The working guide

AI Development Company in Sri Lanka

Ghost Protocol is an artificial intelligence and software company based in Colombo, Sri Lanka. We build AI agents, automation and retrieval systems for Sri Lankan businesses and for clients abroad.

We also publish our own AI product: Wyrm, a memory server used by Claude, Cursor and Copilot. Founded in 2024, a small senior team, and a member of the NVIDIA Inception program. This is the working guide to having AI built here: what it means, what it covers, how the engagement runs, and what the local context actually is.

Start a brief15-min consult: free
COLOMBO
Based in Sri Lanka, LKA
2024
Founded · Ghost Protocol (Pvt) Ltd
WORLDWIDE
Remote delivery, any timezone
Definition

What AI development actually means

Three different things are sold locally under the same words. Buying a subscription to somebody else’s assistant is one. Putting a thin wrapper around a model and calling it a product is the second. Building a system that is wired into your own data, your own rules and your own tools, and that you keep afterwards, is the third. Only the third is development, and it is the one we do.

In practice that means agents that carry a multi-step task, assistants that answer from your documents with the source cited, retrieval pipelines measured against real questions, and MCP servers that give an assistant a typed, auditable surface onto your systems instead of a scrape. The model is one component. Most of the work is the plumbing, the boundary and the evidence that it behaves.

The honest test of a supplier here is simple. Ask which part they wrote, where it runs, who holds the keys, and what you are left with if you stop paying them. Our answer is that you get the code, the prompts, the deployment and a runbook, on infrastructure you control. The pillar page has the full account of what we build with AI.

Scope

What we build here

One team, working in English, from Colombo. In scope by default:

+AI agents that carry a multi-step task end to end
+Customer and internal assistants that answer from your own documents
+MCP servers that give an assistant a typed surface over your systems
+Retrieval and RAG pipelines, with an evaluation set rather than a demo
+Automation wired into the tools your team already uses
+Document intake: reading what arrives, classifying it, routing it
+AI-assisted security testing of what we build
+AI video and image production for launches and campaigns

Three things come out of every engagement, whatever the shape of the build:

  1. The running system

    Deployed on your Cloudflare account or ours, with logs you can read and an obvious way to turn it off.

  2. The evaluation set

    A fixed set of real cases the system is measured against, so a later change can be shown to help rather than argued about.

  3. The handover

    Code, prompts, infrastructure config and a runbook. Your code, your data, your infrastructure.

Not in scope: training a foundation model from scratch, and promising a Sinhala or Tamil quality bar we cannot hold. Both are covered plainly in the questions below. For the security side of the same team, see the penetration testing guide for Sri Lanka.

Demand

Who asks for this here

01ExportersSri Lankan software companies selling abroad that need AI inside the product itself, and need it to survive a customer's security review rather than only a demo call.
02OperationsHospitality, retail, logistics and services where the real system is a spreadsheet and a group chat, and the same task is done fifty times a week by hand.
03Product teamsA team that wants retrieval, an assistant or an agent inside an existing product, built by people who will hand it back rather than sit on top of it.
04StudiosCreative teams that need AI video and image production directed to a standard they can put a client's name on.
Process

How an engagement runs

Five steps, in this order. The prototype sits before the build on purpose: real data is the cheapest way to find out an idea does not work.

  1. The call

    Fifteen minutes, free. What repeats, where the data lives, and what a good outcome looks like in one sentence.

  2. The scope

    Written back to you before anything is built, including what the system may read, write and send, and what always needs a person.

  3. The prototype

    The narrowest version that does the real job on your real data. You use it on live work before we build anything on top of it.

  4. The build

    The working system, on Cloudflare's edge by default, with logs you can read and an evaluation set it has to keep passing.

  5. The handover

    Code, prompts, deployment and a runbook, on infrastructure you control. There is no lock-in step at the end of this.

Context

The Sri Lanka context

A Colombo base is a cost advantage rather than a quality trade-off. Senior engineering here runs at a fraction of US and European rates, which is how a serious build stays affordable without thinning out the seniority on it. The same economics is why our fixed-price security work lands where it does.

Local demand splits two ways. Software companies selling abroad want AI inside the product, and want it to survive a customer security review rather than only a demo. Operations-heavy businesses here want the repeat work absorbed: the questions answered fifty times a week, the spreadsheet that is really the system of record, the queue of documents somebody retypes. That second shape has its own page, on AI automation.

Everything is delivered in English, and we say so rather than implying more. Sri Lanka has no AI-specific statute today, but the Personal Data Protection Act No. 9 of 2022 still governs the personal data an AI system reads, stores or sends. Which obligations actually bind you is a question you can answer for yourself with our obligations tool, and the wider local offering sits on the Sri Lanka services hub.

BASEColombo, Sri Lanka. Founded 2024. Delivery is remote and worldwide.
LANGUAGEEnglish, for every deliverable, document and handover.
REGULATIONNo AI-specific statute here; the PDPA still governs the personal data you touch.
Questions

Frequently asked questions

Yes. Ghost Protocol (Pvt) Ltd is one: a Colombo company founded in 2024 that builds AI agents, automation and retrieval systems, and publishes its own AI memory product on npm. A good deal of what is advertised locally as AI is reselling somebody else's subscription, so ask any supplier which part they wrote, where it runs, and what you are left holding if you stop paying them.

It is quoted per scope. We publish fixed prices for security testing and not for AI builds, because the honest distance between an assistant over one document set and an agent wired into your operations is too wide to print as a number. The first call is free and takes fifteen minutes, and the quote follows a written scope.

A small senior team in Colombo, led by founder-engineer Ryan Sebastian. You talk to the engineer building the thing rather than an account manager, which is the same arrangement as our security work.

We deliver in English, and we will not claim a Sinhala or Tamil quality bar we cannot hold. The models we build on handle both unevenly. If your customers have to be served in those languages, say so at scoping: we will test it against your own examples and tell you where it falls short rather than shipping something that reads badly in a customer's language.

No. Colombo is where the engineering happens; delivery is remote and worldwide. A Sri Lankan base keeps senior engineering affordable without thinning out the seniority on the work, and the scope, method and handover are identical wherever the client sits.

Usually yes, and less of it than people expect. An assistant that answers from your documents needs those documents to exist and to be current. An agent needs the process it is automating to be written down. Where the material is scattered, the first part of the work is making it retrievable, and that is worth doing on its own merits even if the AI never ships.

Cloudflare by default: Workers for the application, Workers AI for inference at the edge, D1 and R2 for data. That is the same stack our own products run on. If it has to run somewhere else, or on hardware you own with a local open model, that is decided at scoping rather than discovered later.

Yes. Most work runs remotely, but for Colombo clients a kickoff or a walkthrough in person is available on request. Start with the free 15-minute call either way.

There is no AI-specific statute in Sri Lanka today. The Personal Data Protection Act No. 9 of 2022 still governs the personal data an AI system reads, stores or sends, and that is the part most projects get wrong. Deciding what the system may touch is part of our scoping step for exactly that reason.

Built in Colombo. Yours at handover.

Send the shape of the problem and you get an engineer’s read on whether AI is the right tool for it. The first call is fifteen minutes and costs nothing.