GhostTrace LLC — Security Awareness Training for Small Businesses

GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.

Who is GhostTrace LLC?

GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.

Founder Details

Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915

GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.

Who runs this

Founder and Owner: Daniel Upperman

Email: Founder@ghosttrace.net

Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.

Ethics & Compliance

Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.

Business registration

GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.

Contact Information

Services

Popular questions we answer

Contact

Email support@ghosttrace.net — replies within one business day. Anonymous intelligence submissions accepted (no account required).

Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.

PROMO

CodeGabe partner code—20.0% off, referred by CodeGabe

CODEGABE5CF6View pricing
Trust Center

How we protect you

You're trusting us with sensitive information. Here's exactly how we handle it, who can access it, and the standards we hold ourselves to — with links to the full policies behind each claim.

Georgia-registered LLC
Control No. 26142915, independently verifiable
E&O insured
Through Hiscox, an A-rated carrier — certificate on request
Direct founder access
Every engagement, no support-ticket queue
Audio Overview
A audio overview about who we are, what we do, what we don't do and more.

Security incident report — July 9, 2026

Published July 9, 2026

On July 9, 2026, we identified and contained an attempt to abuse several platform features, including a webhook vulnerability and abusive content posted through a compromised third-party credential. We found no evidence any customer data, case files, or payment information were accessed. Full details, our response, and the security improvements we made are in the public report below.

Where GhostTrace fits (and where we don't)

We're a boutique firm, not a state-level security apparatus. Being upfront about that scope is part of being trustworthy — here's how we size up against the kind of threat you're facing.

Best fitData brokers, people-search sites, standard online harassment, impersonation, small-scale fraud

This is our core work. OSINT research, digital footprint cleanup, and incident documentation are built for exactly this tier.

Fit — with boundariesTargeted stalking, persistent fraud rings, localized corporate or personal disputes

We can help, but we'll recommend keeping the most sensitive material — unredacted financial records, master credentials — out of the portal unless a specific finding requires it.

Refer outNation-state actors, organized crime with legal resources, active physical danger

We'll tell you directly if a case is beyond our scope, and point you toward law enforcement or firms built for that threat tier, rather than take on an engagement we can't responsibly deliver.

How we handle your information

  • Case messages, notes, ticket replies, and uploaded files are stored encrypted at rest, with the encryption key rotated weekly — access is restricted to cleared staff bound by confidentiality agreements.
  • Retired encryption keys are re-encrypted forward and deleted, not kept around indefinitely, so a leaked old key can't be used to decrypt current data.
  • We never store your card details — all payments are processed directly by Stripe.
  • We do not sell, rent, or trade personal data, and we do not use your case data to train machine-learning models.
  • Account data is anonymized and deactivated immediately when you request deletion — your email, name, and sign-in credentials are irreversibly scrubbed the moment the request is verified, not on a delay. Case records and audit logs are retained only as long as needed for legal defensibility, then deleted or anonymized.
Read the full Privacy Policy →

What to share — and what to hold back

  • Only upload what's directly relevant to your case — for most engagements that's dates, screenshots, account handles, and correspondence, not full financial statements or master password lists.
  • Your client portal lets you scope uploads per case, so unrelated files never enter our systems in the first place.
  • You can request early deletion of specific files once a case closes, rather than waiting on the full account-deletion timeline.
See what we typically need to open a case →

Where your data actually lives

  • We rely on a small, named set of subprocessors, not an unbounded vendor chain: Stripe for payment processing, and a cloud hosting/database provider for encrypted case storage. We don't add new subprocessors without updating this page.
  • Case files never pass through analytics or advertising tools, and nothing sensitive is written to browser local storage.
  • When something goes wrong on our end, we publish it — see the incident report above for an example of that in practice.
Read our data handling policy →

Confidentiality & staff vetting

  • GhostTrace is currently operated solely by its founder. GhostTrace does not use unpaid volunteers — any future personnel will be paid employees or independent contractors, each 18 or older.
  • Any future staff or contractor will sign a standing NDA governed by Georgia law and enforceable in Georgia courts, and undergo background screening before receiving access to any case material.
  • Personnel act under GhostTrace's methodology and direct supervision, with access scoped to what their role requires.

Account & platform security

  • Multi-factor authentication (MFA) is available on every account, and required for staff with access to sensitive case data.
  • Session tokens are stored in httpOnly, secure cookies — never in browser local storage — so they can't be read by page scripts.
  • Every sensitive staff action (case access, permission changes, payment operations) is written to an internal audit log.
  • Found a security issue? Report it via our published security.txt or email tech@ghosttrace.net — we welcome responsible disclosure.

Ethical guidelines & scope limitations

  • GhostTrace LLC is a private research firm — we are not a law enforcement agency, and we have no enforcement authority.
  • We do not conduct unauthorized hacking, surveillance of private spaces, or access to accounts or systems without authorization.
  • We are not a legal firm and do not provide legal representation — we document and research; decisions on disputes, takedowns, and prosecutions belong to banks, platforms, and authorities.
More on who we are (and aren't) →

Responsible research policy

  • All research uses lawful, publicly available information only — public profiles, records, breach-data indexes, domain metadata, and similar open sources.
  • Every finding is documented with its source and timestamp, and labeled with a confidence level (Confirmed, Probable, or Possible) rather than presented as fact.
  • We report findings to clients and, where appropriate, to authorities — we do not take enforcement action ourselves.
Read our OSINT methodology →

Verified business registration

  • GhostTrace LLC is a legally registered, active Georgia LLC (Control No. 26142915), independently verifiable on the Georgia Secretary of State's business search, not just self-reported.
  • GhostTrace carries professional liability (errors & omissions) insurance through Hiscox, an A-rated carrier.
  • GhostTrace is founder-funded today and currently raising a pre-seed round to hire analysts. Client fees fund service delivery; investor capital funds hiring and growth, not case handling — see Invest in GhostTrace for the pitch deck and terms.
  • We're a new firm and haven't yet earned peer citations, CVE credits, or press coverage — we'd rather say that plainly than imply a track record we don't have yet.
See full registration & funding details →

Accountability & complaints

  • Ethics complaints come straight to me. I review every one against the same privacy, sourcing, and platform-policy standards that guide the rest of my work.
  • If you believe GhostTrace acted outside these standards, you can file a confidential, or anonymous, ethics complaint directly.
File an ethics complaint →

Questions about how we operate?

Email support@ghosttrace.net, or read our full legal policies.