Three secure networks. One platform. No shared passwords.
Guests, staff and devices each get a network built for the job, on the access points you already own. Guests and residents connect through your branded portal. Staff sign in as themselves with Entra ID, Google Workspace or Okta. Every till, camera and printer gets its own key. And the shared staff password, the biggest shared account in your business, is gone for good.
Trusted by global enterprise IT teams















Every system you run has proper identity. Except one.
Your team spent years putting identity on everything: email, finance, remote access. Then there's the WiFi. One password, known by every contractor and every leaver since the day it was set.
| System | Own login | MFA | Removed when someone leaves | Sign-in history |
|---|---|---|---|---|
| Microsoft 365 | Yes | Yes | Yes | Yes |
| Finance system | Yes | Yes | Yes | Yes |
| Remote access | Yes | Yes | Yes | Yes |
| Staff WiFi password | No | No | No | No |
Why nobody has fixed it
Because changing it breaks everything. Every laptop, phone, till, printer and camera has to be re-keyed, at every site. So the key never changes, and every leaver walks out with it. A shared key can't be taken back from one person. So stop sharing it.
Already running 802.1X? Here's where it still leaks.
802.1X puts you ahead of most. It rarely covers everything.
Leavers
Does a certificate end when the account is disabled in your identity provider, or only when it expires?
Devices
What do the tills, printers and cameras that can't do 802.1X connect to?
Contractors
Which network are they on, and who removes them when the contract ends?
Guests
Who runs guest WiFi, and is it kept apart from everything else?
Purple closes every one of those gaps, on the hardware you already run.
Your auditors already expect this
Individual access that ends when someone leaves isn't a nice-to-have. It's written into the standards you're assessed against.
PCI DSS v4.0.1
Requirement 2.3.2: wireless keys must change whenever anyone who knows them leaves. With a shared password, that's every leaver, every site, every time. With Purple there's no shared key to change, and card machines sit on their own keyed network.
Cyber Essentials
Cyber Essentials expects every account to belong to one person and to be removed when they leave. A shared WiFi password fails both, and your assessor knows it.
UK Cyber Security Breaches Survey 2025
43% of UK businesses were breached or attacked in the last year. For medium businesses it's 67%. For large, 74%. Don't leave the WiFi as the door nobody locks.
Read the government surveyThe fix isn't a better password. It's no shared password.
- 01
Everyone joins as themselves
Staff sign in with the account they already use for everything else, through Microsoft Entra ID, Google Workspace or Okta.
- 02
Every device gets its own key
Tills, card machines, cameras and printers each get an individual key, so one leaked key opens one thing.
- 03
Leave the company, leave the network
Disable someone in your directory and they're off the WiFi at every site, live sessions included. No re-keying. No site visits.
One password out. Three networks in.
Every business has the same three groups on its WiFi. Purple gives each one a network built for the job.
One network, one password
Staff, contractors, tills, cameras, printers and the phones of people who left, all behind the same key.
Guest
- Who
- Visitors, customers, residents and students
- How they join
- A branded portal on their own SSID and VLAN, fully isolated. Nothing internal is reachable.
- Replaces
- The password on a card at reception
Staff
- Who
- Everyone who works for you, with contractors in their own group on narrower access
- How they join
- 802.1X against Entra ID, Google Workspace or Okta, through Purple cloud RADIUS. Leave the directory, leave the network.
- Replaces
- The shared staff password, and re-keying every time it leaks
Devices
- Who
- Tills, card machines, CCTV, printers, smart TVs and IoT
- How they join
- Each device gets its own pre-shared key (per-device PSK). Revoke one without touching the rest.
- Replaces
- The networks nobody can explain
Contractors are people, not devices, so they never share a network with the tills. And three is where the picture starts, not a limit: per-device keys can give other groups, such as residents or students, private access of their own.
Won't more SSIDs slow things down? No.
The full design is three networks: guests, staff and devices. Skip per-device keys and it's two. In education, add eduroam. Three SSIDs is well within what any enterprise access point handles, and most estates end up broadcasting fewer networks than they do today.
| You broadcast today | What changes |
|---|---|
| One or two networks | The full design is three, or two without per-device keys. Three is well within what access points handle comfortably. |
| Three networks | Same count, different jobs. The shared-password network is replaced, not added to. |
| Four or more | Most businesses can switch some off. |
Our engineer maps your current SSIDs and airtime in the design session, so you switch over with a plan, not a guess.
How it works on your network
Purple runs the authentication in the cloud. Your access points, switching and directory stay exactly as they are.
Cloud RADIUS, no server to run
Purple operates the RADIUS service, replacing on-premises FreeRADIUS or NPS and the single point of failure that comes with it. Access point refreshes need no user reconfiguration.
Policy follows identity
Dynamic VLANs, ACLs and bandwidth limits are returned as RADIUS attributes based on directory group: role, department or location. Staff land on the right VLAN by who they are, not which network they picked.
Leavers cut off at every site
The moment your directory tells Purple someone has gone, their access ends and live sessions are killed with RADIUS Change of Authorization. Every site, at once.
No app on company devices
Your IT team pushes the WiFi certificate to managed devices through your MDM, such as Jamf Pro, so they connect with no app. Personal phones use the Purple app, and both appear in one report.
Per-device keys for headless kit
Devices that can't do 802.1X get their own pre-shared key instead of a shared one. One compromised camera exposes one key, and you revoke it on its own.
A record of who connected
Every connection is logged against a named user or device, so the question of who was on the network that afternoon has an answer. Ready for your auditors, your insurer and your SIEM.
Runs on the access points you already own
Purple is a cloud overlay over standard RADIUS. Nothing to rip out, nothing to buy, and your existing network stays up while the new ones go live beside it.
- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Mixed estates are no problem: Cisco in the office and Ruckus in the venues still gives staff one login that works everywhere.





Prove it on one site
No big bang. Put Purple on one site, see who and what is really on your network, then roll it out everywhere.
A 45-minute design session
Our engineer and whoever owns your network go through your access points, SSIDs, identity provider and devices.
One site live
Setup on our side takes hours. On yours, it's one app registration in Entra ID, Google Workspace or Okta, and you're live.
Roll it out everywhere
You've seen exactly who and what is on your network. Now switch every site over and retire the shared password for good.
What you're not risking
- Nothing to rip out: it runs on the access points you already own
- Your existing network stays on while the new ones run alongside
- No app on company devices, which get their certificate through MDM
- One site first, so nothing changes everywhere at once
One price per access point per year covers guests, staff and devices.

We are continually looking for new ways to enhance the customer experience, and Purple has helped us do just that, with the added benefit of customer insight
90%
reduction in physical site IT visits
4m
WiFi logins a year
80%
fewer IT helpdesk requests
Frequently asked
Why three SSIDs rather than one?
Because every business has three groups on its WiFi, and one shared password can't serve any of them properly. Guests join through a branded portal on their own SSID and VLAN, fully isolated from everything internal. Staff join as themselves over 802.1X, authenticated against Microsoft Entra ID, Google Workspace or Okta through Purple cloud RADIUS. Tills, card machines, cameras and printers each get their own key. Nobody shares anything, and nobody keeps access after they leave.
Will more SSIDs slow the network down?
No. The full design is three networks: guests, staff, and devices on their own keys. Skip per-device keys and it is two; in education, eduroam makes it four. Three SSIDs is well within what any enterprise access point handles, and most estates end up broadcasting fewer networks than they do today. Our engineer maps your airtime and SSID layout in the design session.
We already run 802.1X. What does Purple add?
Everything 802.1X usually leaves behind. Certificates that outlive the person because they only die at expiry. Tills, printers and cameras that cannot do 802.1X and end up on a shared key. Contractors on the wrong network. Guest WiFi run by someone else entirely. Purple ties every connection to your directory, gives headless kit its own keys, isolates guests, and runs the whole lot as a cloud service on the access points you already own.
Do staff need to install an app?
Not on company devices. Your IT team pushes the WiFi certificate through your MDM, such as Jamf Pro, and they connect with no app at all. Personal phones use the Purple app, and both show up in one report.
Does it work with our existing access points?
Yes. Purple is a hardware-agnostic cloud overlay over standard RADIUS. It runs on Cisco Meraki, Cisco Catalyst, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are no problem, so staff get one login that works at every site. Nothing to rip out, nothing to buy.
How does this help with PCI DSS?
PCI DSS v4.0.1 requirement 2.3.2 says wireless keys must change whenever anyone who knows them leaves. With a shared password that means re-keying every site, every time someone goes. With Purple there is no shared key to change: staff access ends with their directory account, and card machines sit on their own keyed network. Purple never touches payment card data.
How is it priced?
Per access point per year, and one price covers guests, staff and devices. Start with one site, see exactly who and what is on your network, then roll it out everywhere.
Book your 45-minute design session
Bring whoever owns your network. In 45 minutes our engineer maps your access points, SSIDs, directory and devices, and shows you exactly how the three networks land on your estate.