A ctlplne studio product
Network observatory

One vantage point for the entire network.

From BGP routes crossing the open internet down to packets inside your kernel, probectl gathers five planes of signal and folds them into one correlated incident: synthetic, routing, flow, device and eBPF. Self-hosted, so the signal is yours alone.

5signal planes
0phone-home, ever
Source-availablethe five-plane core is free
01 Who runs it

Two ways to run the same observatory.

The same five-plane core and the same self-hosted promise, pointed at one network or at many.

For platform and netops teams

Stand up one tenant and get a correlated view across synthetic, routing, flow, device and eBPF, with cross-plane root cause and an MCP server for your own AI tools. Self-hosted, so no telemetry leaves your network.

For MSPs and providers

Run it once and serve many hard-isolated tenants: pooled, siloed or hybrid isolation per tenant, with per-tenant metering, and break-glass that is explicit, time-bounded and separately audited. Every tenant sees the probectl product; there is no per-tenant rebranding, by design.

02 Signals

Five signals. One incident.

Each plane is gathered by your own agents, with no third-party collector in the path. Routing is the exception by nature: it reads public route-collector feeds, because the subject is the open internet.

01 · Active

Synthetic and path

ICMP, TCP, UDP, DNS, HTTP, agent-to-agent, voice quality and scripted browser checks, plus ECMP and MPLS-aware hop-by-hop traces with a geographic path view.

02 · Routing

BGP intelligence

Live RIS and RouteViews monitoring for hijacks, leaks and origin changes, RPKI-aware, with ASN and geographic context.

03 · Flow

Flow analytics

Passive NetFlow, IPFIX and sFlow, plus AWS, Azure and GCP flow logs your own export pipeline already writes. Top talkers, link capacity and egress anomalies, with sampling corrected.

04 · Device

Device telemetry

SNMP over standard MIBs plus streaming gNMI and OpenConfig: interface health, errors and capacity. A box that lacks a table yields fewer metrics rather than failing the poll.

05 · Kernel

eBPF · L3 to L7

A kernel sensor that maps service dependencies from L3 to L7 with no application changes, on Linux 5.8 and newer. It observes and never blocks.

+ correlation

All on one OpenTelemetry-native control plane.

Semantic conventions are pinned and conformance-tested, and OTLP metrics, traces and logs move in both directions: probectl ingests them and re-exports them to your collector.

03 Answers

Built for the questions you ask at 2 a.m.

“Berlin says the app is slow. Network, path, or server?”

Synthetic probes, ECMP and MPLS-aware path discovery and flow analytics show where the latency lives, not just that it exists.

“Is it us, or the user's WiFi?”

The endpoint agent measures WiFi link health, the local gateway and the ISP path, then attributes the slowdown to the closest impaired layer. Access-point identifiers and last-mile hop addresses stay off unless you turn them on.

“Did the 14:03 deploy cause this?”

Change intelligence correlates deployment and configuration events with the symptoms that followed them.

“Why did this prefix go dark, us or the internet?”

Routing intelligence from RouteViews and RIPE RIS, RPKI validity and a collective outage view separate a you-problem from an everyone-problem.

“What breaks if I drain this node?”

The topology graph is versioned, so a what-if removes a node or link at any point in its history and reports which paths break and which reroute, with the coverage behind that answer stated.

“Who is saturating this link, and what does it cost?”

Flow top talkers plus egress attributed to services and teams, priced against list rates. It is an attribution model, not a billing reconciliation.

04 Correlation

From signal to cause.

A flare on the map is not an answer. probectl folds every plane's signal into one tenant-scoped incident, walks the live topology to find the cause, and cites the evidence behind each step.

Traced across planes

A route change, a path shift and an egress spike become one story rather than three pages.

Cited, never guessed

Every claim links to the exact signal that supports it. A reading you can audit.

Observe-only by default

It reads the network and explains it. Remediation is human-gated, and the detection engine emits signals rather than blocking traffic.

observation log · incident 4471sample
14:01:48Z api-gateway p99 latency +6.2×
14:02:11Z bgp origin change observed, AS64500
14:02:13Z path +2 hops via transit
14:02:20Z flow egress +340% · 203.0.113.0/24
14:02:34Z ebpf retransmits up · svc/gateway
 
resolved cause: AS64500 origin change
confidence high · 1 incident, not 31 alerts
05 Beyond the planes

The five planes are the floor, not the product.

Everything on this page is in the free, source-available core. The commercial editions add the FIPS build, bring-your-own-key, governance and support, plus the provider plane and metering for MSPs.

Real user monitoring

Core Web Vitals from real browsers, consent-gated, with no visitor address ever stored, joined against the synthetic tests watching the same host.

TLS posture

Nine certificate and protocol findings read from traffic probectl already captured, so nothing is re-handshaked and no scanner touches your estate.

Detections, not enforcement

Six shipped detectors for beaconing, DNS exfiltration, hostile egress and lateral fan-out. They raise signals; there is no enforcement surface anywhere in the package.

Service level objectives

Import and export OpenSLO v1 definitions, with error budgets and multi-window multi-burn-rate alerting.

Segmentation evidence

Declare zones and forbidden flows; probectl validates them against observed traffic and answers violation, clean, or not observed. It never claims you are compliant.

Grafana and Prometheus

A Grafana datasource, a federation endpoint, and remote-write ingest, so probectl fits the dashboards you already run.

Cost and carbon

Observed egress attributed to services and teams, and a carbon estimate from published coefficients that reports itself as an estimate rather than a measurement.

Identity and ticketing

SCIM 2.0 provisioning, read-only ServiceNow and NetBox correlation, five SIEM presets, and seven on-call and ITSM connectors that carry acknowledgement and resolution back onto the incident.

Infrastructure as code

A Terraform provider with four resources and six data sources, Helm charts, ArgoCD and Flux manifests, and signed packages.

06 AI

Ask your network. It answers with evidence.

Most AI-powered observability sends your telemetry to someone else's model and returns prose. probectl's assistant is built the other way around: it answers only with citations to signals you are allowed to see, and runs air-gapped by default.

Cited, or silent

Every claim links to a real incident or change event. Ungrounded model output is rejected before you see it, and not knowing is a first-class answer.

The sovereignty ladder

A deterministic built-in engine with no model at all, then a model on your own hardware through the OpenAI-compatible adapter, which is how Ollama and vLLM are used. A hosted model requires an explicit written opt-in, and every call is audited.

Your AI, your map

An MCP server hands the live network to Claude or any MCP client as eight tenant-scoped tools: read-only queries, analysis, and one proposal-only remediation. The AI sees exactly what its token's user may see.

ask probectl · /v1/ai/asksample
you why is checkout slow?
 
root_cause AS64500 origin change shifted the egress path
grounded true · confidence high
cites incident 4471 · change event 8821
engine: builtin (air-gapped) · no data left the network
07 Perimeter

The signal never leaves the room.

probectl is self-hosted by design. Your telemetry stays inside your perimeter, and there is no phone-home, down to licence checks, which are offline signature math. Point the assistant at a local model and the whole observatory runs air-gapped.

No phone-home

No vendor endpoint appears in the source, every optional external feed ships disabled, and a documentation gate binds that promise to the code and fails the build if it drifts.

Local AI

Run root-cause analysis against a model on your own hardware. Nothing crosses the perimeter.

mTLS everywhere

Every agent-to-control-plane channel is mutually authenticated and encrypted, with SPIFFE-style agent identity, and every listener requires TLS.

FIPS-ready

Builds can link the FIPS 140-3 validated Go cryptographic module. probectl itself holds no product-level certificate.

08 Alternatives

If you already watch your network.

probectl is not another hosted agent fleet. The difference is where the data lives, and how many planes it correlates for you.

vs. Kentik or ThousandEyes

Both are excellent, and both send your telemetry to someone else's cloud. probectl keeps every signal inside your perimeter and folds routing, flow, device and eBPF into one correlated incident.

vs. Grafana and Prometheus

A great dashboard layer, but you assemble and correlate the planes yourself. probectl ships them already folded into one tenant-scoped incident, and still speaks to Grafana as a datasource and exports OTLP.

vs. a hosted network monitor

Most stop at flow or device. probectl spans synthetic, routing, flow, device and eBPF, with cross-plane root cause and an answer that cites its evidence.

~ / first data in one commandeval stack
$ docker compose -f deploy/compose/eval.yml up --build -d
 
control plane online loopback only · eval stack
eBPF agent replaying labelled sample flows · no kernel needed
 
$ docker compose -f deploy/compose/eval.yml \
  --profile tools run --rm viewer
"edges": [{ "from": "service:10.0.1.5", … }]
→ your first data: a live service map
09 Deploy

Command the observatory.

Source-available and self-hosted. The evaluation stack on the left is real: sample data, loopback only, one command to a live service map. Production is the same idea grown up, with one static binary per agent, Docker or Helm, and HTTPS by default. Single-tenant for one team, or multi-tenant for a provider.

source-available docker / helm argocd / flux multi-tenant MCP server OpenTelemetry / OTLP terraform provider

The five-plane core is free. Enterprise adds the FIPS build, bring-your-own-key, governance and guarded remediation; Provider adds the management plane and metering. See editions.

10 Trust

Built like infrastructure, not a demo.

Signed releases

Every image, binary, checksum file and bill of materials is keyless-signed with cosign and verified inside the same job that produced it.

SBOM and provenance

Images carry build provenance and SBOM attestations, and each release ships an SPDX bill of materials for the source tree.

Isolation, gated in CI

Tenant isolation is enforced by the database with forced row-level security, checked at boot, and a cross-tenant suite runs on every change: a query crossing a tenant line fails the build, not the customer.

No silent access

Provider operators get no implicit access to tenant telemetry. Break-glass is explicit, time-bounded and separately audited, and the security policy puts that bypass in scope for reports.

Accessible by gate

The console holds a WCAG 2.2 AA baseline checked against a real browser in continuous integration.

Claims that answer to code

The product's documentation is bound to its source by a gate that fails the build when a sentence outruns what the code does. This page is governed the same way.

probectl is pre-1.0 and in active development. Scale and multi-region figures in the documentation are labelled provisional until reference-hardware runs are recorded, and the docs keep a standing list of what is served, what is built but not yet served, and what is a deliberate non-goal.

probectl.com

Claim your vantage point.

Source-available and self-hosted. Clone it, run the eval stack, and you are on a live service map in minutes. No waitlist, no sales call.