Synthetic and path
ICMP, TCP, UDP, DNS, HTTP, voice and browser checks, plus MPLS-aware traces on a map.
From BGP routes crossing the open internet down to packets inside your kernel, probectl gathers five planes of signal and folds them into one correlated incident: synthetic, routing, flow, device and eBPF. Self-hosted, so the signal is yours alone.
The console in your browser on sample data: no signup, no backend, nothing sent.
For network and platform teams who want one incident instead of five dashboards, and for MSPs serving many hard-isolated tenants from one deployment. Built for regulated and sovereignty-conscious organizations, in finance, healthcare, public sector, defense and critical infrastructure, that cannot send telemetry to a third-party cloud.
Every tenant sees the probectl product; there is no per-tenant rebranding. Per-tenant metering, audited break-glass, siloed and hybrid isolation and the provider plane are commercial tiers. The provider plane →
Each plane is gathered by your own agents. Routing is the exception by nature: it reads public route-collector feeds, because the subject is the open internet.
ICMP, TCP, UDP, DNS, HTTP, voice and browser checks, plus MPLS-aware traces on a map.
Live RIS and RouteViews watch for hijacks, leaks and origin changes, RPKI-aware.
NetFlow, IPFIX, sFlow and cloud flow logs: top talkers, capacity and egress anomalies.
SNMP over standard MIBs and streaming gNMI: interface health, errors and capacity.
A kernel sensor that maps service dependencies with no app changes, Linux 5.8 and newer.
OTLP metrics, traces and logs in and out, on pinned, conformance-tested conventions.
“Berlin says the app is slow. Network, path, or server?”
Synthetic probes, ECMP and MPLS-aware path discovery and flow analytics show where the latency lives, not just that it exists.
“Is it us, or the user's WiFi?”
The endpoint agent measures WiFi link health, the local gateway and the ISP path, then attributes the slowdown to the closest impaired layer. Access-point identifiers and last-mile hop addresses stay off unless you turn them on.
“Did the 14:03 deploy cause this?”
Change intelligence correlates deployment and configuration events with the symptoms that followed them.
“Why did this prefix go dark, us or the internet?”
Routing intelligence from RouteViews and RIPE RIS, RPKI validity and a collective outage view separate a you-problem from an everyone-problem.
“What breaks if I drain this node?”
The topology graph is versioned, so a what-if removes a node or link at any point in its history and reports which paths break and which reroute, with the coverage behind that answer stated.
“Who is saturating this link, and what does it cost?”
Flow top talkers plus egress attributed to services and teams, priced against list rates. It is an attribution model, not a billing reconciliation.
A flare on the map is not an answer. probectl folds every plane's signal into one tenant-scoped incident, walks the live topology to find the cause, and cites the evidence behind each step.
A route change, a path shift and an egress spike become one story rather than three pages.
Every claim links to the exact signal that supports it. A reading you can audit.
It reads the network and explains it. Remediation is human-gated, and the detection engine emits signals rather than blocking traffic.
Most AI-powered observability sends your telemetry to someone else's model and returns prose. probectl's assistant is built the other way around: it answers only with citations to signals you are allowed to see, and runs air-gapped by default.
Every claim links to a real incident or change event. Ungrounded model output is rejected before you see it, and not knowing is a first-class answer.
A deterministic built-in engine with no model at all, then a model on your own hardware: Ollama directly, or vLLM through the OpenAI-compatible adapter. A hosted model requires an operator acknowledgment at configuration time and the tenant's own consent, and every call that leaves is audited.
An MCP server hands the live network to Claude or any MCP client as eight tenant-scoped tools: read-only queries, analysis, and one proposal-only remediation. The AI sees exactly what its token's user may see.
probectl is not another hosted agent fleet. The difference is where the data lives, and how many planes it correlates for you.
Hosted platforms work by shipping your telemetry to the vendor's cloud. probectl keeps every signal inside your perimeter and folds routing, flow, device and eBPF into one correlated incident.
A great dashboard layer, but you assemble and correlate the planes yourself. probectl ships them already folded into one tenant-scoped incident, and still serves your dashboards through a Prometheus-compatible datasource and exports OTLP.
Most stop at flow or device. probectl spans synthetic, routing, flow, device and eBPF, with cross-plane root cause and an answer that cites its evidence.
The evaluation stack on the left is real: sample data, loopback only, one command to a live service map. Production is the same idea grown up, with one static binary per agent, Docker or Helm, and HTTPS by default. Single-tenant for one team, or multi-tenant for a provider.
Business Source License 1.1: run it in production free, with no signed license; each release converts to MPL 2.0 four years after it ships. Licensing →
The five-plane core is free. Enterprise adds the FIPS build, bring-your-own-key, governance, guarded remediation, HA support and siloed isolation; MSP adds the provider plane and metering. See editions.
Every image, binary, checksum file and bill of materials is signed with cosign and verified in the job that built it. The release workflow →
Tenant isolation is enforced by the database with forced row-level security, checked at boot, and a cross-tenant suite runs on every change. How tenants are isolated →
Your telemetry stays inside your perimeter. No vendor endpoint exists in the source, every optional feed ships disabled, license checks are offline signature math, and a documentation gate fails the build if that promise drifts. The claims gate →
One signed tarball carries every image, chart, binary and package across the gap, the chart renders with no network access at all, and agents install offline and download nothing. The air-gapped install →
Public routing feeds need a path out; the synthetic, flow, device and eBPF planes and the built-in AI run inside.
probectl is pre-1.0 and in active development. Scale and multi-region figures are labeled provisional until reference-hardware runs are recorded, and the docs keep a standing list of what is served, what is built but not yet served, and what is a deliberate non-goal. Limitations and non-goals → · Report an issue →
probectl’s code is reviewed with OpenAI Daybreak, the vetted-defender program the founder was approved for in 2026.
Clone it, run the eval stack, and you are on a live service map in minutes. No waitlist, no sales call, and no promise it is finished.