GhostTrace LLC — Security Awareness Training for Small Businesses
GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.
Who is GhostTrace LLC?
GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.
Founder Details
Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915
GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.
Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.
Ethics & Compliance
Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.
Business registration
GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.
Anonymous intelligence submissions:Anonymous form (no account required)
Services
Security awareness training (primary service): live training for small business teams on phishing, invoice fraud, and safe operational practices, with completion certificates and an insurer-ready completion report.
Incident documentation support: help producing the documented records insurers and regulators require after an incident.
Exposure monitoring for your business's own domain, brand terms, and executive identifiers.
Business & domain due diligence on entities and infrastructure using only publicly available information. We do not research individuals.
Impersonation documentation: a platform-ready evidence package when your brand or a team member is being impersonated.
Digital safety review: an audit of your website, email, and domain security, with prioritized fixes.
Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.
Email security details to tech@ghosttrace.net. Encrypt sensitive details using the PGP key published at ghosttrace.net/.well-known/pgp-key.txt if you prefer. Please include: the affected URL or system, the steps to reproduce, and the impact you believe it has. We aim to acknowledge every good-faith report within 3 business days.
Scope
In scope: ghosttrace.net and its subpaths, and our public API surface. Out of scope: third-party services we use (Stripe, Firebase/Google, Resend, and similar) — report issues in those directly to the provider; denial-of-service testing; social engineering of our staff or contractors; and physical security testing.
Safe harbor
If you make a good-faith effort to comply with this policy while researching a vulnerability, we will not pursue legal action against you for that research, and we consider such research authorized under the Computer Fraud and Abuse Act and applicable state computer-crime law. Good faith means: you avoid privacy violations, data destruction, and service disruption; you stop and report immediately upon finding a vulnerability rather than continuing to explore its impact further than necessary to demonstrate it; and you give us a reasonable opportunity to remediate before any public disclosure.
What we ask you not to do
Do not access, modify, or delete data that isn't yours, including in a shared/multi-tenant system. Do not run automated scanning at a volume that could degrade service for real users. Do not test in ways that could affect a real client's ongoing case. If you're unsure whether an action is in scope, ask first.
A structured research relationship
If you'd like ongoing, authorized access to test more deeply — not just a one-off report — GhostTrace also runs a Security Research Program with a signed scope agreement and its own researcher portal; see /pentest-program.
Recognition
With your permission, we're glad to credit valid reports publicly. We do not currently offer paid bounties, but pro bono program participants may be featured on our public Hall of Fame — see the Security Research Program for details.