Secure staff WiFi and guest WiFi from one platform
SecureW2 delivers certificate-based authentication and cloud RADIUS for IT and security teams. Purple delivers the same passwordless WPA2/3-Enterprise and RADIUS-as-a-Service, with no PKI to run, and adds guest WiFi, captive portal and venue analytics on the access points you already own. One platform gives IT secure staff access and the venue its guest WiFi.
- RADIUS-as-a-Service with passwordless WPA2/3-Enterprise (EAP-TLS)
- Entra ID, Okta and Google Workspace sync, no PKI to operate
- Runs on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist and Ubiquiti UniFi
- ISO 27001, GDPR, CCPA and Cyber Essentials certified
See Purple on your network
Book a 30-minute demo and we will show RADIUS-as-a-Service and guest WiFi running on your stack.
Join 80,000+ venues. We’ll never share your details.
Why teams move from SecureW2 to Purple
SecureW2 focuses on certificate-based authentication and managed PKI.
Purple delivers passwordless WPA2/3-Enterprise and RADIUS-as-a-Service with managed certificates, so there is no PKI for your team to run.
SecureW2 gives IT an onboarding portal for device enrolment.
Purple adds a branded guest WiFi captive portal alongside staff access, so one platform covers visitors and employees.
SecureW2 reports on authentication and access telemetry.
Purple adds footfall, dwell and repeat-visit analytics on top of access logs, so the venue sees behaviour as well as auth.
SecureW2 is a specialist identity and PKI product.
Purple is a full WiFi platform, running guest, staff and multi-tenant networks with EAP-TLS security built in.
SecureW2 integrates with Entra ID, Okta and Google Workspace.
Purple syncs with the same identity providers and runs on the access points you already own across Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist and Ubiquiti UniFi.
Built for IT, security and the whole venue
Purple gives IT and security teams secure staff WiFi and gives the venue guest WiFi, analytics and marketing, all on one platform and on the access points you already own.
IT & network teams
RADIUS-as-a-Service and passwordless WPA2/3-Enterprise on the hardware you already run - Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist and Ubiquiti UniFi - with no PKI to operate.
Security & compliance
EAP-TLS certificate-based authentication, identity sync with Entra ID, Okta and Google Workspace, and ISO 27001, GDPR, CCPA and Cyber Essentials certification.
Guest experience & marketing
A branded captive portal, first-party data capture and footfall and dwell analytics in the same platform as staff WiFi.
Multi-site or campus
Every building and site in one dashboard, from a single campus to a national airport group, with 99.999% uptime.
Trusted at enterprise scale
See what secure staff and guest WiFi looks like on your network.
Feature-by-feature comparison
| Feature | Purple | SecureW2 |
|---|---|---|
| RADIUS-as-a-Service | ✓Native, multi-region, full EAP method support | ✓Core product under the CloudRADIUS brand |
| Passwordless WPA2/3-Enterprise (EAP-TLS) | ✓Certificate-based staff access, managed certificates included | ✓Core strength - EAP-TLS with managed PKI |
| Managed PKI / certificate lifecycle | ✓Managed certificate issuance and auto-renewal tied to RADIUS | ✓Flagship capability, official Intune CA partner |
| Identity provider sync (Entra ID, Okta, Google Workspace) | ✓Entra ID, Okta, Google Workspace, JumpCloud, SAML, LDAP | ✓Entra ID, Okta, Google Workspace, on-prem AD |
| Guest WiFi + branded captive portal | ✓Full brandable portal builder, multi-language, data capture | –JoinNow onboarding portal only, not a guest experience |
| Footfall & dwell analytics | ✓Location analytics across venues and multi-site estates | ✕Authentication logs and access telemetry only |
| WiFi marketing (email & SMS) | ✓Purple Engage: WiFi-triggered email and SMS, 70+ CRMs | ✕Not in product scope |
| Multi-tenant / iPSK WiFi | ✓Resident-isolated networks for BTR, student and coworking | ✕Moves customers off shared PSKs to certificates |
| Runs on your existing hardware | ✓Vendor-agnostic overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, UniFi | ✓Cloud RADIUS works with any 802.1X-capable access point |
See how the switch from SecureW2 works on your stack.
One platform for secure staff and guest WiFi
Purple runs cloud RADIUS and passwordless WPA2/3-Enterprise with EAP-TLS certificate-based authentication, synced to Entra ID, Okta or Google Workspace, with no PKI for your team to operate. On the same platform you get branded guest WiFi, captive portal and footfall analytics, all on the Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist or Ubiquiti UniFi hardware you already run, backed by ISO 27001, GDPR, CCPA and Cyber Essentials certification. Book a demo and we will show it on your network.
Frequently asked
Does Purple offer certificate-based authentication like SecureW2?
Yes. Purple runs passwordless WPA2/3-Enterprise with EAP-TLS and managed certificates tied to RADIUS-as-a-Service, so your team gets certificate-based authentication without operating its own PKI - alongside guest WiFi, captive portal and analytics on the same platform.
Can Purple replace SecureW2 for staff WiFi?
In most deployments, yes. WPA2/3-Enterprise with EAP-TLS against Entra ID, Okta or Google Workspace runs the same way on either platform. The migration is usually a weekend: stand Purple up alongside, add it as a secondary RADIUS, move SSIDs across, then decommission SecureW2.
What does Purple add beyond cloud RADIUS?
Branded guest WiFi and a captive portal, footfall and dwell analytics, WiFi marketing, and multi-tenant iPSK networks, all on the same platform as staff access. SecureW2 is a specialist identity and PKI product and does not carry these.
Does Purple run on our existing hardware?
Yes. Purple deploys as a cloud overlay and is hardware-agnostic across Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist and Ubiquiti UniFi, so there is no hardware swap to run secure staff WiFi and guest WiFi together.
Where Purple beats SecureW2
See the product hub and the industries where teams pick Purple over SecureW2.
See Purple Passwordless WiFi
Replace shared passwords with EAP-TLS, iPSK, Passpoint, or SAML/SSO. Identity-based credentials on your existing access points.