Skip to content
Guest, staff and IoT WiFi for IT teams

Run every WiFi network you have on three SSIDs, and retire the shared password

Right now your WiFi carries guests, staff, tills, cameras and residents across a pile of SSIDs and passwords you cannot take back. Collapse it to three. Guests come in through a captive portal, everyone you trust connects on certificates, and everything else gets its own key. One price per access point, on the hardware you already run, on the largest cloud RADIUS in the world: 500 million logins a year.

Cloud RADIUS sends every device to the open, secure or xPSK network by identity, each on its own VLAN.

OpenVLAN 10SecureVLAN 20xPSKVLAN 40
  • 99.999% uptime
  • 99.9% RADIUS uptime SLA
  • 80,000+ venues in 90 countries
  • ISO 27001 and Cyber Essentials Plus

99.999% is the uptime the Purple platform runs at. 99.9% is the cloud RADIUS SLA in your contract: the floor we commit to in writing. Multi-region failover across the UK, EU and US sits behind both.

Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.

Every deviceYour access pointsCloud RADIUSRejected: account disabled
Open
  • Captive portal sign-in
  • Consent recorded
  • BYOD onboarding lane
Secure
  • EAP-TLS from your MDM
  • Identity decides the VLAN
  • Passpoint and OpenRoaming
xPSK
  • A key per device
  • Own VLAN and bandwidth limit
  • Revoke one key alone
VLAN 10VLAN 20VLAN 40

IT teams running on Purple

  • JPMorgan
  • McDonald's
  • Whitbread
  • SoFi Stadium
  • Vancouver International Airport
  • University of New Brunswick
  • Newcastle City Council
  • Murray State University
  • Kinetic Melbourne Airport
  • Meydenbauer Center
Book my design session

SSID sprawl

You never designed seven networks. They just kept arriving.

Every new device type got its own SSID and its own shared password. Each one costs you airtime, risk and tickets today. Three questions show how much: where do your tills connect, who still knows the password, and what else is on that network?

Seven SSIDs on one channel, guest, guest 5G, staff, an old staff network, tills, CCTV and printers, collapse into three networks: open, secure and xPSK. 8 to 10 SSIDs use 15 to 25% of channel airtime on beacons; three SSIDs and a 12 Mbps basic rate win it back.

  1. Seven networks and counting

    Guest, guest-5G, staff, the old staff network nobody dares switch off, tills, CCTV and the office printers. Typical vendor guidance is three to five SSIDs. Count yours.

  2. Every SSID is burning airtime

    Each SSID beacons at the lowest basic rate, whether anyone uses it or not. 8 to 10 SSIDs use 15 to 25% of channel airtime before a single guest loads a page.

  3. Your shared password is an audit finding

    It is on a sticky note, a whiteboard or a laminated sign by the till, and the tills share the guest network. PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves. With a shared key, that means every leaver, every site, every time.

  4. And the risk is real

    The UK Cyber Security Breaches Survey 2025 found 43% of businesses breached or attacked, rising to 67% of medium and 74% of large businesses. A flat network on shared keys gives an intruder the run of the place.

Plan yours

Count your SSIDs in the planner

Tick what connects to your network today and see where each group lands. Nothing you tick leaves this page.

How many SSIDs do you broadcast today?
What connects to your network?

Your plan: 3 SSIDs.

Network 1Open
  • Guests and visitorsCaptive portal, consent recorded
Network 2Secure
  • Staff on managed devicesEAP-TLS from your MDM
Network 3xPSK
  • Tills, screens, CCTV and sensorsA key per device

Book a design session with this planThe full planner, on purple.ai

The model

Three networks. One platform. Zero shared passwords.

People sign in as themselves. Every device gets a key of its own, and every tenant or resident gets a key that belongs to them alone, revoked without touching anyone else. Identity puts each one on the right VLAN through RADIUS attributes, whichever network it joined. The model flexes from two to four SSIDs to suit your policy: three is the design, skip per-device keys and it is two, and in education eduroam makes it four. The identity model never changes.

1. Open

Open: guests in, and BYOD on its way to a certificate

Guest WiFi through a captive portal, and the onboarding lane for BYOD and unmanaged devices before they get a certificate.

  • SSO, Google, Apple, Facebook and SMS sign-in
  • Hotel PMS room check
  • Visitors connected before they arrive
  • Consent recorded for GDPR and CCPA
Inside the open network

Guest WiFi that doubles as your onboarding lane

The captive portal signs guests in, records consent and hands BYOD and unmanaged devices a route to a certificate. Adding RADIUS and the splash URL to the controller you run today takes under 15 minutes.

  • Every sign-in method. SSO, Google, Apple, Facebook, SMS one-time passcode, custom fields and a hotel PMS room check.
  • Consent on record. Each sign-up records consent for GDPR and CCPA, so the evidence is there when someone asks.
  • Kept apart. Guests land on their own VLAN, away from tills, staff devices and center systems.
  • Visitors ready on arrival. A visitor gets a calendar invite, their device connects on its own the moment they walk in, and their host is told they have arrived. No form at reception, no manual approval.

2. Secure

Secure: one passwordless SSID for everyone you trust

One WPA-Enterprise SSID for every trusted user, passwordless and certificate-based. Staff on EAP-TLS with your MDM and a compliance-gated join, and secure guest access with Passpoint and free OpenRoaming.

  • EAP-TLS certificates delivered by your MDM
  • Conditional Access and device posture checked at every join
  • Entra ID, Okta and Google Workspace decide the VLAN
  • Passpoint profile installs once, connects every visit
Inside the secure network

One passwordless SSID for every person you trust

WPA-Enterprise on certificates. Your directory decides the VLAN. The moment you disable an account, that leaver is off the WiFi at every site.

  • Staff on EAP-TLS, from the MDM you already run. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver certificates over SCEP. Five to ten minutes, once, for the whole organization. Compliance state feeds Conditional Access, so a device that fails a rule is refused at authentication, and device posture and MDM enrollment state land in the log. Personal phones go through the Purple app on the same SSID, because nobody wants a two-SSID solution. No more staff on the guest WiFi, and no more hotspotting because the corporate network is too hard to join. McDonald's runs it with 80% fewer IT helpdesk requests. Staff WiFi
  • Your directory decides who gets on, and where they land. Entra ID, Okta and Google Workspace over SAML and SCIM. Group membership drives the VLAN. Disable an account and access ends at every site, with live sessions killed by RADIUS CoA. Identity-based networking
  • Secure guest access with no portal, ever again. The profile installs once, then connects securely at every visit, encrypted from association. Identity survives iOS 18 MAC rotation. OpenRoaming is free through the Connect license, Purple is a certified WBA identity broker, and OpenRoaming reaches 5 million+ hotspots worldwide. Newcastle runs the world's first city-wide OpenRoaming network on Purple. Passpoint and OpenRoaming
  • The largest cloud RADIUS in the world: 500 million logins a year, nothing to patch. A 99.9% RADIUS SLA on a platform with 99.999% uptime, and multi-region failover with regions in the UK, EU and US. It replaces Cisco ISE, Aruba ClearPass, Microsoft NPS and FreeRADIUS, usually in a weekend. Managed PKI issues and auto-renews every certificate. Cloud RADIUS

3. xPSK

xPSK, the Swiss Army knife

One SSID, a key per device, person or tenant. Each key gets its own VLAN, policy and bandwidth limit, and you revoke one without touching the rest. Works on Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK.

  • Things: tills, screens, CCTV, sensors
  • Communities: a private network per resident
  • Concessions: each mall or airport tenant on its own key
Inside the xPSK network

xPSK: a key per device, the Swiss Army knife network

Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK: one SSID, a unique key per device, person or tenant, on every one of them. Certificates are the default. xPSK is for everything that cannot hold one.

  • Things. Printers, screens and TVs, tills and EPOS, CCTV, sensors and door controllers. Tills, screens and cameras share the network, never the access. Each key gets its own VLAN, policy and bandwidth limit, and MAC binding stops a key becoming a second shared password.
  • Communities. MDU, student accommodation, elderly care and build to rent. Each resident gets a private area network that follows them across the building, with mDNS reflection so AirPlay and Chromecast stay in their own bubble. About 1 million students and residents live on Purple community networks, and the University of New Brunswick runs iPSK on Purple. Every resident gets a network that feels like home. Their own TV in their cast list, and nobody else's.
  • Concessions. Each concession or tenant in a mall, airport or venue gets its own key and VLAN, kept apart from shoppers and center systems. No extra SSID per tenant. Malls, Vancouver International Airport and Kinetic Melbourne Airport run their tenants this way. When the lease ends, revoke that tenant's key and nobody else notices.
  • Contractors. Time-limited keys with no MDM, issued from a branded self-service portal or the Purple API. When the job ends, so does the access.

Rollout

How your estate goes live, one site, then every site

Live on one site in days, not quarters. Your existing network stays up while the new ones run beside it, so nothing breaks while you prove it.

  • 01

    The design session

    A Purple network engineer who runs this every week maps your access points, SSIDs, directory and devices onto open, secure and xPSK. You leave with the plan and the pilot site.
  • 02

    One site live in days

    Setup on our side takes hours. On yours, it is one app registration in Entra ID, Google Workspace or Okta, plus RADIUS and the splash URL on the controller, which takes under 15 minutes. The old SSIDs keep running beside the new ones.
  • 03

    Judge it, then roll out in waves

    You judge the pilot on tickets and audit evidence. Then every remaining site follows the same design, on the same three SSIDs, in waves you set. Site 300 looks exactly like site one.
  • 04

    What your staff and tills see on cutover night

    Managed laptops and phones receive their certificate from your MDM and join on their own. Personal phones install a WiFi pass from the Purple app in two taps. Each till moves to its own key once, and never needs re-keying for a leaver again. The shared password goes when you switch the old SSID off, and not before.

Visibility and reporting

See every authentication on every network, then prove it

Every accept and reject, at every site, in one pane of glass. When the auditor asks, you answer from the log in minutes, not days of exports.

Illustration

What the authentication log answers

  • Authentication log

    Every accept and every reject, with the reason

    Identity and groups, device, MDM enrollment state and posture, method (EAP-TLS, PEAP or individual PSK), access point, SSID, site, VLAN and role returned, accept or reject with the reason, and timestamps. One estate-wide query across open, secure and xPSK, no per-building exports.

  • Audit answers

    Prove this leaver lost access on their last day

    Evidence for ISO 27001 A.5.15, A.5.18, A.8.15 and A.8.16, Cyber Essentials, and PCI DSS Req 8 and 10, from the same log.

  • SIEM

    Stream it to the SIEM you already run

    Microsoft Sentinel, Splunk, Elastic or Datadog, over webhook or syslog.

  • Ask AI

    Ask your WiFi data in plain English

    Which department used the most bandwidth last week? Ask the question, get the answer from your session data.

  • Network health

    From the whole estate to a single access point

    Estate, location and hardware drill-down, speed tests and authentication rates, and download and behavioral data to spot misuse.

  • Occupancy

    Occupancy and footfall, without a single beacon

    By site, hour and day, from access point signals, with MAC addresses anonymized. Share reports and dashboards with the people who need them.

Add-on: Purple Shield

Make all three networks safer and faster with Purple Shield

Purple Shield bolts onto any of the three networks or runs standalone, with a different policy per VLAN and by time of day: staff, guest, paid against free, or student safeguarding. Page loads up to 500% faster and 20 to 40% less web traffic, with dashboard analytics. Whitbread and AGS airports run it. Try it free for 30 days.

Explore Purple Shield

Proof

IT teams at 80,000+ venues in 90 countries already made the switch

JPMorgan put staff WiFi on Purple across 5,000 branches. McDonald's cut IT helpdesk requests by 80% and engineer visits by 90%. Whitbread runs segmented staff WiFi on Purple. SoFi Stadium, University of New Brunswick on iPSK, Meydenbauer Center, Vancouver International Airport and Kinetic Melbourne Airport run on Purple, and so do 130 airports, about 40 live cities, Miami Heat, Brooklyn Nets, NASCAR, cruises, ferries and trains. Newcastle City Council runs the world's first city-wide OpenRoaming network, city-wide WiFi at £0 cost to the council, used by 1,000 SMEs, with 2.3 million logins and an 88% authentication rate. Murray State University signed a five-year deal for Purple PSK WiFi, and about 1 million students and residents connect on Purple community networks.

80,000+
venues run on Purple, in 90 countries
500M
logins a year
~2M
people onboarded every day
99.999%
uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
  • JPMorganSecure5,000branches on Purple staff WiFiJPMorgan runs staff WiFi on Purple across 5,000 branches.
  • McDonald'sStaff WiFi80%fewer IT helpdesk requests
  • McDonald's BelgiumStaff WiFi90%fewer on-site IT engineer visits
  • Newcastle City CouncilOpenRoaming£0cost to the councilThe world's first city-wide OpenRoaming network, used by 1,000 SMEs.
  • Murray State UniversityxPSK5 yearsdeal for Purple PSK WiFi
  • Community networksxPSK~1Mstudents and residents on Purple community networks

Purple is a B Corp, profitable and cash-flow generative, founded 13 years ago, with zero data breaches since 2012.

On-site visits from IT engineers reduced by 90%.

Ségolène de ChestretDigital IT specialist, McDonald's Belgium

Prove it on one site first

Pick a site. We put open, secure and xPSK on the access points it already has, beside the network it runs today. You judge the result on tickets and audit evidence, then roll out.

Cloud RADIUS sends every device to the open, secure or xPSK network by identity, each on its own VLAN.

OpenVLAN 10SecureVLAN 20xPSKVLAN 40

Comparison

Seven SSIDs and a shared password, or three SSIDs on Purple

The same estate, run two ways. Read across and decide which one you want to defend in your next audit.

Shared passwords and seven SSIDs compared with three SSIDs on Purple Access
Three SSIDs on PurpleShared passwords, seven SSIDs
IsolationThree SSIDs on PurpleIdentity decides the VLAN. Each resident, tenant or device group sits in its own segment.Shared passwords, seven SSIDsEveryone on an SSID shares one segment, so one compromised device can see the rest.
RevokingThree SSIDs on PurpleDisable one account or one key. Nobody else notices.Shared passwords, seven SSIDsChange the password, then re-key every device that knew it.
LifecycleThree SSIDs on PurpleJoiners and leavers flow from Entra ID, Okta or Google Workspace. Certificates auto-renew.Shared passwords, seven SSIDsLeavers keep the password until someone remembers to rotate it.

Integrations

Works with the network and tools you already run

A cloud overlay on your access points, your directory, your MDM and your SIEM, with 1,000+ connectors. Nothing is replaced. Nothing is ripped out.

Access points

For the open and secure networks. Mixed estates are supported.

  • Cisco Meraki
  • HPE Aruba
  • Ruckus
  • Juniper Mist
  • Ubiquiti UniFi
  • Cambium
  • Extreme
  • Fortinet

Identity providers

Over SAML and SCIM. Group membership decides the VLAN.

  • Microsoft Entra ID
  • Okta
  • Google Workspace

Device management

EAP-TLS certificates delivered over SCEP, with a compliance-gated join through Conditional Access.

  • Microsoft Intune
  • Jamf Pro
  • JumpCloud
  • Kandji
  • Hexnode
  • Iru
  • Addigy

SIEM

The authentication log, over webhook or syslog.

  • Microsoft Sentinel
  • Splunk
  • Elastic
  • Datadog

Pricing

One price per access point per year. Guests, staff and devices included.

No per-device meter and no per-authentication meter, so growth never shows up on your bill. Start on the free Connect license for the guest portal and free OpenRoaming. Capture and the secure and xPSK networks are priced per access point.

Connect

Free

  • The guest portal
  • Free OpenRoaming

FAQ

Questions IT teams ask before they switch

We have more SSIDs and they work. Why change?

They work, and they are costing you. Every SSID beacons at the lowest basic rate, and 8 to 10 SSIDs spend 15 to 25% of airtime on overhead. Three SSIDs plus a 12 Mbps basic rate win it back.

Do we have to rip and replace our access points?

No. Purple Access is a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet, and mixed estates are supported. Keep the hardware. Lose the shared passwords.

What happens when someone leaves?

Disable the account in Entra ID, Okta or Google Workspace and access ends at every site, live sessions included. Nobody changes a password, and nobody re-keys a till.

Will per-device pricing bite as we grow?

Never. Purple Access is priced per access point per year, with no per-device or per-authentication meter.

Who runs Purple Access?

JPMorgan across 5,000 branches, Whitbread, SoFi Stadium, Murray State University, University of New Brunswick on iPSK, Meydenbauer Center, Vancouver International Airport and Kinetic Melbourne Airport. Newcastle runs the world's first city-wide OpenRoaming network on Purple, and McDonald's cut IT helpdesk requests by 80%. So do 130 airports, about 40 live cities, Miami Heat, Brooklyn Nets and NASCAR.

Get your three-SSID plan in 45 minutes

Bring your access point vendor, your directory and MDM, and the list of what is on your network today. A Purple network engineer maps every network you run onto open, secure and xPSK, on the access points you already own. You keep the plan. The next step is proving it on one site.

  1. Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
  2. Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
  3. Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.

Your design session

45 minutes. Your estate. A plan you keep.

Led by a Purple network engineer. No slides. You keep the plan.