Hotel WiFi for guests, staff and every room device
Guests sign in with a hotel PMS room check, staff run on segmented certificate-based WiFi, and room TVs and building systems each get their own key. Whitbread runs segmented staff WiFi on Purple.
- Whitbread runs staff WiFi on Purple
- PMS room check
- 99.9% RADIUS uptime SLA
Your three networks
Three SSIDs for hotels
Identity decides the VLAN inside each network, so one SSID carries many groups.
Network 1
Open
Guests sign in with their room number against the hotel PMS, or by SSO, social or SMS.Network 2
Secure
Staff on EAP-TLS, segmented by group, with Passpoint for returning guests.Network 3
xPSK
A key per room TV, screen, till and building system.
A key per room TV and building systemSegmented staff WiFi by directory group
Visibility and reporting
Every authentication, hotel by hotel, in one place
Accepts and rejects with the reason, by guest, member of staff and room device, across every property, streamed to your SIEM and ready for the auditor.
- One estate-wide query, no per-building exports.
- Microsoft Sentinel, Splunk, Elastic or Datadog over webhook or syslog.
- Occupancy and footfall by site, hour and day, with MAC addresses anonymized.
Proof
Whitbread runs segmented staff WiFi on Purple
Whitbread runs segmented staff WiFi on Purple, with Purple Shield on top of it.
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.999%
- uptime
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Common questions
Can guests sign in with their room number?
Yes. The captive portal checks the room number against the hotel property management system.
Do we need new access points in our hotels?
No. Purple Access is a cloud overlay on the access points your hotels already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet, and mixed estates are supported.
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each till and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
How are xPSK keys issued, rotated and revoked?
Every key is unique to one device, resident or tenant, bound to its own VLAN and policy, and MAC binding ties it to its device, so a key cannot become a second shared password. Issue keys from the console, a branded self-service portal or the Purple API. Rotate or revoke one key and every other device stays connected.
Take the tills and room devices off the guest network
Book a 45-minute design session and leave with the plan for your sites.
- Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
- Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
- Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.
Your design session
45 minutes. Your estate. A plan you keep.
Led by a Purple network engineer. No slides. You keep the plan.