Skip to content
Industries

Residential WiFi: a personal WiFi key per household, one SSID per building

Households sit on xPSK, one key each with its own VLAN. Prospects and visitors use the open network, and the on-site team signs in on EAP-TLS. One authentication log across every building, on the access points you already own.

  • ~1 million residents on Purple
  • 60% fewer helpdesk tickets at move-in
  • 80,000+ venues in 90 countries
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Residential

Residential: pick your estate

The resident lifecycle is the design problem: a key follows the household, the building's own devices stay up between lets, and one platform runs every building on whichever access point brand is on the ceiling.

  • Build to rent

    Two key lifecycles on one SSID: the household's key follows the occupancy, and the keys for locks, thermostats and leak sensors follow the unit, so a move-out revokes one and never touches the other.
  • Multifamily and apartments

    Bulk internet delivered per unit across a mixed access point estate: the unit is a VLAN or role and not an SSID or a router, with one RADIUS and one dashboard across the portfolio, on any AP brand.
  • Student accommodation

    eduroam stays for 802.1X identity, the key follows the student and not the room, and a summer let is a time-boxed key instead of a second network.
  • Co-living

    Key lifetime equals the booking, from one week to a year, and shared printers and screens are reachable from members' VLANs by gateway policy while private devices never are.
  • Social housing

    No broadband contract or credit check anywhere in the lifecycle: the landlord holds the uplink, a key per household is the only credential, and it works across scattered blocks on whichever controllers each was built with.
  • Military and service family housing

    A posting is a lifecycle event at estate scale: households arrive and leave in batches, so each home is a VLAN and a key issued and revoked in bulk from the allocation list.

Use cases

The problems that thread these estates

FAQ

Questions IT leads ask

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

How does a move-out end access for one household only?

Each household's key is its own entry in RADIUS, bound to its devices by MAC address and placed on its own VLAN. Revoking it ends that household and nothing else, and the building's own locks, thermostats and sensors keep the keys that belong to the unit.

What does revoking one key do to everyone else?

Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.

Book a demo: we issue and revoke a key on a live network

Bring the list of what connects to your network. We issue a key, bind it to a device, place it on its VLAN and revoke it on a live network, on the access points you already own.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.