Social housing: a personal WiFi key per household, staff on EAP-TLS, visitors on the portal
Digital inclusion at estate scale. Each household gets one xPSK key and its own VLAN or role, housing officers sign in on EAP-TLS, hubs and community rooms use the portal, and communal systems keep their own keys. One authentication log across every block, on the access points you already own.
- ~1 million residents on Purple
- 60% fewer helpdesk tickets at move-in
- ISO 27001 and Cyber Essentials Plus
Who is on the social housing network
Who connects across a social housing estate, and where each one lands
No broadband contract or credit check anywhere in the lifecycle: the landlord holds the uplink, a key per household is the only credential, and it works across scattered blocks on whichever controllers each was built with.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Partner agency staff and support workers on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Visitors and groups in community rooms and neighbourhood hubs | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in, session expires on timeout |
| Housing officers and support workers on managed devices | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Tenant households | xPSK | Individual key, MAC-bound (one key per household, no account to create) | A VLAN or role per household | Issued at sign-up, revoked at the end of the tenancy |
| Communal door entry, CCTV and lift controllers | xPSK | Individual key, MAC-bound (bound to the device's MAC) | A building-systems VLAN, unreachable from households | One key per device, revoked when the device is swapped |
| Repairs operatives and contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A contractor VLAN and bandwidth limit per key | Ends on the day the job does |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Social housing: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Community rooms, hubs and partner phones: portal and onboarding lane
A community room is a public space, so it gets the guest lane and never a household's VLAN. Partner agencies' staff use the onboarding lane without enrolling in your device management.
- Community rooms and hubs on the portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA and client isolation on. Under 15 minutes to add the splash URL and RADIUS to a controller.
- Partner and support staff with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
Housing officers and support workers: EAP-TLS and directory groups
One WPA-Enterprise SSID per site. Cloud RADIUS checks the directory and returns the VLAN for the group, so housing management, repairs and support each land in their own lane.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once, for the whole organisation.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every estate stops authenticating them.
Households and communal systems: a key each, on its own VLAN
A tenant's phone has no account with you and should not need one. A key is an ordinary WPA2-Personal passphrase to the device, so nothing has to be created, installed or paid for first.
- A household online with no broadband contract or credit check. The landlord holds the uplink and the access points. The household's key is issued like any other credential, so there is no retail account, no credit check and no installer visit.
- Scattered blocks, mixed controllers, one platform. Blocks built in different decades run different access point brands. Each vendor's per-device key feature has its own name, and Purple runs all of them from one platform.
- Communal systems on their own keys. Door entry, CCTV and lift controllers sit on a building-systems VLAN a household cannot reach, and each is revoked alone when swapped.
- Repairs operatives with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
Lifecycle
Sign-up to end of tenancy: one key per household, issued by the landlord
The system of record is your housing management system and the tenancy. The key carries no account, so the lifecycle is issue, place, watch and withdraw.
Issue at sign-up
Create the household's key at sign-up or at the first visit, from the console, in bulk for a newly handed-over block, or through the Purple API from your own housing system. Communal systems are keyed once, at commissioning.
Place each household on its own VLAN
RADIUS returns the VLAN, role or group policy, depending on each block's vendor. The access points enforce it, and rules between VLANs live on your gateway.
Operate every estate from one log
Every accept and reject carries its reason, by block, household and device, whichever access point brand answered, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
Withdraw one key when the tenancy ends
The household's key is revoked and its live session ended with RADIUS CoA on access points that support it. Communal systems and every other household stay connected.
One authentication log
One authentication log across every estate and controller brand
A mixed estate usually means a console per brand and no single view. One RADIUS gives one record, whichever access point answered.
- Which households' keys have never authenticated, so outreach goes to the right doors.
- Which communal systems are authenticating at each block, and on which VLAN.
- Why a device was rejected: a revoked key, an expired key or an unbound MAC address.
- Which repairs keys are still live after the job closed.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Resident networks at scale
About 1 million students and residents run on Purple's community networks, and Purple holds ISO 27001 and Cyber Essentials Plus.
- ~1M
- students and residents on Purple community networks
- 60%
- fewer helpdesk tickets at move-in, US university housing across 40 buildings
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points across our estates?
No. Purple Access is a cloud overlay on the access points your estates already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
How does a household get WiFi with no contract and no credit check?
The landlord provides the uplink and the access points, and the key is a credential you issue and revoke, not a retail account. There is no tenant sign-up with a provider, no credit check and no engineer visit.
How does a tenant who does not use email get connected?
A key is an ordinary WPA2-Personal passphrase to the device, so a housing officer can read it out, write it down or print it with the sign-up pack. There is no account, address or app to set up before a device joins.
Our blocks run three different controller brands. Is that one platform?
Yes. Each vendor ships per-device keys under its own name, and Purple runs all of them from one platform, so the estate keeps one RADIUS, one dashboard and one log.
Does this suit council housing and housing association stock alike?
Yes. The platform keys on the household and the device, not on the landlord's legal form, so council housing and housing association blocks use the same model, and one RADIUS and one log cover whichever you run.
Book a demo: we issue and revoke a key on a live network
Bring one block's worth of devices: a tenant's phone, a door entry panel, a housing officer's laptop and a contractor's phone. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.