channel is allegedly established between the Slide Box and Slide Cloud, as evidenced by the required outbound network connections for the system to function. | ¶60 | col. 4:23-25 |
| transferring data from the first computing device to the second computing device over the data channel in parallel with the control information being transferred over the control channel. | Upon information and belief, backup data is transferred from the Slide Box to the Slide Cloud in parallel with the control information. | ¶61 | col. 4:26-30 |
- Identified Points of Contention:
- Scope Question: The complaint's allegations for "negotiating a data transfer" and "transferring data... in parallel" are made "upon information and belief" (Compl. ¶59; Compl. ¶61). This suggests a potential point of contention over whether the accused system actually performs these steps as claimed. The evidentiary basis for these specific steps may be a focus of discovery.
- Technical Question: A key question will be whether the exchange of status information (e.g., replication start/complete logs as shown in the complaint at page 25) constitutes the exchange of "control information" for "streaming data" in parallel with the data transfer itself, as required by the claim.
'499 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| A method, comprising: retrieving at least one data file to be restored from a data storage location; | The Slide products provide a "File Restore" feature, which enables users to browse and download files from a backup stored on either the local Slide Box or the Slide Cloud. | ¶75 | col. 2:25-27 |
| determining that the at least one data file is a link file storing metadata comprising a uniform resource identifier (URI) of a repository source file, and which also includes a key encrypted with an agent and server shared secret that was previously exchanged; | Upon information and belief, Plaintiffs allege that when a user performs a file restore, the system uses an HTTPS response that functions as the claimed "link file." This response allegedly contains a URI and a key encrypted via a TLS handshake, which serves as the "agent and server shared secret." | ¶¶78-80 | col. 2:28-35 |
| decrypting the key from the link file using the shared secret; and; | Upon information and belief, the key sent in the HTTPS response is allegedly decrypted using the shared secret (session key) generated by the TLS handshake. | ¶¶81-82 | col. 2:36-37 |
| retrieving data from a data repository location to be restored using the decrypted key. | Upon information and belief, the user's device downloads the file to be restored using the now-decrypted key. | ¶83 | col. 2:38-40 |
- Identified Points of Contention:
- Scope Question: The central dispute will likely be whether a standard HTTPS response, secured by a TLS handshake, can be construed as the claimed "link file" containing a "key encrypted with an agent and server shared secret that was previously exchanged". The complaint's theory appears to equate a common web security protocol with the specific components of the patent claim, raising a significant question of claim scope.
- Technical Question: The complaint's allegations for this patent are almost entirely based on "information and belief" and rely on explaining how standard HTTPS/TLS works, rather than presenting direct evidence of the accused product's internal architecture (Compl. ¶¶78-83). A key technical question is what evidence exists that the accused system uses a "link file" structure as opposed to simply executing a standard secure file download protocol.
V. Key Claim Terms for Construction
'039 Patent
- The complaint does not provide sufficient detail for analysis of key claim terms for this patent.
'499 Patent
- The Term: "link file"
- Context and Importance: This term is the lynchpin of the infringement allegation for the '499 Patent. The complaint's theory hinges on equating a standard HTTPS network response with this claimed "link file" (Compl. ¶80). The viability of the infringement claim will depend heavily on whether the court adopts this broad interpretation or a narrower one that requires a specific, persistent file object as described in the patent. Practitioners may focus on this term because the plaintiff's infringement theory appears to stretch the term to cover a ubiquitous, standard technology.
- Intrinsic Evidence for Interpretation: The complaint does not provide the patent's specification, which is necessary for a full analysis of intrinsic evidence.
- Evidence for a Broader Interpretation: The complaint itself does not provide evidence from the patent for a broad interpretation; it instead relies on describing how HTTPS works and alleging, upon information and belief, that this standard process meets the claim limitation (Compl. ¶¶79-80).
- Evidence for a Narrower Interpretation: The complaint's description of the patent's technical solution as involving "the use of link files, each containing a link to a source file" suggests the term may refer to a discrete data object, which could support a narrower interpretation than a transient network response (Compl. ¶24).
VI. Other Allegations
- Indirect Infringement: The complaint alleges both induced and contributory infringement for all asserted patents. Inducement is primarily based on Defendant allegedly providing product documentation, technical support, and user manuals that instruct customers on how to use the Slide products in an infringing manner (e.g., Compl. ¶¶47-48; Compl. ¶¶69-70). Contributory infringement is based on allegations that the Slide products are specially designed to practice the patents and have no substantial non-infringing uses (e.g., Compl. ¶49; Compl. ¶71).
- Willful Infringement: Willfulness is alleged for all asserted patents. For the Datto-owned patents (e.g., '636, '424, '057, '907, '688, '442), the complaint alleges Defendant had knowledge since each patent's issue date because the patents were assigned to Datto and many former Datto employees, including inventors, now work at Slide (e.g., Compl. ¶90; Compl. ¶112). For other patents, knowledge is alleged as of at least October 6, 2025, based on public statements made by Defendant's co-founders (e.g., Compl. ¶46; Compl. ¶64).
VII. Analyst’s Conclusion: Key Questions for the Case
- Definitional Scope vs. Standard Technology: A core issue for several patents, particularly the '499 Patent, will be one of definitional scope: can claim terms like "link file" be construed to cover standard, off-the-shelf technologies like HTTPS responses and TLS handshakes, or are they limited to the specific structures described in the patent specifications? The outcome of this claim construction battle could be dispositive for a significant portion of the case.
- Evidence of Knowledge for Willfulness: A key question for damages will be what level of pre-suit knowledge, if any, Plaintiffs can prove. The allegations regarding Defendant's founders and employees originating from Plaintiff Datto, and in one case being a named inventor on asserted patents, create a particularly strong factual basis for willfulness claims that will likely be a central focus of litigation.
- Evidentiary Sufficiency for "Information and Belief" Allegations: For claims such as those in the '039 Patent, where key steps like "negotiating" are pled "upon information and belief," a primary question will be evidentiary: what proof can Plaintiffs obtain through discovery to substantiate these functional steps, and does the accused system's communication protocol actually meet the claim's specific requirements?
Analysis metadata
Loading Amended Complaint
Suggested improvements