Security · Software · AI · Colombo → Worldwide

Member of NVIDIA Inception

UncompromisedWe engineer, penetrate, and harden the systems that cannot afford to fail.

A Colombo, Sri Lanka company building AI, software and security, serving clients worldwide.

▸ Check your site free · 60 seconds · nothing stored

Book a pentest

Fix-it guidance on the scan, and a free re-test on every engagement.

Built with: Cloudflare, Workers, Next.js, React, TypeScript, Node.js, Python, Rust, Docker, Tailwind CSS, Radix UI, SQLite, Anthropic, Ollama, Stripe, Vercel, GitHub. Ghost Protocol is a member of the NVIDIA Inception program.

Flagship · Wyrm

Memory that survives the session.

Wyrm is our flagship: the local-first memory & intelligence layer for AI agents. An MCP server that makes Claude, Cursor and Copilot remember your project, learn from failures, and refuse to repeat them. Free to use, runs on your machine.

Live · Wyrm MCP session
Install
$ npm install -g wyrm-mcp

Receipts, measured · v9.1.2

100 · 100
Negative-learning firewall: recall % · precision %
33 → 52
Reranked recall@1, +19 pts
33 · 137
Verbs · tools callable (typed surface)
−38.9%
Token economy (fleet), measured
2,697
Tests · 226 suites · green
Local
Local-first · no cloud LLM

Every figure is from a committed benchmark, reproducible from the repo, never asserted.

Arsenal · Products

The launch bay is loaded.

Core capabilities

Built for real users, real data, real attackers.

File · capabilities manifest

1 / 4

Security audits

we find the weaknesses before attackers do, then help you fix them.

  • » Penetration Testing
  • » Ethical Hacking
  • » Vulnerability Scans
  • » Social Engineering
2 / 4

Engineering

fast, secure, reliable software, built to be attacked and survive.

  • » High-Performance Web Apps
  • » Secure System Design
  • » Enterprise Development
  • » API & Microservices
3 / 4

Infrastructure

your data and cloud environments, protected around the clock.

  • » Zero-Trust Cloud Setup
  • » AWS/GCP Security
  • » Secure Dev Pipelines
  • » Security monitoring and alerting
4 / 4

Advanced tech

AI, OSINT, and AR, built when off-the-shelf doesn't fit.

  • » Autonomous AI Agents
  • » OSINT Investigations
  • » Spatial Computing (AR)
  • » Custom Security Tools
See every serviceBook a free 15-minute intro call
Proof · in production

We run what we build.

These three are ours, not case studies borrowed from a client list. We run them in production, take the pages at 3am, and ship the same way for the people who hire us.

See all case studies · full dossier

Pricing

Transparent pricing. Real results.

No hidden fees, no scope creep. Every pentest includes fix-it guidance and a free re-test. Listed in USD; companies registered in Sri Lanka have a local rate card, see pricing.

Free

Ghost Scan

PhantomDragon runs a surface scan of your site.

  • No sales call, no card. See what an attacker sees first.

$299

one-time

Security Scan

AI-powered deep scan of your site or app

  • Deep AI scan, human-verified findings

$2,999

per project

Penetration Test

A real engineer attempts to break into your system

  • 5–7 days · free re-test · attestation letter

$899

per month, 6-month minimum

Security Retainer

Ongoing protection for your team

  • Continuous coverage, priority response

From $5,000

quoted per scope

Regulated / Enterprise

Scope specification, board-format reporting

  • PO-ready, flexible billing
Full pricing, line by lineQuotes on WhatsApp · +94 71 055 5055

No sales pitch: describe the problem, an engineer replies

Ready when
you are.

Ryan answers within 24 hours · ryan@ghosts.lk