GhostTrace LLC — Security Awareness Training for Small Businesses
GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.
Who is GhostTrace LLC?
GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.
Founder Details
Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915
GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.
Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.
Ethics & Compliance
Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.
Business registration
GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.
Anonymous intelligence submissions:Anonymous form (no account required)
Services
Security awareness training (primary service): live training for small business teams on phishing, invoice fraud, and safe operational practices, with completion certificates and an insurer-ready completion report.
Incident documentation support: help producing the documented records insurers and regulators require after an incident.
Exposure monitoring for your business's own domain, brand terms, and executive identifiers.
Business & domain due diligence on entities and infrastructure using only publicly available information. We do not research individuals.
Impersonation documentation: a platform-ready evidence package when your brand or a team member is being impersonated.
Digital safety review: an audit of your website, email, and domain security, with prioritized fixes.
Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.
Everything you need is already public. A trail of clues has been intentionally placed across our official website, files, and social presence. Find it. Follow it. Capture the flag.
Rules of engagement
Public information only — every clue was put there on purpose, by us.
No hacking, scanning, brute-forcing, or vulnerability testing of any kind.
No contacting GhostTrace staff, partners, or clients about the challenge.
All clues live on GhostTrace's own official channels — nowhere else.
First correct flag submission wins. One flag, one winner.
You must record yourself working through the challenge and post that recording publicly with #GhostTraceLLCcomp — submissions without a posted recording do not count.
Each one below gives away a little more. Open only as many as you need — the challenge is more fun if you stop early.
Hint 1
Not everything on a website is meant to be clicked. Some of the most useful pages for a researcher are the ones nobody linked to.
Hint 2
Every site publishes a small file that tells search engines where not to look. That's often exactly where a human should look. It's always at the same predictable path, on every site.
Hint 3
Once you're on the page a search engine wasn't supposed to find, use View Page Source (not Inspect Element) — it shows you what was actually delivered, including things a normal visitor would scroll straight past.
Hint 4
Files carry information about themselves that never shows up in the reader window. Check Document Properties / metadata — most PDF viewers have it under a File or Info menu.
Hint 5
No metadata tool handy? Zoom all the way into the last page instead. Not everything worth reading is full-size.
Hint 6
One of our blog posts is more personal than the rest. Read the first letter of every paragraph, in order.
Hint 7
Keep an eye on our social accounts for a plain-looking company update graphic. It isn't just a graphic.
Hint 8
Once you have a single word, there are two ways to reach the ending: one involves a camera, one involves just typing a URL.
Not every important page appears in the navigation.