GhostTrace LLC — Security Awareness Training for Small Businesses
GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.
Who is GhostTrace LLC?
GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.
Founder Details
Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915
GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.
Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.
Ethics & Compliance
Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.
Business registration
GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.
Anonymous intelligence submissions:Anonymous form (no account required)
Services
Security awareness training (primary service): live training for small business teams on phishing, invoice fraud, and safe operational practices, with completion certificates and an insurer-ready completion report.
Incident documentation support: help producing the documented records insurers and regulators require after an incident.
Exposure monitoring for your business's own domain, brand terms, and executive identifiers.
Business & domain due diligence on entities and infrastructure using only publicly available information. We do not research individuals.
Impersonation documentation: a platform-ready evidence package when your brand or a team member is being impersonated.
Digital safety review: an audit of your website, email, and domain security, with prioritized fixes.
Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.
Data Minimization: The Privacy Principle Most Companies Ignore
Jul 12, 2026 · GhostTrace Team
Most privacy conversations focus on protecting data: encryption, access controls, breach response. Those matter. But there's a simpler control that gets far less attention, precisely because it isn't a product you can buy: only collecting and retaining the data you actually need.
The logic is uncomfortable but simple
Data that was never collected can't be breached. Data that's deleted on schedule can't be exposed in an incident five years later. Every field on a signup form, every log retained indefinitely, every "just in case we need it someday" database is a liability sitting on a shelf — useful to the business in theory, valuable to an attacker in practice, and a growing regulatory exposure the longer it sits unused.
Where it tends to go wrong
Collecting more than the interaction requires. Asking for a date of birth on a newsletter signup when age isn't otherwise relevant.
No retention policy, or one that isn't enforced. Data from customers who left years ago, sitting in the same database as active customers, with no different handling.
Logs that capture more than they need to. Debug logs that happen to include full request bodies — which might include passwords, tokens, or personal data — retained far longer than the debugging need justified.
Third-party sharing by default. Analytics and marketing tools configured to receive full user records when aggregate or pseudonymized data would answer the same business question.
What minimization looks like in practice
For every field you collect, ask what breaks if you don't have it. If nothing breaks, don't collect it.
Set an actual retention period per data category, and automate deletion — a policy that requires someone to remember to act on it usually doesn't get enforced.
Separate what's operationally necessary from what's merely convenient, and treat the second category as opt-in, not default.
Audit what third-party scripts and integrations actually receive, not just what you intended them to receive.
The business case, not just the compliance case
Minimization isn't only a regulatory checkbox. A breach of data you never collected costs nothing to disclose, nothing to remediate, and damages no one. The cheapest way to reduce breach impact is to reduce what there is to breach — a principle worth applying before the incident, not after.