pathproof by badnetworks

Continuous path-quality monitoring

Prove it's the network. Or prove it isn't.

Pathproof watches the actual capacity and available bandwidth of every network path you care about — continuously, from distributed vantage points, at kilobits per second of probe traffic. When users say “the network is bad,” you'll know how, where, and since when — with numbers that carry their own evidence.

HQ → payments-api.example — 30 days probe load 41 Kb/s avg · mode 1 (agent ↔ agent)
Days 12–15: available bandwidth collapsed to ~210 Mb/s. Capacity never moved. That's congestion on the path — not a failing link, not a provider downgrade — and it's the difference between opening a peering conversation and replacing hardware that was never broken.
Chart data as text

Capacity holds between 918 and 947 Mb/s for all 30 days. Available bandwidth varies 610–780 Mb/s on normal days, drops to 205–260 Mb/s on days 12 through 15 (marked as the incident window), then recovers.

Three ways a path goes bad. One chart tells them apart.

A speed test gives you one number that blends them all together. Packet-dispersion measurement separates what the path could carry from what it can carry right now — so the diagnosis is in the data.

capacity low

The slow link

The path's narrow link is smaller than what you're paying for, or a device renegotiated to a lower rate. Capacity is flat — and flat at the wrong number.

reads: capacity < contracted rate, steady

adr sagging

The busy link

Capacity is fine; available bandwidth sags on a schedule or after a routing change. Someone else's traffic is on your narrow link. Evidence for a peering or QoS conversation.

reads: capacity steady, ADR dips

loss / jitter

The broken path

Loss bursts, reordering, jitter spikes, hop-count changes. The dispersion probes carry a full path-health suite alongside the bandwidth brackets.

reads: loss > 0, IPDV up, route shift

How it works

Place vantage points

Drop a lightweight agent at each site — offices, DCs, cloud VPCs. Paths between any two agents get the full double-endpoint methodology; anything else can still be covered by service probes or plain ICMP.

Probe with dispersion, not floods

Packet pairs and short trains read the time-structure of the path: capacity, an available-bandwidth bracket, loss, jitter, reordering. Kilobits per second, continuously — not a saturating test you can only run at night.

Alert on the difference

Baselines per path, alerts when capacity steps down or ADR sags below policy, and reports you can attach to an SLA claim — every number carries its method, confidence, and clock provenance.

Pricing as legible as the measurements

Tokens, not tiers. One token is one day of monitoring and storage for one path. Monitor three circuits for a month, spend ninety tokens — the bill reads like the measurement log.

standard

Tokens

Continuous monitoring and storage, one token per path-day. Every plan includes a 90-day archive of full measurement history — raw samples, methods, confidence, provenance.

1 token = 1 path × 1 day · 90-day archive included

premium

Premium license

Everything in standard, with a 1-year archive and circuit analysis: an expert-reviewed report on your circuit's capacity, congestion pattern, and the evidence behind both.

1-year archive · circuit analysis · same tokens

Bring your own S3. Point Pathproof at your bucket and your measurement history lives in storage you own — for long-term analysis, for as long as you decide. It's your evidence; you hold it.

Pathproof is the commercial service from badnetworks, built on Pathrate, our open-source implementation of peer-reviewed packet-dispersion capacity estimation (Dovrolis, Ramanathan & Moore, IEEE/ACM ToN 2004). The measurement core is BSD-licensed and free, forever — the service adds the fleet, the history, the alerting, and the support.

github.com/Pathrate