Try to break in.
We're asking you to.
GhostTrace runs on trust — case files, client communications, and evidence that can't leak. We work with a small, vetted group of penetration testers and security researchers who test that trust on purpose, before anyone else does.
Live counts from the program, updated continuously — not marketing placeholders.
- Status
- Open · rolling applications
- Access
- By approval, not self-serve
- Compensation
- Pro bono — recognition, not paid work
- Scope
- Defined per researcher, in writing
- Contact
- security@ghosttrace.net
We'd rather you find it than someone else.
GhostTrace handles material that can't be treated casually — case documentation, client communications, evidence chains, background screening records. Internal review catches most things. It doesn't catch everything. So we built a standing channel for outside researchers to test our platform on purpose, under clear rules, instead of finding our blind spots the way an attacker would.
Every staff account requires multi-factor authentication. Sensitive records are encrypted at rest. Every action a staff member takes is logged and reviewable. None of that replaces an outside set of eyes — it's the reason we want one.
The security research community operates on a kind of trust most companies never earn. We're not interested in a one-time audit and a press release. We're interested in an ongoing relationship with people who take this seriously — and we intend to treat it just as seriously in return.
What you can expect from us
- A real person reads your application — no automated approval, no queue you fall into and never hear from again.
- A written scope and authorization before you test anything.
- A response on every submitted finding, including the ones we don't act on.
- Credit that's actually yours to point to — not buried in a changelog.
From application to recognition
Six steps, start to finish. Nothing about scope or authorization is implied — you'll have it in writing before you begin.
Apply
Tell us who you are and what you're good at. About ten minutes, no account required.
Review
Our security team reads every application individually. We're looking for real experience, not a polished résumé.
Authorization
Approved researchers receive a written scope and a signed testing authorization — your permission, on record.
Test
Test what's in scope, methodically, without degrading the platform for the people actually using it.
Report
Submit findings through our private reporting channel with enough detail for us to reproduce and fix it.
Recognition
Verified findings earn credit — anywhere from a Hall of Fame listing to a signed certificate, on your terms.
This isn't a mass open door.
It's a working list of people we trust to test us well. If you fit here, we want to hear from you.
Backgrounds we welcome
Skills that matter most right now
What approved researchers may test
This is Appendix A of the actual Pro Bono Penetration Testing Agreement every approved researcher signs — not a summary. You'll see the full text, and sign it, in your researcher portal after approval.
In scope
- +The domain ghosttrace.net
- +Web applications, web forms, and authentication workflows on ghosttrace.net
- +Public API endpoints hosted on ghosttrace.net
- +IPv4 172.66.2.113, solely where it directly hosts ghosttrace.net
Out of scope
- −Any domain or subdomain not explicitly listed above
- −CDN/WAF edge infrastructure (e.g. Cloudflare) and core DNS — target Layer-7, not the network
- −Hosting-provider infrastructure — datacenters, hypervisors, upstream cloud
- −Third-party APIs, payment gateways, and SaaS integrations linked from the site
- −Live client case data or real client accounts
Prohibited testing methods
- ×Denial of Service (DoS/DDoS), volumetric flooding, or resource exhaustion
- ×Destructive payloads — database deletions, account wiping, mass overwrites
- ×Social engineering or phishing targeting GhostTrace personnel, contractors, or customers
- ×Physical intrusion at any GhostTrace facility
- ×Automated spam or rate abuse, including credential stuffing
Good-faith testing that stays inside your authorized scope and follows the program rules will not result in legal action from GhostTrace.
We don't run a bounty board.
We build a public record of the people who made us better — and make sure it's actually worth having your name on.
Security Researcher Hall of Fame
A permanent, public listing of every researcher with a verified finding — newest first, never quietly removed.
Public researcher profiles
An opt-in profile: your handle, your focus areas, and what you've found — built the way you'd actually want it on your own portfolio.
Credit on our site
Named credit on the finding itself, visible to anyone who reads our security page — not folded into a generic thank-you list.
Certificate of appreciation
A signed, GhostTrace-branded certificate for every verified finding — built for a portfolio, a LinkedIn post, or a client conversation.
Portfolio-ready writeups
A redacted, publication-ready summary you can point to — cleared for your portfolio without exposing anything sensitive.
Special mentions
Novel techniques and unusually high-impact findings get called out individually, not folded into a generic list.
A few of the people already on this list
Profiles are opt-in and researcher-controlled — live from the program, not staged examples.
Before you apply
Who can apply?
Anyone 18 or older with genuine security testing experience — professional, freelance, academic, or self-taught through CTFs and personal research. We care about what you can demonstrate, not where you learned it.
Is this paid?
No — it's a pro bono program. You participate under a written Pro Bono Penetration Testing Agreement as an independent security researcher, not as an employee or a paid contractor: no monetary compensation, no minimum hours, no fixed schedule. In exchange, verified findings earn public credit: Hall of Fame listing, a signed certificate, and a portfolio-ready writeup. If that's not the right fit for you right now, we understand.
How do I participate?
Submit an application. If approved, we'll set up your researcher account and you'll review and e-sign the Pro Bono Penetration Testing Agreement in your portal — that's your written scope and testing authorization. You're not cleared to test anything until it's signed.
What systems can I test?
Only what's listed in Appendix A of your signed agreement — see Testing Scope above for the exact in-scope domain and IP address, and what's explicitly excluded. Testing anything else, including before you've signed, is not authorized.
How are researchers recognized?
Every verified finding is eligible for Hall of Fame listing, named credit on our security page, and a signed certificate of appreciation. Novel or high-impact findings get an individual mention rather than a line in a list.
What happens after I submit a report?
We acknowledge every report within two business days and keep you updated on triage status. Our security team reproduces and validates the finding, works on remediation, and classifies it (accepted, duplicate, informational, not reproducible, or out of scope). Once it's resolved, we coordinate on recognition and, if you'd like, a public writeup. Found something critical — RCE, full admin access, direct operational exposure? Stop testing that vector immediately and email founder@ghosttrace.net within four hours.
Can I share my work publicly?
Yes, once we've coordinated on disclosure — generally after a fix ships. Anything you publish needs to follow our redaction standards (no client data, no internal system detail beyond what we've cleared together). We'll help you put together a portfolio-safe version if you want one.
Think you belong on this list?
Applications are reviewed on a rolling basis by our security team.
Apply Now