Skip to content
Industries

Operations and IoT WiFi: a personal WiFi key per device, so one leak opens one device

Devices with no screen and no certificate store join with a MAC-bound key and sit on their own VLAN. People sit on EAP-TLS or directory groups, and visitors and agency staff use the open network or time-limited keys.

  • 80,000+ venues in 90 countries
  • 1,000+ connectors
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Operations and IoT

Operations and IoT: pick your estate

Risk leads: one leaked shared password exposes every device on it, a key per device exposes one.

  • Smart buildings and IoT

    One leaked shared password exposes every device on it, so each lift controller, EV charger and camera gets its own MAC-bound key and VLAN: one leak opens one device, and a device with no screen and no certificate store never needs either.
  • Warehouses and logistics

    A certificate has an expiry, and a scanner that sat in its cradle all off-season meets it on the first shift of peak, so scanners, robots and vehicle terminals get a MAC-bound key with no certificate to renew, and agency staff arrive in bulk and end on a date.
  • Film and TV studios

    Productions arrive, run for a contract's length and leave, and each needs its own VLAN on the lot's shared access points with keys that end when the contract does, so the studio never builds a network per shoot.
  • Ports

    A port is many legal entities on one authority's infrastructure, the airport model: each terminal operator and agent gets its own VLAN and key set, gate and crane systems sit on locked-down device keys, and visiting hauliers get keys that end with the visit.

Use cases

The problems that thread these estates

FAQ

Questions IT leads ask

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

What happens when one device is compromised?

Its key is revoked alone, and a RADIUS CoA ends its live session on access points that support it. Every other device keeps its own key and its own VLAN, so the blast radius is one device.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

Book a demo: we issue and revoke a key on a live network

Bring the list of what connects to your network. We issue a key, bind it to a device, place it on its VLAN and revoke it on a live network, on the access points you already own.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.