GhostTrace LLC — Security Awareness Training for Small Businesses

GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.

Who is GhostTrace LLC?

GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.

Founder Details

Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915

GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.

Who runs this

Founder and Owner: Daniel Upperman

Email: Founder@ghosttrace.net

Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.

Ethics & Compliance

Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.

Business registration

GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.

Contact Information

Services

Popular questions we answer

Contact

Email support@ghosttrace.net — replies within one business day. Anonymous intelligence submissions accepted (no account required).

Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.

PROMO

CodeGabe partner code20.0% off, referred by CodeGabe

CODEGABE5CF6View pricing
GhostTrace · Security Research Program

Try to break in.
We're asking you to.

GhostTrace runs on trust — case files, client communications, and evidence that can't leak. We work with a small, vetted group of penetration testers and security researchers who test that trust on purpose, before anyone else does.

1
Vetted researchers
2
Accepted findings
7.8h
Median first response

Live counts from the program, updated continuously — not marketing placeholders.

Program brief
Status
Open · rolling applications
Access
By approval, not self-serve
Compensation
Pro bono — recognition, not paid work
Scope
Defined per researcher, in writing
Why this exists

We'd rather you find it than someone else.

GhostTrace handles material that can't be treated casually — case documentation, client communications, evidence chains, background screening records. Internal review catches most things. It doesn't catch everything. So we built a standing channel for outside researchers to test our platform on purpose, under clear rules, instead of finding our blind spots the way an attacker would.

Every staff account requires multi-factor authentication. Sensitive records are encrypted at rest. Every action a staff member takes is logged and reviewable. None of that replaces an outside set of eyes — it's the reason we want one.

The security research community operates on a kind of trust most companies never earn. We're not interested in a one-time audit and a press release. We're interested in an ongoing relationship with people who take this seriously — and we intend to treat it just as seriously in return.

What you can expect from us

  • A real person reads your application — no automated approval, no queue you fall into and never hear from again.
  • A written scope and authorization before you test anything.
  • A response on every submitted finding, including the ones we don't act on.
  • Credit that's actually yours to point to — not buried in a changelog.
How it works

From application to recognition

Six steps, start to finish. Nothing about scope or authorization is implied — you'll have it in writing before you begin.

01

Apply

Tell us who you are and what you're good at. About ten minutes, no account required.

02

Review

Our security team reads every application individually. We're looking for real experience, not a polished résumé.

03

Authorization

Approved researchers receive a written scope and a signed testing authorization — your permission, on record.

04

Test

Test what's in scope, methodically, without degrading the platform for the people actually using it.

05

Report

Submit findings through our private reporting channel with enough detail for us to reproduce and fix it.

06

Recognition

Verified findings earn credit — anywhere from a Hall of Fame listing to a signed certificate, on your terms.

Who we're looking for

This isn't a mass open door.

It's a working list of people we trust to test us well. If you fit here, we want to hear from you.

Backgrounds we welcome

Penetration TestersSecurity ResearchersEthical HackersBug HuntersRed Team ProfessionalsApplication Security Specialists

Skills that matter most right now

Web Application TestingAPI SecurityAuthentication TestingAuthorization TestingOWASP Top 10Vulnerability Research
Testing scope

What approved researchers may test

This is Appendix A of the actual Pro Bono Penetration Testing Agreement every approved researcher signs — not a summary. You'll see the full text, and sign it, in your researcher portal after approval.

In scope

  • +The domain ghosttrace.net
  • +Web applications, web forms, and authentication workflows on ghosttrace.net
  • +Public API endpoints hosted on ghosttrace.net
  • +IPv4 172.66.2.113, solely where it directly hosts ghosttrace.net

Out of scope

  • Any domain or subdomain not explicitly listed above
  • CDN/WAF edge infrastructure (e.g. Cloudflare) and core DNS — target Layer-7, not the network
  • Hosting-provider infrastructure — datacenters, hypervisors, upstream cloud
  • Third-party APIs, payment gateways, and SaaS integrations linked from the site
  • Live client case data or real client accounts

Prohibited testing methods

  • ×Denial of Service (DoS/DDoS), volumetric flooding, or resource exhaustion
  • ×Destructive payloads — database deletions, account wiping, mass overwrites
  • ×Social engineering or phishing targeting GhostTrace personnel, contractors, or customers
  • ×Physical intrusion at any GhostTrace facility
  • ×Automated spam or rate abuse, including credential stuffing
Only systems explicitly listed in your written authorization may be tested. Testing anything outside that scope — including this website, before you're approved — is not authorized and will be treated as unauthorized access, not research. If you find a critical flaw (RCE, full admin access, direct operational exposure), stop testing that vector immediately and email founder@ghosttrace.net within four hours.

Good-faith testing that stays inside your authorized scope and follows the program rules will not result in legal action from GhostTrace.

Recognition

We don't run a bounty board.

We build a public record of the people who made us better — and make sure it's actually worth having your name on.

Security Researcher Hall of Fame

A permanent, public listing of every researcher with a verified finding — newest first, never quietly removed.

Public researcher profiles

An opt-in profile: your handle, your focus areas, and what you've found — built the way you'd actually want it on your own portfolio.

Credit on our site

Named credit on the finding itself, visible to anyone who reads our security page — not folded into a generic thank-you list.

Certificate of appreciation

A signed, GhostTrace-branded certificate for every verified finding — built for a portfolio, a LinkedIn post, or a client conversation.

Portfolio-ready writeups

A redacted, publication-ready summary you can point to — cleared for your portfolio without exposing anything sensitive.

Special mentions

Novel techniques and unusually high-impact findings get called out individually, not folded into a generic list.

Featured researchers

A few of the people already on this list

View full Hall of Fame

Profiles are opt-in and researcher-controlled — live from the program, not staged examples.

Frequently asked

Before you apply

Who can apply?

Anyone 18 or older with genuine security testing experience — professional, freelance, academic, or self-taught through CTFs and personal research. We care about what you can demonstrate, not where you learned it.

Is this paid?

No — it's a pro bono program. You participate under a written Pro Bono Penetration Testing Agreement as an independent security researcher, not as an employee or a paid contractor: no monetary compensation, no minimum hours, no fixed schedule. In exchange, verified findings earn public credit: Hall of Fame listing, a signed certificate, and a portfolio-ready writeup. If that's not the right fit for you right now, we understand.

How do I participate?

Submit an application. If approved, we'll set up your researcher account and you'll review and e-sign the Pro Bono Penetration Testing Agreement in your portal — that's your written scope and testing authorization. You're not cleared to test anything until it's signed.

What systems can I test?

Only what's listed in Appendix A of your signed agreement — see Testing Scope above for the exact in-scope domain and IP address, and what's explicitly excluded. Testing anything else, including before you've signed, is not authorized.

How are researchers recognized?

Every verified finding is eligible for Hall of Fame listing, named credit on our security page, and a signed certificate of appreciation. Novel or high-impact findings get an individual mention rather than a line in a list.

What happens after I submit a report?

We acknowledge every report within two business days and keep you updated on triage status. Our security team reproduces and validates the finding, works on remediation, and classifies it (accepted, duplicate, informational, not reproducible, or out of scope). Once it's resolved, we coordinate on recognition and, if you'd like, a public writeup. Found something critical — RCE, full admin access, direct operational exposure? Stop testing that vector immediately and email founder@ghosttrace.net within four hours.

Can I share my work publicly?

Yes, once we've coordinated on disclosure — generally after a fix ships. Anything you publish needs to follow our redaction standards (no client data, no internal system detail beyond what we've cleared together). We'll help you put together a portfolio-safe version if you want one.

Think you belong on this list?

Applications are reviewed on a rolling basis by our security team.

Apply Now