Operations and IoT WiFi: a personal WiFi key per device, so one leak opens one device
Devices with no screen and no certificate store join with a MAC-bound key and sit on their own VLAN. People sit on EAP-TLS or directory groups, and visitors and agency staff use the open network or time-limited keys.
- 80,000+ venues in 90 countries
- 1,000+ connectors
- 99.9% RADIUS uptime SLA
Operations and IoT
Operations and IoT: pick your estate
Risk leads: one leaked shared password exposes every device on it, a key per device exposes one.
Smart buildings and IoT
One leaked shared password exposes every device on it, so each lift controller, EV charger and camera gets its own MAC-bound key and VLAN: one leak opens one device, and a device with no screen and no certificate store never needs either.Warehouses and logistics
A certificate has an expiry, and a scanner that sat in its cradle all off-season meets it on the first shift of peak, so scanners, robots and vehicle terminals get a MAC-bound key with no certificate to renew, and agency staff arrive in bulk and end on a date.Film and TV studios
Productions arrive, run for a contract's length and leave, and each needs its own VLAN on the lot's shared access points with keys that end when the contract does, so the studio never builds a network per shoot.Ports
A port is many legal entities on one authority's infrastructure, the airport model: each terminal operator and agent gets its own VLAN and key set, gate and crane systems sit on locked-down device keys, and visiting hauliers get keys that end with the visit.
Use cases
The problems that thread these estates
IoT and devices with no screen
A device with no screen or certificate still gets its own MAC-bound key and VLAN.Contractors and visitors
Access that ends on its date: a portal for visitors, a time-limited key for contractors.Card payments and compliance
Payment and clinical devices on their own keys and VLANs, with a log to prove it.
FAQ
Questions IT leads ask
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
What happens when one device is compromised?
Its key is revoked alone, and a RADIUS CoA ends its live session on access points that support it. Every other device keeps its own key and its own VLAN, so the blast radius is one device.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
Book a demo: we issue and revoke a key on a live network
Bring the list of what connects to your network. We issue a key, bind it to a device, place it on its VLAN and revoke it on a live network, on the access points you already own.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.