A ctlplne studio product Alpha · probectl is pre-1.0 and in active development. What that means →
Network observatory alpha

One vantage point for the entire network.

From BGP routes crossing the open internet down to packets inside your kernel, probectl gathers five planes of signal and folds them into one correlated incident: synthetic, routing, flow, device and eBPF. Self-hosted, so the signal is yours alone.

The console in your browser on sample data: no signup, no backend, nothing sent.

5signal planes
0phone-home, ever
Source-availableBSL 1.1 core, free to run in production
Reviewed with OpenAI DaybreakOpenAI’s vetted-defender program.
01 Who runs it

One network, or many.

For network and platform teams who want one incident instead of five dashboards, and for MSPs serving many hard-isolated tenants from one deployment. Built for regulated and sovereignty-conscious organizations, in finance, healthcare, public sector, defense and critical infrastructure, that cannot send telemetry to a third-party cloud.

Every tenant sees the probectl product; there is no per-tenant rebranding. Per-tenant metering, audited break-glass, siloed and hybrid isolation and the provider plane are commercial tiers. The provider plane →

02 What it sees

Five signals. One incident.

Each plane is gathered by your own agents. Routing is the exception by nature: it reads public route-collector feeds, because the subject is the open internet.

01 · Active

Synthetic and path

ICMP, TCP, UDP, DNS, HTTP, voice and browser checks, plus MPLS-aware traces on a map.

02 · Routing

BGP intelligence

Live RIS and RouteViews watch for hijacks, leaks and origin changes, RPKI-aware.

03 · Flow

Flow analytics

NetFlow, IPFIX, sFlow and cloud flow logs: top talkers, capacity and egress anomalies.

04 · Device

Device telemetry

SNMP over standard MIBs and streaming gNMI: interface health, errors and capacity.

05 · Kernel

eBPF, L3 to L7

A kernel sensor that maps service dependencies with no app changes, Linux 5.8 and newer.

+ one model

OpenTelemetry-native

OTLP metrics, traces and logs in and out, on pinned, conformance-tested conventions.

03 Answers

Built for the questions you ask at 2 a.m.

“Berlin says the app is slow. Network, path, or server?”

Synthetic probes, ECMP and MPLS-aware path discovery and flow analytics show where the latency lives, not just that it exists.

“Is it us, or the user's WiFi?”

The endpoint agent measures WiFi link health, the local gateway and the ISP path, then attributes the slowdown to the closest impaired layer. Access-point identifiers and last-mile hop addresses stay off unless you turn them on.

“Did the 14:03 deploy cause this?”

Change intelligence correlates deployment and configuration events with the symptoms that followed them.

“Why did this prefix go dark, us or the internet?”

Routing intelligence from RouteViews and RIPE RIS, RPKI validity and a collective outage view separate a you-problem from an everyone-problem.

“What breaks if I drain this node?”

The topology graph is versioned, so a what-if removes a node or link at any point in its history and reports which paths break and which reroute, with the coverage behind that answer stated.

“Who is saturating this link, and what does it cost?”

Flow top talkers plus egress attributed to services and teams, priced against list rates. It is an attribution model, not a billing reconciliation.

04 Correlation

From signal to cause. One incident, not thirty-one alerts.

A flare on the map is not an answer. probectl folds every plane's signal into one tenant-scoped incident, walks the live topology to find the cause, and cites the evidence behind each step.

Traced across planes

A route change, a path shift and an egress spike become one story rather than three pages.

Cited, never guessed

Every claim links to the exact signal that supports it. A reading you can audit.

Observe-only by default

It reads the network and explains it. Remediation is human-gated, and the detection engine emits signals rather than blocking traffic.

observation log · incident 4471sample
14:01:48Z api-gateway p99 latency +6.2×
14:02:11Z bgp origin change observed, AS64500
14:02:13Z path +2 hops via transit
14:02:20Z flow egress +340% · 203.0.113.0/24
14:02:34Z ebpf retransmits up · svc/gateway
 
resolved cause: AS64500 origin change
confidence high · 1 incident, not 31 alerts
05 AI

Ask your network. It answers with evidence.

Most AI-powered observability sends your telemetry to someone else's model and returns prose. probectl's assistant is built the other way around: it answers only with citations to signals you are allowed to see, and runs air-gapped by default.

Cited, or silent

Every claim links to a real incident or change event. Ungrounded model output is rejected before you see it, and not knowing is a first-class answer.

The sovereignty ladder

A deterministic built-in engine with no model at all, then a model on your own hardware: Ollama directly, or vLLM through the OpenAI-compatible adapter. A hosted model requires an operator acknowledgment at configuration time and the tenant's own consent, and every call that leaves is audited.

Your AI, your map

An MCP server hands the live network to Claude or any MCP client as eight tenant-scoped tools: read-only queries, analysis, and one proposal-only remediation. The AI sees exactly what its token's user may see.

ask probectl · /v1/ai/asksample
you why is checkout slow?
 
root_cause AS64500 origin change shifted the egress path
grounded true · confidence high
cites incident 4471 · change event 8821
engine: builtin (air-gapped) · no data left the network
07 If you already run something

Where probectl fits next to the tools you have.

probectl is not another hosted agent fleet. The difference is where the data lives, and how many planes it correlates for you.

Next to hosted network observability

Hosted platforms work by shipping your telemetry to the vendor's cloud. probectl keeps every signal inside your perimeter and folds routing, flow, device and eBPF into one correlated incident.

Next to a dashboard stack

A great dashboard layer, but you assemble and correlate the planes yourself. probectl ships them already folded into one tenant-scoped incident, and still serves your dashboards through a Prometheus-compatible datasource and exports OTLP.

Next to a flow or device monitor

Most stop at flow or device. probectl spans synthetic, routing, flow, device and eBPF, with cross-plane root cause and an answer that cites its evidence.

~ / first data in one commandeval stack
$ docker compose -f deploy/compose/eval.yml up --build -d
 
✓ control plane online loopback only · eval stack
✓ eBPF agent replaying labeled sample flows · no kernel needed
 
$ docker compose -f deploy/compose/eval.yml \
  --profile tools run --rm --no-deps viewer
"edges": [{ "from": "service:10.0.1.5", … }]
→ your first data: a live service map
08 Deploy

Run it yourself.

The evaluation stack on the left is real: sample data, loopback only, one command to a live service map. Production is the same idea grown up, with one static binary per agent, Docker or Helm, and HTTPS by default. Single-tenant for one team, or multi-tenant for a provider.

Business Source License 1.1: run it in production free, with no signed license; each release converts to MPL 2.0 four years after it ships. Licensing →

source-available docker / helm argocd / flux multi-tenant MCP server OpenTelemetry / OTLP terraform provider

The five-plane core is free. Enterprise adds the FIPS build, bring-your-own-key, governance, guarded remediation, HA support and siloed isolation; MSP adds the provider plane and metering. See editions.

06 Why you can trust it

Four receipts, not a promise.

Signed releases

Every image, binary, checksum file and bill of materials is signed with cosign and verified in the job that built it. The release workflow →

Isolation tested in CI

Tenant isolation is enforced by the database with forced row-level security, checked at boot, and a cross-tenant suite runs on every change. How tenants are isolated →

Runs where the internet doesn’t.

Your telemetry stays inside your perimeter. No vendor endpoint exists in the source, every optional feed ships disabled, license checks are offline signature math, and a documentation gate fails the build if that promise drifts. The claims gate →

One signed tarball carries every image, chart, binary and package across the gap, the chart renders with no network access at all, and agents install offline and download nothing. The air-gapped install →

Public routing feeds need a path out; the synthetic, flow, device and eBPF planes and the built-in AI run inside.

Status: alpha

probectl is pre-1.0 and in active development. Scale and multi-region figures are labeled provisional until reference-hardware runs are recorded, and the docs keep a standing list of what is served, what is built but not yet served, and what is a deliberate non-goal. Limitations and non-goals → · Report an issue →

probectl’s code is reviewed with OpenAI Daybreak, the vetted-defender program the founder was approved for in 2026.

probectl.com

Run the alpha. Tell us what breaks.

Clone it, run the eval stack, and you are on a live service map in minutes. No waitlist, no sales call, and no promise it is finished.