WiFi visibility: see every authentication, on every network, at every site
One pane of glass across open, secure and xPSK. Accepts and rejects with the reason, device posture and MDM enrolment state, audit answers in minutes, your SIEM fed, Ask AI, and occupancy without a single beacon.
- One estate-wide query
- Sentinel, Splunk, Elastic, Datadog
- ISO 27001 and Cyber Essentials Plus
Authentication log
Every 802.1X authentication, accepts and rejects in one view
One estate-wide query. No per-building exports. No technician driving to site to read a log.
- WhoIdentity and groups, the device, its posture and its MDM enrolment state.
- HowMethod: EAP-TLS, PEAP or individual PSK.
- WhereAccess point, SSID and site.
- What happenedVLAN and role returned, accept or reject with the reason, and timestamps.
Audit answers
Prove this leaver lost access on their last day
The question every auditor asks, answered from the log. Evidence for ISO 27001 A.5.15, A.5.18, A.8.15 and A.8.16, Cyber Essentials, and PCI DSS Req 8 and 10.
- The account disabled in Entra ID, Okta or Google Workspace.
- The live session killed with RADIUS CoA.
- Every later attempt rejected, with the reason.
Control mapping
The control mapping, line by line
Hand this table to your auditor. Every row is answered from the same authentication log.
| Control | What the Purple log proves | Export |
|---|---|---|
| ISO 27001 A.5.15 Access control | What the Purple log provesWho joined which network and VLAN, by identity, and the rule that let them in | ExportMicrosoft Sentinel, Splunk, Elastic or Datadog, over webhook or syslog |
| ISO 27001 A.5.18 Access rights | What the Purple log provesAccess granted, changed and removed as directory groups change, including the leaver's last accept and first reject | ExportAs above |
| ISO 27001 A.8.15 Logging | What the Purple log provesEvery accept and reject, with time, site, network, identity and reason | ExportAs above |
| ISO 27001 A.8.16 Monitoring activities | What the Purple log provesRejects by site and by reason, streamed live to your SIEM | ExportAs above |
| Cyber Essentials, user access control | What the Purple log provesEvery account belongs to one person and is removed when they leave | ExportAs above |
| PCI DSS Req 8 | What the Purple log provesEach person and device authenticated individually, with no shared credentials | ExportAs above |
| PCI DSS Req 10 | What the Purple log provesEvery authentication event logged with its outcome, for review | ExportAs above |
Your tools
Into your SIEM, and answerable in plain English
Stream it to the SIEM you already run
Microsoft Sentinel, Splunk, Elastic or Datadog, over webhook or syslog.
Ask your WiFi data in plain English
For example: which department used the most bandwidth last week?
Network health and occupancy
From the estate down to one access point
Network health
Estate, location and hardware drill-down. Speed tests and authentication rates. Download and behavioural data to spot misuse.
Who used the network, and when
Logins, people connected and usage by day, hour and group.
Occupancy and footfall
By site, hour and day, from access point signals. No beacons, and MAC addresses anonymised. Shareable reports and dashboards.
Add-on: Purple Shield
Make this network safer and faster with Purple Shield
Purple Shield bolts onto Access or runs standalone. Set a different DNS policy per VLAN and by time of day, so staff, guests and residents each get the filtering that fits them, with dashboard analytics. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Common questions
Does this make us ISO 27001 or PCI DSS certified?
No tool does. It gives you the evidence: every accept and reject logged with its reason, mapped to ISO 27001 A.5.15, A.5.18, A.8.15 and A.8.16, Cyber Essentials, and PCI DSS Req 8 and 10.
Which SIEMs can we stream to?
Microsoft Sentinel, Splunk, Elastic and Datadog, over webhook or syslog.
Is occupancy reporting privacy-safe?
MAC addresses are anonymised and no beacons are used. Reporting is by site, hour and day.
Does it cover all three networks?
Yes. The authentication log, SIEM streaming, Ask AI and network health cover open, secure and xPSK, at every site, in one place.
Our auditors need evidence. What do we show them?
Every accept and reject, logged with its reason and streamed to your SIEM, mapped to ISO 27001 A.5.15, A.5.18, A.8.15 and A.8.16, Cyber Essentials, and PCI DSS Req 8 and 10. Show them the leaver who lost access on their last day. The full mapping is on the visibility page.
See your own authentication log, on your own estate
We walk you through the log, the control mapping and the SIEM stream, on your own setup. All in a 45-minute design session.
- Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
- Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
- Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.
Your design session
45 minutes. Your estate. A plan you keep.
Led by a Purple network engineer. No slides. You keep the plan.