GhostTrace LLC — Security Awareness Training for Small Businesses
GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.
Who is GhostTrace LLC?
GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.
Founder Details
Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915
GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.
Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.
Ethics & Compliance
Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.
Business registration
GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.
Anonymous intelligence submissions:Anonymous form (no account required)
Services
Security awareness training (primary service): live training for small business teams on phishing, invoice fraud, and safe operational practices, with completion certificates and an insurer-ready completion report.
Incident documentation support: help producing the documented records insurers and regulators require after an incident.
Exposure monitoring for your business's own domain, brand terms, and executive identifiers.
Business & domain due diligence on entities and infrastructure using only publicly available information. We do not research individuals.
Impersonation documentation: a platform-ready evidence package when your brand or a team member is being impersonated.
Digital safety review: an audit of your website, email, and domain security, with prioritized fixes.
Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.
OSINT — open-source intelligence — is neutral. It's simply the practice of collecting and analyzing information that's already public. Defenders use it to investigate scams and verify identities. Attackers use the exact same techniques to plan their next move. Understanding how they do it is the first step in reducing what they can find.
Reconnaissance comes before the attack
Almost no serious attack starts cold. A convincing phishing email references a real coworker's name. A fake recruiter knows what company you actually work for. A romance scam profile mirrors interests pulled from a dating app bio. That specificity doesn't come from luck — it comes from a few minutes of searching a name, a username, or a profile photo across public platforms.
Common sources attackers pull from:
Social media profiles — employer, job title, location, family names, daily routines
Reused usernames and profile photos — linking an anonymous account back to a real identity
Public records and data broker sites — addresses, phone numbers, relatives
Breach dumps — old passwords and emails that reveal patterns (and sometimes still work)
Metadata in shared files and images — GPS coordinates, device information, software versions
Why oversharing is the real vulnerability
Most people assume attackers need to "hack" something. Frequently they don't — they just read. A LinkedIn post announcing a new job, a vacation photo with location tags still on, a public event RSVP list. None of it looks dangerous in isolation. Combined, it builds a profile detailed enough to impersonate someone convincingly or time a scam around when they're least likely to notice.
Reducing your exposure
You can't erase your digital footprint entirely, but you can shrink the useful parts of it:
Audit what's public on your main social profiles — not just what you post, but what's visible to strangers.
Stop reusing the same username and profile photo across unrelated platforms.
Strip metadata from images before posting publicly where possible.
Treat "security questions" (mother's maiden name, first pet) as passwords — never answers a stranger could look up.
If you suspect someone has already built a profile on you for malicious purposes — an impersonation account, a targeted scam, sustained harassment — that's a documentation and evidence problem, not just a privacy-settings problem. See GhostTrace's OSINT Research service for lawful investigative support.