How we protect you
You're trusting us with sensitive information. Here's exactly how we handle it, who can access it, and the standards we hold ourselves to — with links to the full policies behind each claim.
Security incident report — July 9, 2026
On July 9, 2026, we identified and contained an attempt to abuse several platform features, including a webhook vulnerability and abusive content posted through a compromised third-party credential. We found no evidence any customer data, case files, or payment information were accessed. Full details, our response, and the security improvements we made are in the public report below.
Where GhostTrace fits (and where we don't)
We're a boutique firm, not a state-level security apparatus. Being upfront about that scope is part of being trustworthy — here's how we size up against the kind of threat you're facing.
This is our core work. OSINT research, digital footprint cleanup, and incident documentation are built for exactly this tier.
We can help, but we'll recommend keeping the most sensitive material — unredacted financial records, master credentials — out of the portal unless a specific finding requires it.
We'll tell you directly if a case is beyond our scope, and point you toward law enforcement or firms built for that threat tier, rather than take on an engagement we can't responsibly deliver.
How we handle your information
- Case messages, notes, ticket replies, and uploaded files are stored encrypted at rest, with the encryption key rotated weekly — access is restricted to cleared staff bound by confidentiality agreements.
- Retired encryption keys are re-encrypted forward and deleted, not kept around indefinitely, so a leaked old key can't be used to decrypt current data.
- We never store your card details — all payments are processed directly by Stripe.
- We do not sell, rent, or trade personal data, and we do not use your case data to train machine-learning models.
- Account data is anonymized and deactivated immediately when you request deletion — your email, name, and sign-in credentials are irreversibly scrubbed the moment the request is verified, not on a delay. Case records and audit logs are retained only as long as needed for legal defensibility, then deleted or anonymized.
What to share — and what to hold back
- Only upload what's directly relevant to your case — for most engagements that's dates, screenshots, account handles, and correspondence, not full financial statements or master password lists.
- Your client portal lets you scope uploads per case, so unrelated files never enter our systems in the first place.
- You can request early deletion of specific files once a case closes, rather than waiting on the full account-deletion timeline.
Where your data actually lives
- We rely on a small, named set of subprocessors, not an unbounded vendor chain: Stripe for payment processing, and a cloud hosting/database provider for encrypted case storage. We don't add new subprocessors without updating this page.
- Case files never pass through analytics or advertising tools, and nothing sensitive is written to browser local storage.
- When something goes wrong on our end, we publish it — see the incident report above for an example of that in practice.
Confidentiality & staff vetting
- GhostTrace is currently operated solely by its founder. GhostTrace does not use unpaid volunteers — any future personnel will be paid employees or independent contractors, each 18 or older.
- Any future staff or contractor will sign a standing NDA governed by Georgia law and enforceable in Georgia courts, and undergo background screening before receiving access to any case material.
- Personnel act under GhostTrace's methodology and direct supervision, with access scoped to what their role requires.
Account & platform security
- Multi-factor authentication (MFA) is available on every account, and required for staff with access to sensitive case data.
- Session tokens are stored in httpOnly, secure cookies — never in browser local storage — so they can't be read by page scripts.
- Every sensitive staff action (case access, permission changes, payment operations) is written to an internal audit log.
- Found a security issue? Report it via our published security.txt or email tech@ghosttrace.net — we welcome responsible disclosure.
Ethical guidelines & scope limitations
- GhostTrace LLC is a private research firm — we are not a law enforcement agency, and we have no enforcement authority.
- We do not conduct unauthorized hacking, surveillance of private spaces, or access to accounts or systems without authorization.
- We are not a legal firm and do not provide legal representation — we document and research; decisions on disputes, takedowns, and prosecutions belong to banks, platforms, and authorities.
Responsible research policy
- All research uses lawful, publicly available information only — public profiles, records, breach-data indexes, domain metadata, and similar open sources.
- Every finding is documented with its source and timestamp, and labeled with a confidence level (Confirmed, Probable, or Possible) rather than presented as fact.
- We report findings to clients and, where appropriate, to authorities — we do not take enforcement action ourselves.
Verified business registration
- GhostTrace LLC is a legally registered, active Georgia LLC (Control No. 26142915), independently verifiable on the Georgia Secretary of State's business search, not just self-reported.
- GhostTrace carries professional liability (errors & omissions) insurance through Hiscox, an A-rated carrier.
- GhostTrace is founder-funded today and currently raising a pre-seed round to hire analysts. Client fees fund service delivery; investor capital funds hiring and growth, not case handling — see Invest in GhostTrace for the pitch deck and terms.
- We're a new firm and haven't yet earned peer citations, CVE credits, or press coverage — we'd rather say that plainly than imply a track record we don't have yet.
Accountability & complaints
- Ethics complaints come straight to me. I review every one against the same privacy, sourcing, and platform-policy standards that guide the rest of my work.
- If you believe GhostTrace acted outside these standards, you can file a confidential, or anonymous, ethics complaint directly.
Questions about how we operate?
Email support@ghosttrace.net, or read our full legal policies.