Residential WiFi: a personal WiFi key per household, one SSID per building
Households sit on xPSK, one key each with its own VLAN. Prospects and visitors use the open network, and the on-site team signs in on EAP-TLS. One authentication log across every building, on the access points you already own.
- ~1 million residents on Purple
- 60% fewer helpdesk tickets at move-in
- 80,000+ venues in 90 countries
Residential
Residential: pick your estate
The resident lifecycle is the design problem: a key follows the household, the building's own devices stay up between lets, and one platform runs every building on whichever access point brand is on the ceiling.
Build to rent
Two key lifecycles on one SSID: the household's key follows the occupancy, and the keys for locks, thermostats and leak sensors follow the unit, so a move-out revokes one and never touches the other.Multifamily and apartments
Bulk internet delivered per unit across a mixed access point estate: the unit is a VLAN or role and not an SSID or a router, with one RADIUS and one dashboard across the portfolio, on any AP brand.Student accommodation
eduroam stays for 802.1X identity, the key follows the student and not the room, and a summer let is a time-boxed key instead of a second network.Co-living
Key lifetime equals the booking, from one week to a year, and shared printers and screens are reachable from members' VLANs by gateway policy while private devices never are.Military and service family housing
A posting is a lifecycle event at estate scale: households arrive and leave in batches, so each home is a VLAN and a key issued and revoked in bulk from the allocation list.
Use cases
The problems that thread these estates
Private networks for every resident
A household's own devices find each other and the neighbors' never appear, from one building network on your own access points.Move-in and move-out without password changes
One resident leaves, one key is revoked, and nobody else is disconnected.IoT and devices with no screen
A device with no screen or certificate still gets its own MAC-bound key and VLAN.Contractors and visitors
Access that ends on its date: a portal for visitors, a time-limited key for contractors.
FAQ
Questions IT leads ask
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
How does a move-out end access for one household only?
Each household's key is its own entry in RADIUS, bound to its devices by MAC address and placed on its own VLAN. Revoking it ends that household and nothing else, and the building's own locks, thermostats and sensors keep the keys that belong to the unit.
What does revoking one key do to everyone else?
Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.
Book a demo: we issue and revoke a key on a live network
Bring the list of what connects to your network. We issue a key, bind it to a device, place it on its VLAN and revoke it on a live network, on the access points you already own.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.