GhostTrace LLC — Security Awareness Training for Small Businesses
GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.
Who is GhostTrace LLC?
GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.
Founder Details
Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915
GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.
Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.
Ethics & Compliance
Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.
Business registration
GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.
Anonymous intelligence submissions:Anonymous form (no account required)
Services
Security awareness training (primary service): live training for small business teams on phishing, invoice fraud, and safe operational practices, with completion certificates and an insurer-ready completion report.
Incident documentation support: help producing the documented records insurers and regulators require after an incident.
Exposure monitoring for your business's own domain, brand terms, and executive identifiers.
Business & domain due diligence on entities and infrastructure using only publicly available information. We do not research individuals.
Impersonation documentation: a platform-ready evidence package when your brand or a team member is being impersonated.
Digital safety review: an audit of your website, email, and domain security, with prioritized fixes.
Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.
OSINT — open-source intelligence — means gathering and analyzing information that's already publicly available, then turning scattered pieces into something useful. It's not hacking, and it's not "cyber-anything" in the dramatic sense. It's disciplined research.
What counts as "open source"
Public social media profiles, news archives, public records, company filings, archived web pages, public forum posts, image metadata, DNS and WHOIS records — anything accessible without bypassing a login, breaking an access control, or otherwise stepping outside what the information owner made available. That boundary is what separates OSINT from unauthorized access, and it's not a gray area professionals treat casually.
What OSINT is actually used for
Verifying identity — confirming a person or business is who they claim to be before a transaction or partnership.
Investigating scams and impersonation — tracing fake profiles, linked aliases, and reused infrastructure.
Due diligence — researching a business or individual's public history before engaging with them.
Threat intelligence — understanding attacker infrastructure and behavior from what's publicly observable.
Personal digital footprint review — seeing what a stranger could learn about you from public information alone.
A basic OSINT workflow
Define the question. "Is this profile real" is different from "has this domain been linked to prior scams" — the sources you check depend entirely on what you're trying to answer.
Collect from multiple independent sources. A single data point is a clue; the same fact confirmed across unrelated sources is closer to a finding.
Document as you go — source, date, and method for every piece of information, not just the conclusion. Undocumented findings are much harder to act on later.
Separate fact from inference. "This username appears on three platforms with the same profile photo" is a fact. "This is definitely the same person" is an inference — a good OSINT process keeps those clearly labeled as different things.
Where it stops being lawful
Accessing an account without authorization, deceiving a platform's support team into revealing private information, or acquiring data through a breach — even to investigate a legitimate concern — crosses from OSINT into unlawful access. It also tends to destroy the usefulness of whatever you find, since improperly obtained information is rarely accepted by banks, platforms, or law enforcement.
Getting started responsibly
If you're researching a personal safety concern rather than a professional one, start with what you already have — screenshots, messages, usernames — and be methodical about preserving originals before anything changes. For anything with real stakes (money already sent, ongoing harassment, a business relationship on the line), a lawful, professionally documented investigation carries far more weight than self-directed searching. See GhostTrace's OSINT Research service for how a professional engagement is scoped.