The pillar
Artificial Intelligence Development & AI Agents
Ghost Protocol is a Colombo software company that builds artificial intelligence into systems people actually run: AI agents, automation, MCP servers, and retrieval pipelines.
We build on Cloudflare Workers AI and Claude, we publish our own AI memory product, and we use AI inside our own security testing. A small senior team, a member of the NVIDIA Inception program, delivering worldwide from Sri Lanka.
What we do with AI
We build artificial intelligence into software that has a job to do. In practice that is agents and automation for clients, chat assistants and retrieval systems over their own data, MCP servers that give an assistant a proper surface onto a business, and the AI engine we run inside our own penetration tests. We also produce AI video and creative work. One team does all of it, and the same team has to live with what it ships.
What we hand over is a system on infrastructure you control, not a demo and not a subscription with our name on it. It runs on Cloudflare’s edge by default, on Claude and Cloudflare Workers AI, or on open models running locally where the data is not allowed to leave. At the end you get the code, the prompts, the deployment and a runbook.
We are a small senior team in Colombo, Sri Lanka, founded in 2024, and a member of the NVIDIA Inception program. Clients are in Sri Lanka and abroad, and the work is delivered remotely either way.
The rest of this page is the detail: the six lines of work, the two AI products we run ourselves, how an engagement is actually sequenced, and the things we will not claim. If you already know the shape of your problem, the automation page is aimed at repeating work, and the Sri Lanka page covers the local side.
The two we run ourselves
The most useful thing we can show you is not a slide. It is the two AI systems we depend on every day, both public, both built here.
Client work and the engineering behind it sit in the case studies and the portfolio. How Wyrm differs from the alternatives is set out on the comparison page.
How a build runs
Five steps, in this order. The prototype comes before the build because the fastest way to learn that an idea does not survive real data is to put it in front of real data.
What we do not claim
Three things this page could easily have said and does not, because they would not survive a first meeting.
We do not train foundation models. Ghost Protocol builds on models other people train: Claude, the models available through Cloudflare Workers AI, and open models run locally with Ollama where the data cannot leave the machine. Machine learning research is a different discipline, and if your problem genuinely needs a model trained from scratch we will say so on the first call rather than in month three.
We do not sell AI as the answer to a process nobody has written down. If the rule lives in one person’s judgement and shifts case by case, automating it makes the inconsistency faster rather than smaller. Writing the process down is sometimes the whole fix, and that is a cheaper answer than the one we would be paid for.
We do not quote a number before scoping the work. The fixed prices published on this site are for security testing, where the scope is a known shape. An AI build is quoted against a written scope, and the first conversation costs nothing.
The same team tests it
An agent is an authenticated user holding tools. Give one broad permissions over your systems and you have not added a feature, you have added a fast path for anyone who can talk to it. Prompt injection is not an exotic risk in that setting. It is the ordinary case where untrusted text reaches something that can act.
So the boundary is part of the build rather than a review at the end. The people who write the agent are the people who run our penetration tests, and the method we test by is published in full. If you want a read on your current exposure before any of this starts, the free Ghost Scan takes about a minute and needs no signup.
Frequently asked
Closer to a specific problem? AI automation for repeating work, AI development in Sri Lanka for the local side, or everything else we build.
Six lines of work, one team: AI agents and automation, MCP servers, chat assistants, retrieval and RAG systems, AI-assisted security testing, and AI video and creative production. We build on Cloudflare Workers AI and Claude, and we publish our own AI memory product, Wyrm, as an MCP server on npm.
An agent is software that is given a goal, a set of tools it may call, and a boundary it may not cross, and that works through the steps itself. It is worth building when the same multi-step task runs often, the inputs vary enough that a plain script keeps breaking, and a person reviews the output before anything irreversible happens. If one of those three is missing, a script or a form is usually the better answer, and we will say so.
No. We build on models trained by others: Claude for reasoning-heavy work, the models available through Cloudflare Workers AI, and open models run locally with Ollama when data cannot leave your machine. Machine learning research is not our line of work, and we will tell you at the first call if a problem genuinely needs a model trained from scratch.
Claude where the reasoning has to hold, Cloudflare Workers AI for inference at the edge, and local open models through Ollama where data residency matters. The system around the model is usually Cloudflare Workers, D1 and R2, the same edge stack the rest of our software runs on.
Yes. Wyrm is our AI memory and intelligence layer: an MCP server that gives assistants like Claude, Cursor and Copilot memory that survives the session. It is published on npm as wyrm-mcp and listed on the official MCP Registry as lk.ghosts/wyrm. It is free to use and local-first.
Wherever you decide, and it is decided in writing before anything is built. The default is your own infrastructure: your Cloudflare account, your database, your keys. Where nothing may leave your environment at all, we build against open models you host yourself.
There is no list price, and we will not invent one before we understand the work. The fixed prices published on this site cover security testing. An AI build is quoted against a written scope after the first call, which is free and takes fifteen minutes.
By deciding the boundary first. What it may read, write and send, and what always needs a person, are settled before the build rather than patched afterwards. An agent is an authenticated user holding tools, so it gets read the way we read any other authenticated user, by the same people who run our penetration tests.
Yes. We are based in Colombo and deliver remotely worldwide. The Colombo base keeps senior engineering affordable; the scope, the method and the handover are the same wherever the client sits.
Tell us what the work actually is.
One process, one repeating task, or one product that needs to remember. Send a brief and you get an engineer’s read on whether AI is the right tool for it, including when the answer is no.
