Skip to main content

Trusted by global enterprise IT teams

Every system you run has proper identity. Except one.

Your team spent years putting identity on everything: email, finance, remote access. Then there's the WiFi. One password, known by every contractor and every leaver since the day it was set.

Where does your staff WiFi sit?
SystemOwn loginMFARemoved when someone leavesSign-in history
Microsoft 365YesYesYesYes
Finance systemYesYesYesYes
Remote accessYesYesYesYes
Staff WiFi passwordNoNoNoNo

Why nobody has fixed it

Because changing it breaks everything. Every laptop, phone, till, printer and camera has to be re-keyed, at every site. So the key never changes, and every leaver walks out with it. A shared key can't be taken back from one person. So stop sharing it.

Already running 802.1X? Here's where it still leaks.

802.1X puts you ahead of most. It rarely covers everything.

  1. Leavers

    Does a certificate end when the account is disabled in your identity provider, or only when it expires?

  2. Devices

    What do the tills, printers and cameras that can't do 802.1X connect to?

  3. Contractors

    Which network are they on, and who removes them when the contract ends?

  4. Guests

    Who runs guest WiFi, and is it kept apart from everything else?

Purple closes every one of those gaps, on the hardware you already run.

Your auditors already expect this

Individual access that ends when someone leaves isn't a nice-to-have. It's written into the standards you're assessed against.

PCI DSS v4.0.1

Requirement 2.3.2: wireless keys must change whenever anyone who knows them leaves. With a shared password, that's every leaver, every site, every time. With Purple there's no shared key to change, and card machines sit on their own keyed network.

Cyber Essentials

Cyber Essentials expects every account to belong to one person and to be removed when they leave. A shared WiFi password fails both, and your assessor knows it.

UK Cyber Security Breaches Survey 2025

43% of UK businesses were breached or attacked in the last year. For medium businesses it's 67%. For large, 74%. Don't leave the WiFi as the door nobody locks.

Read the government survey

The fix isn't a better password. It's no shared password.

  1. 01

    Everyone joins as themselves

    Staff sign in with the account they already use for everything else, through Microsoft Entra ID, Google Workspace or Okta.

  2. 02

    Every device gets its own key

    Tills, card machines, cameras and printers each get an individual key, so one leaked key opens one thing.

  3. 03

    Leave the company, leave the network

    Disable someone in your directory and they're off the WiFi at every site, live sessions included. No re-keying. No site visits.

One password out. Three networks in.

Every business has the same three groups on its WiFi. Purple gives each one a network built for the job.

Today

One network, one password

Staff, contractors, tills, cameras, printers and the phones of people who left, all behind the same key.

With Purple

Guest

Who
Visitors, customers, residents and students
How they join
A branded portal on their own SSID and VLAN, fully isolated. Nothing internal is reachable.
Replaces
The password on a card at reception
With Purple

Staff

Who
Everyone who works for you, with contractors in their own group on narrower access
How they join
802.1X against Entra ID, Google Workspace or Okta, through Purple cloud RADIUS. Leave the directory, leave the network.
Replaces
The shared staff password, and re-keying every time it leaks
With Purple

Devices

Who
Tills, card machines, CCTV, printers, smart TVs and IoT
How they join
Each device gets its own pre-shared key (per-device PSK). Revoke one without touching the rest.
Replaces
The networks nobody can explain

Contractors are people, not devices, so they never share a network with the tills. And three is where the picture starts, not a limit: per-device keys can give other groups, such as residents or students, private access of their own.

Won't more SSIDs slow things down? No.

The full design is three networks: guests, staff and devices. Skip per-device keys and it's two. In education, add eduroam. Three SSIDs is well within what any enterprise access point handles, and most estates end up broadcasting fewer networks than they do today.

You broadcast todayWhat changes
One or two networksThe full design is three, or two without per-device keys. Three is well within what access points handle comfortably.
Three networksSame count, different jobs. The shared-password network is replaced, not added to.
Four or moreMost businesses can switch some off.

Our engineer maps your current SSIDs and airtime in the design session, so you switch over with a plan, not a guess.

How it works on your network

Purple runs the authentication in the cloud. Your access points, switching and directory stay exactly as they are.

Cloud RADIUS, no server to run

Purple operates the RADIUS service, replacing on-premises FreeRADIUS or NPS and the single point of failure that comes with it. Access point refreshes need no user reconfiguration.

Policy follows identity

Dynamic VLANs, ACLs and bandwidth limits are returned as RADIUS attributes based on directory group: role, department or location. Staff land on the right VLAN by who they are, not which network they picked.

Leavers cut off at every site

The moment your directory tells Purple someone has gone, their access ends and live sessions are killed with RADIUS Change of Authorization. Every site, at once.

No app on company devices

Your IT team pushes the WiFi certificate to managed devices through your MDM, such as Jamf Pro, so they connect with no app. Personal phones use the Purple app, and both appear in one report.

Per-device keys for headless kit

Devices that can't do 802.1X get their own pre-shared key instead of a shared one. One compromised camera exposes one key, and you revoke it on its own.

A record of who connected

Every connection is logged against a named user or device, so the question of who was on the network that afternoon has an answer. Ready for your auditors, your insurer and your SIEM.

Hardware-agnostic

Runs on the access points you already own

Purple is a cloud overlay over standard RADIUS. Nothing to rip out, nothing to buy, and your existing network stays up while the new ones go live beside it.

  • Cisco Meraki
  • HPE Aruba
  • Ruckus
  • Juniper Mist
  • Ubiquiti UniFi
  • Cambium
  • Extreme
  • Fortinet

Mixed estates are no problem: Cisco in the office and Ruckus in the venues still gives staff one login that works everywhere.

Prove it on one site

No big bang. Put Purple on one site, see who and what is really on your network, then roll it out everywhere.

  1. A 45-minute design session

    Our engineer and whoever owns your network go through your access points, SSIDs, identity provider and devices.

  2. One site live

    Setup on our side takes hours. On yours, it's one app registration in Entra ID, Google Workspace or Okta, and you're live.

  3. Roll it out everywhere

    You've seen exactly who and what is on your network. Now switch every site over and retire the shared password for good.

What you're not risking

  • Nothing to rip out: it runs on the access points you already own
  • Your existing network stays on while the new ones run alongside
  • No app on company devices, which get their certificate through MDM
  • One site first, so nothing changes everywhere at once

One price per access point per year covers guests, staff and devices.

Frequently asked

Why three SSIDs rather than one?

Because every business has three groups on its WiFi, and one shared password can't serve any of them properly. Guests join through a branded portal on their own SSID and VLAN, fully isolated from everything internal. Staff join as themselves over 802.1X, authenticated against Microsoft Entra ID, Google Workspace or Okta through Purple cloud RADIUS. Tills, card machines, cameras and printers each get their own key. Nobody shares anything, and nobody keeps access after they leave.

Will more SSIDs slow the network down?

No. The full design is three networks: guests, staff, and devices on their own keys. Skip per-device keys and it is two; in education, eduroam makes it four. Three SSIDs is well within what any enterprise access point handles, and most estates end up broadcasting fewer networks than they do today. Our engineer maps your airtime and SSID layout in the design session.

We already run 802.1X. What does Purple add?

Everything 802.1X usually leaves behind. Certificates that outlive the person because they only die at expiry. Tills, printers and cameras that cannot do 802.1X and end up on a shared key. Contractors on the wrong network. Guest WiFi run by someone else entirely. Purple ties every connection to your directory, gives headless kit its own keys, isolates guests, and runs the whole lot as a cloud service on the access points you already own.

Do staff need to install an app?

Not on company devices. Your IT team pushes the WiFi certificate through your MDM, such as Jamf Pro, and they connect with no app at all. Personal phones use the Purple app, and both show up in one report.

Does it work with our existing access points?

Yes. Purple is a hardware-agnostic cloud overlay over standard RADIUS. It runs on Cisco Meraki, Cisco Catalyst, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are no problem, so staff get one login that works at every site. Nothing to rip out, nothing to buy.

How does this help with PCI DSS?

PCI DSS v4.0.1 requirement 2.3.2 says wireless keys must change whenever anyone who knows them leaves. With a shared password that means re-keying every site, every time someone goes. With Purple there is no shared key to change: staff access ends with their directory account, and card machines sit on their own keyed network. Purple never touches payment card data.

How is it priced?

Per access point per year, and one price covers guests, staff and devices. Start with one site, see exactly who and what is on your network, then roll it out everywhere.