- Purple
- Enterprise WiFi security and authentication: a complete guide
- IronWiFi Alternatives for Enterprise Deployments
IronWiFi Alternatives for Enterprise Deployments
You will be able to shortlist an IronWiFi alternative on the jobs your network must do: authentication, identity, consent, hardware coverage and three-year cost. You will know when Purple, Cloud4Wi, Spotipo or Cloudi-Fi fits better, when IronWiFi still wins, and how to run a one-venue pilot that proves each vendor's claims.
Part of our core series: Enterprise WiFi Security Guide →
- Which IronWiFi alternative should you choose?
- Where do IronWiFi and its alternatives genuinely differ?
- Authentication architecture
- Identity and directory integration
- Visitor data and consent
- Hardware coverage
- Compliance and certification
- When is Purple the right IronWiFi replacement?
- You run many venues on mixed hardware
- You need guest, staff and resident access in one place
- You need scale and uptime evidence
- When do Cloud4Wi, Spotipo or Cloudi-Fi fit better?
- Cloud4Wi for engagement-led brands
- Spotipo for small, budget-led estates
- Cloudi-Fi for security-led guest access
- Where does IronWiFi still win?
- You only need cloud RADIUS for staff
- You want self-serve sign-up and published pricing
- Your team is comfortable owning the configuration
- What does each option cost to run?
- How the pricing models differ
- Worked scenario: a retail chain
- How do you decide for your estate?
- What to include in your pilot test script
- Decision matrix
- Worked scenario: a hotel group
- A note for public-sector buyers
- Frequently asked questions
- Who are the main IronWiFi competitors for enterprise deployments?
- Can Purple replace IronWiFi on my existing access points?
- How do IronWiFi and Purple pricing models differ?
- How much effort does migrating from IronWiFi take?
- Is Purple GDPR compliant for guest WiFi data?
- Does IronWiFi still make sense if I only need staff WiFi?
- Which IronWiFi alternative suits a single small venue?
To choose the right IronWiFi alternative, evaluate your network requirements. Purple supports multi-venue estates running on existing hardware, integrating with Microsoft Entra ID and utilizing the IEEE 802.1X standard. With over 80,000 venues globally, Purple offers a scalable platform for organizations needing guest, staff, and multi-tenant WiFi.
Which IronWiFi alternative should you choose?
IronWiFi is known for cloud RADIUS and a hosted captive portal. RADIUS (Remote Authentication Dial-In User Service) is the protocol that checks credentials before a device joins your network. A captive portal is the web page a visitor sees before they get online. Together they give IT teams authentication without running their own server.
The alternatives differ in what they add beyond authentication. Choose on the job your network has to do across the whole estate, not on the look of the login page.
- Purple fits estates with many venues that want guest, staff and resident access in one platform, on the access points already installed.
- Cloud4Wi fits retail and hospitality brands that care most about guest engagement and marketing integration.
- Spotipo fits smaller sites and managed service providers that want a low-cost hosted captive portal.
- Cloudi-Fi fits security teams that treat guest access as part of the corporate security stack.
- IronWiFi still fits teams that want self-serve cloud RADIUS with pricing published on its website.
These positions reflect each vendor's own published material at the time of writing. Product scope changes faster than comparison pages, so confirm every capability in a hands-on trial before you sign.
Where do IronWiFi and its alternatives genuinely differ?
The real differences sit in several places. These are who the platform is built for, how it licenses, how it handles identity, how it treats visitor data and which hardware it supports. The table maps each vendor against the axes that matter most at shortlist stage.
| Vendor | Where it fits best | Lead buyer | Pricing approach | What to prove in your trial |
|---|---|---|---|---|
| Purple | Multi-venue estates needing guest, staff and multi-tenant WiFi | IT and venue operations together | Plan-based (Connect, Capture, Engage), quoted for your estate | Guest, staff and resident access on your own access points |
| IronWiFi | IT teams wanting cloud RADIUS and a hosted captive portal | IT and network teams | Self-serve plans published on its website | Directory sync and 802.1X on your controller |
| Cloud4Wi | Retail and hospitality brands focused on guest engagement | Marketing and digital teams | Quote-based enterprise contracts | Marketing integrations and consent capture |
| Spotipo | Small sites and MSPs on a tight budget | Site owners and MSPs | Plans published on its website | Portal branding and compatibility with your controller |
| Cloudi-Fi | Security-led guest and visitor access | Security and compliance teams | Quote-based enterprise contracts | Integration with your existing security stack |
Authentication architecture
IronWiFi works as a cloud RADIUS service. You point your controller at it, and it answers authentication requests. That model is clean for IT teams who already know what they want from 802.1X. IEEE 802.1X is the standard for port-based network access control, which lets each person or device authenticate individually.
Purple works as a cloud overlay on top of the infrastructure you already run. It combines the captive portal, cloud RADIUS and Identity-Based Networks in one platform. Identity-Based Networks tie each connection to a known person or device rather than a shared password. Purple also supports iPSK (identity pre-shared key), which gives each device or person its own key on a single SSID.
Identity and directory integration
Staff WiFi lives or dies on your directory. Ask every vendor which identity providers it supports and how quickly access ends when someone leaves. Purple integrates with Microsoft Entra ID, Okta and Google Workspace. Joiners, movers and leavers (JML) flow from the directory, so Purple revokes access when HR removes the account.
IronWiFi also publishes directory integrations, which is part of why IT teams choose it. The test is not whether a connector exists. The test is how long a leaver keeps network access after you disable the account.
Visitor data and consent
If you capture guest data, the GDPR applies to every login. Consent must be demonstrable, and withdrawal must be as easy as giving consent. Purple uses conscious-choice opt-ins, so marketing consent is a separate, deliberate action rather than a pre-ticked box.
Purple then passes that first-party data into the CRM and marketing platforms you already use. Cloud4Wi also positions itself around marketing integration. IronWiFi and Spotipo focus more on access than on what happens to the data afterwards.
Hardware coverage
Purple is hardware-agnostic and runs on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. That matters when acquisitions or regional refresh cycles leave you with more than one vendor. Ask every alternative for its supported list and check it against each controller model in your estate.
Compliance and certification
Purple holds ISO 27001, Cyber Essentials and B Corp certification, and operates to GDPR and CCPA requirements. Ask every shortlisted vendor for current certificates, not a logo slide. Public-sector buyers also have duties under the Public Sector Bodies Accessibility Regulations. Purple publishes its own accessibility statement. It states that Purple Maps and Wayfinding are partially conformant with WCAG Level AA.
When is Purple the right IronWiFi replacement?
Purple is the right call when your network serves several audiences across many sites, and you want one console for all of them. Several situations come up most often in evaluations.
You run many venues on mixed hardware
Purple layers on top of your existing access points, so there is no rip and replace. A hotel group running HPE Aruba in older properties and Cisco Meraki in newer ones manages both from a single pane of glass. Purple runs at 80,000+ live venues globally.
You need guest, staff and resident access in one place
IronWiFi is strongest on authentication. Purple covers Guest WiFi, Staff WiFi and Multi-Tenant WiFi in one platform. For hotels, that means guests, back-of-house teams and long-stay residents each get the right access on the same infrastructure. Security add-ons extend this: SecurePass for secure passwordless access, Verify for identity checks and Shield for content protection.
You need scale and uptime evidence
Purple handled 440 million logins in 2024 and delivers 99.999% uptime (Purple data). Major brands and transit hubs run on Purple. For transport operators, Purple also runs onboard and station WiFi for major rail operators. See how that works for trains.
Purple also supports OpenRoaming, which lets visitors join participating networks automatically and securely after a one-time sign-up. OpenRoaming builds on Passpoint, the WiFi Alliance standard for automatic, encrypted network access. In healthcare, that removes repeat logins for patients and visitors returning to the same site.
When do Cloud4Wi, Spotipo or Cloudi-Fi fit better?
Purple is not the answer for every estate. Each of the other alternatives has a clear home, based on how the vendor positions itself.
Cloud4Wi for engagement-led brands
Cloud4Wi presents itself as a platform for retail and hospitality brands that want to turn WiFi logins into marketing engagement. If your project is owned by a marketing team, and staff authentication sits elsewhere, Cloud4Wi belongs on the shortlist. Test its consent flows against GDPR requirements and its integration with your CRM before you commit.
Spotipo for small, budget-led estates
Spotipo publishes its plans on its website and targets smaller venues and managed service providers. If you run a handful of sites on one hardware vendor and need a branded captive portal quickly, it is a reasonable option. Check controller compatibility and whether its feature set will cover you if the estate grows.
Cloudi-Fi for security-led guest access
Cloudi-Fi positions guest and visitor access as part of the enterprise security stack. That suits a corporate campus where the security team owns visitor connectivity, and the main goal is compliance rather than engagement. Ask for documented integrations with the security tools you already run, and for its certifications.
Where does IronWiFi still win?
A fair comparison names the places where IronWiFi is still the better fit. If any of these describes you, stay put or put IronWiFi on the shortlist.
You only need cloud RADIUS for staff
If the brief is 802.1X for employees, with no guest data and no multi-tenant requirement, IronWiFi does the job without extra features to pay for. A platform built for guest, staff and resident access will be more than you need.
You want self-serve sign-up and published pricing
IronWiFi publishes its plans online, so a network engineer can sign up and start testing without a sales call. For a small IT team with a fixed budget and a short deadline, that speed matters.
Your team is comfortable owning the configuration
IronWiFi suits teams who are happy to design their own policies and integrations. If you would rather hand that work to a vendor with managed onboarding, look at the alternatives.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.
What does each option cost to run?
Licence price is the line on the quote, but rarely the largest cost over the long term. Total cost of ownership comes from several areas. The table shows what drives each one and the question to put to every vendor.
| Cost line | What drives it | Question to ask every vendor |
|---|---|---|
| Subscription licence | Per access point, per venue, per site or per authenticated person | What happens to my bill if I add more access points? |
| Hardware | Whether the platform runs on your current access points | Which of my controller models are supported today? |
| Integration effort | Directory, CRM and property management system connectors | Which integrations are native, and which need custom work? |
| Migration | Reconfiguring controllers, captive portal and SSIDs at each site | Do you manage onboarding, or does my team do it? |
| Support | Hours, channels and escalation for a multi-site estate | What uptime do you commit to, and how is it measured? |
| Compliance evidence | Certificates, data processing terms and audit support | Can you provide current ISO 27001 and GDPR documentation? |
How the pricing models differ
IronWiFi and Spotipo publish plans on their websites, which makes early budgeting easy. Cloud4Wi and Cloudi-Fi quote enterprise contracts. Purple sells plan-based subscriptions, Connect, Capture and Engage, quoted for your estate. Connect covers access, Capture adds data capture and Engage adds marketing engagement.
The licensing unit matters more than the headline price. A per-access-point model grows every time you improve coverage. A per-venue model grows only when you open sites. Model both against your long-term plans, not today's estate.
Worked scenario: a retail chain
Situation. A fashion retailer runs multiple access points per store. A recent acquisition left the estate split between Cisco Meraki and HPE Aruba. The chain plans to add more access points to cover stockrooms and fitting rooms.
What was done. The IT team modelled licence exposure under two units: per access point and per venue. It also counted the consoles needed to run guest access across both hardware vendors.
Modelled outcome. Under per-access-point licensing, the licence count rises significantly, driven by coverage alone. Under per-venue licensing, the licence count remains flat. A hardware-agnostic overlay also cuts guest access management from multiple consoles to one. The team weighted those two results above headline price. Purple's approach for retail estates follows the same logic.
How do you decide for your estate?
Run the decision as a short, structured evaluation. Several steps keep it honest and comparable.
- Write down the jobs. List every audience: guests, staff, residents, contractors and IoT devices. A vendor strong on one audience may be weak on the rest.
- Inventory your hardware. Record every controller and access point model by site. Rule out any vendor that cannot support them all.
- Map identity. Note which identity provider holds staff accounts and how leavers are removed. Test revocation, not just sign-in.
- Set data and compliance rules. Decide what guest data you need, how consent is recorded and which certificates procurement requires.
- Pilot at one representative venue. Pick a site with typical hardware and footfall, then run the same test script with every vendor.
- Model long-term cost. Use your growth plan, not today's estate, and include migration and integration effort.
What to include in your pilot test script
Test captive portal redirection on modern devices. Most web pages use HTTPS, and a captive portal cannot redirect a secure page without the browser showing a certificate warning. Good platforms prompt the visitor to log in as soon as they connect. Purple's connection error article explains why this happens and the workaround.
Add further tests. Disable a test staff account and time how long network access lasts afterwards. Withdraw marketing consent and confirm it reaches your CRM. Finally, check each guest-facing page for keyboard navigation and screen reader support.
Decision matrix
| Your situation | Shortlist first | Why |
|---|---|---|
| Multiple venues, mixed hardware, guest and staff WiFi | Purple | Hardware-agnostic overlay with Identity-Based Networks |
| Multi-tenant BTR, student or MDU buildings | Purple | Multi-Tenant WiFi gives each resident a private network |
| Marketing-led retail or hospitality brand | Cloud4Wi or Purple | Both position around consented guest data and CRM integration |
| Small number of sites, one hardware vendor, tight budget | Spotipo or IronWiFi | Published plans and fast self-serve set-up |
| Corporate campus where security owns visitors | Cloudi-Fi or Purple | Security-led access with directory integration |
| Staff 802.1X only, no guest data | IronWiFi | Cloud RADIUS without features you will not use |
Worked scenario: a hotel group
Situation. A hotel group runs IronWiFi for the guest captive portal across its properties. Staff share one pre-shared key per hotel, and the group captures no consented marketing data. Every leaver means rotating a shared key at the affected property and briefing remaining staff.
What was done. The group piloted Purple at one hotel on its existing access points. Guest WiFi captured conscious-choice opt-ins. Staff WiFi authenticated against Microsoft Entra ID. Back-of-house devices such as handheld terminals moved to iPSK, so each device had its own key.
Measurable outcome. Shared staff keys were eliminated once rolled out to every property. A leaver now triggers one directory change instead of a key rotation and staff briefing. Consent records moved from none to a documented opt-in per guest, which supports the GDPR duty to show consent.
A note for public-sector buyers
Councils, NHS trusts and universities face extra tests: procurement frameworks, accessibility regulations and data protection impact assessments. Ask each vendor for its accessibility statement, its data processing terms and where guest data is hosted. Weight those criteria before price, because a failed compliance check ends the evaluation regardless of cost.
Frequently asked questions
Who are the main IronWiFi competitors for enterprise deployments?
The main IronWiFi competitors at enterprise tier are Purple, Cloud4Wi, Spotipo and Cloudi-Fi. Purple suits multi-venue estates needing guest, staff and multi-tenant WiFi on existing hardware. Cloud4Wi targets engagement-led retail and hospitality brands. Spotipo serves smaller, budget-led sites and managed service providers. Cloudi-Fi positions guest access as part of the security stack. Shortlist on the jobs your network must do, then prove each claim in a pilot.
Can Purple replace IronWiFi on my existing access points?
Yes, Purple runs as a cloud overlay on your existing access points, so you do not need new hardware. Purple supports Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Moving from IronWiFi means repointing your controller's captive portal and RADIUS settings to Purple, site by site. Start with one representative venue, confirm every flow works, then roll out across the estate.
How do IronWiFi and Purple pricing models differ?
IronWiFi publishes self-serve plans on its website, while Purple quotes plan-based subscriptions for your estate. Purple's plans are Connect, Capture and Engage, which add data capture and marketing engagement on top of access. Compare more than headline price. Check the licensing unit, because per-access-point pricing grows whenever you add coverage. Also include integration, migration and support effort in a long-term cost model.
How much effort does migrating from IronWiFi take?
Migrating from IronWiFi is a configuration project, not a hardware project. The work sits in several areas: repointing controllers to the new captive portal and RADIUS service, reconnecting your identity provider, and rebuilding portal branding and consent flows. Purple manages onboarding with your team. Run a pilot at one venue first, then migrate in waves grouped by hardware vendor to limit disruption to guests and staff.
Is Purple GDPR compliant for guest WiFi data?
Yes, Purple is GDPR compliant and also holds ISO 27001 and Cyber Essentials certification. Purple uses conscious-choice opt-ins, so marketing consent is a separate, deliberate action. That supports the GDPR requirement to demonstrate consent and to make withdrawal as easy as giving it. Purple also operates to CCPA requirements for visitors in California. Ask for data processing terms during procurement.
Does IronWiFi still make sense if I only need staff WiFi?
Yes, IronWiFi is a sensible choice if you only need cloud RADIUS for staff 802.1X authentication. Its published pricing and self-serve sign-up suit small IT teams with a fixed brief. The case changes once you add guest data capture, multi-tenant access or several hardware vendors. At that point, a platform covering guest, staff and resident access in one console usually reduces management effort across the estate.
Which IronWiFi alternative suits a single small venue?
Spotipo or IronWiFi usually suit a single small venue best, because both publish plans and offer self-serve set-up. A cafe or independent hotel with one hardware vendor rarely needs enterprise contracts or multi-site management. Choose Purple if you expect to grow into a group, or if you need consented guest data flowing into your CRM. Switching platforms later costs more than choosing for growth now.
Key Definitions
RADIUS
Remote Authentication Dial-In User Service, specified in IETF RFC 2865. A client-server protocol in which a network access server forwards credentials to a RADIUS server, which returns Access-Accept or Access-Reject plus authorisation attributes.
IronWiFi is built around cloud RADIUS, and Purple includes cloud RADIUS in its platform. Migrating means repointing each controller's RADIUS settings, site by site.
IEEE 802.1X
The IEEE standard for port-based network access control. It defines the supplicant, authenticator and authentication server roles and carries EAP over LAN (EAPOL), so each person or device authenticates individually, typically against a RADIUS server.
If your brief is staff 802.1X only, IronWiFi may be enough. In a trial, prove 802.1X and directory sync work on your own controller.
Captive portal
A web page a visitor must use before the network grants internet access. Because most pages use HTTPS, a portal cannot redirect a secure page without the browser showing a certificate warning, so platforms rely on operating system detection to prompt login on connection.
Test portal redirection on modern devices in every pilot. Purple's connection error article explains the certificate warning and the workaround.
iPSK (identity pre-shared key)
A WPA2 or WPA3 Personal deployment pattern in which each device or person receives a unique pre-shared key on a single SSID, with the key mapped to an identity, usually via RADIUS, rather than one shared password for everyone.
In the hotel group pilot, handheld terminals moved to iPSK, so each device had its own key and shared staff keys were eliminated.
Identity-Based Networks
Purple's approach of tying each connection to a known person or device rather than a shared password, combining captive portal, cloud RADIUS, 802.1X and iPSK in one platform.
This is the reason Purple appears first in the decision matrix for 20+ venues on mixed hardware running guest and staff WiFi.
Cloud overlay
A cloud-hosted service that layers authentication, portal and policy on top of existing access points and controllers, using their standard captive portal redirect and RADIUS integration rather than replacing hardware.
Purple runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet, so there is no rip and replace.
Joiners, movers and leavers (JML)
The identity lifecycle process in which account creation, role changes and removal flow from the directory, such as Microsoft Entra ID, Okta or Google Workspace, into downstream systems including network access.
Staff WiFi depends on it. The test is not whether a connector exists but how long a leaver keeps network access after the account is disabled.
GDPR Article 7
Article 7 of Regulation (EU) 2016/679 sets the conditions for consent: the controller must be able to demonstrate consent (7(1)), and withdrawal must be as easy as giving consent (7(3)).
It applies to every guest login where you capture data. Test each vendor's consent flow and withdrawal path against it before you commit.
Conscious-choice opt-ins
Purple's consent design in which marketing consent is a separate, deliberate action rather than a pre-ticked box, producing a documented opt-in record per guest to meet GDPR Article 7.
The hotel group moved from no consent records to a documented opt-in per guest after piloting Purple Guest WiFi.
Passpoint (Hotspot 2.0)
The WiFi Alliance certification programme, based on IEEE 802.11u, that lets devices discover and join networks automatically using credentials, with WPA2 or WPA3 Enterprise encryption.
Passpoint underpins OpenRoaming. It matters where visitors return often, because it removes repeat captive portal logins.
OpenRoaming
A Wireless Broadband Alliance federation built on Passpoint that lets visitors join participating networks automatically and securely after a one-time sign-up with an identity provider.
Purple supports OpenRoaming, which in healthcare removes repeat logins for patients and visitors returning to the same site.
WCAG 2.1 Level AA
The W3C Web Content Accessibility Guidelines 2.1 at conformance Level AA, the benchmark referenced by the UK Public Sector Bodies Accessibility Regulations 2018 for websites and apps.
Public-sector buyers should request each vendor's accessibility statement. Purple's states that Purple Maps and Wayfinding are partially conformant with WCAG 2.1 Level AA.
Worked Examples
A 150-store fashion retailer runs four access points per store, 600 in total, split between Cisco Meraki and HPE Aruba after an acquisition. It plans to add two access points per store for stockrooms and fitting rooms. How should it compare licensing?
The IT team modelled licence exposure under two units: per access point and per venue. It also counted the consoles needed to run guest access across both hardware vendors. Under per-access-point licensing, the licence count rises from 600 to 900, a 50% increase driven by coverage alone. Under per-venue licensing, it stays at 150. A hardware-agnostic overlay also cuts guest access management from two consoles to one. The team weighted those two results above headline price, because the licensing unit drives three-year cost more than the figure on the first quote.
A 12-hotel group with 200 rooms per property runs IronWiFi for its guest captive portal. Staff share one pre-shared key per hotel, and the group captures no consented marketing data. Every leaver means rotating a key and briefing remaining staff. What should it change?
The group piloted Purple at one 200-room hotel on its existing access points. Guest WiFi captured conscious-choice opt-ins. Staff WiFi authenticated against Microsoft Entra ID, and back-of-house handheld terminals moved to iPSK, so each device had its own key. Once rolled out to every property, shared staff keys fell from 12 to zero. A leaver now triggers one directory change instead of a key rotation and staff briefing. Consent records moved from none to a documented opt-in per guest, which supports the GDPR Article 7 duty to show consent.
An estate running IronWiFi across several hardware vendors wants to move to Purple without disrupting guests and staff. How should the migration run?
Treat it as a configuration project, not a hardware project, because Purple runs as a cloud overlay on existing access points. The work sits in three places: repointing controllers to the new captive portal and RADIUS service, reconnecting the identity provider, and rebuilding portal branding and consent flows. Start with one representative venue with typical hardware and footfall, and confirm every flow works, including leaver revocation and consent withdrawal. Then migrate in waves grouped by hardware vendor, so each controller configuration is proven once and repeated, limiting disruption. Purple manages onboarding with your team.
Frequently asked questions
Who are the main IronWiFi competitors for enterprise deployments?
The main IronWiFi competitors at enterprise tier are Purple, Cloud4Wi, Spotipo and Cloudi-Fi. Purple suits multi-venue estates needing guest, staff and multi-tenant WiFi on existing hardware. Cloud4Wi targets engagement-led retail and hospitality brands. Spotipo serves smaller, budget-led sites and managed service providers. Cloudi-Fi positions guest access as part of the security stack. Shortlist on the jobs your network must do, then prove each claim in a pilot.
Can Purple replace IronWiFi on my existing access points?
Yes, Purple runs as a cloud overlay on your existing access points, so you do not need new hardware. Purple supports Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Moving from IronWiFi means repointing your controller's captive portal and RADIUS settings to Purple, site by site. Start with one representative venue, confirm every flow works, then roll out across the estate.
How do IronWiFi and Purple pricing models differ?
IronWiFi publishes self-serve plans on its website, while Purple quotes plan-based subscriptions for your estate. Purple's plans are Connect, Capture and Engage, which add data capture and marketing engagement on top of access. Compare more than headline price. Check the licensing unit, because per-access-point pricing grows whenever you add coverage. Also include integration, migration and support effort in a three-year cost model.
How much effort does migrating from IronWiFi take?
Migrating from IronWiFi is a configuration project, not a hardware project. The work sits in three places: repointing controllers to the new captive portal and RADIUS service, reconnecting your identity provider, and rebuilding portal branding and consent flows. Purple manages onboarding with your team. Run a pilot at one venue first, then migrate in waves grouped by hardware vendor to limit disruption to guests and staff.
Is Purple GDPR compliant for guest WiFi data?
Yes, Purple is GDPR compliant and also holds ISO 27001 and Cyber Essentials certification. Purple uses conscious-choice opt-ins, so marketing consent is a separate, deliberate action. That supports the GDPR Article 7 requirement to demonstrate consent and to make withdrawal as easy as giving it. Purple also operates to CCPA requirements for visitors in California. Ask for data processing terms during procurement.
Does IronWiFi still make sense if I only need staff WiFi?
Yes, IronWiFi is a sensible choice if you only need cloud RADIUS for staff 802.1X authentication. Its published pricing and self-serve sign-up suit small IT teams with a fixed brief. The case changes once you add guest data capture, multi-tenant access or several hardware vendors. At that point, a platform covering guest, staff and resident access in one console usually reduces management effort across the estate.
Which IronWiFi alternative suits a single small venue?
Spotipo or IronWiFi usually suit a single small venue best, because both publish plans and offer self-serve set-up. A cafe or independent hotel with one hardware vendor rarely needs enterprise contracts or multi-site management. Choose Purple if you expect to grow into a group, or if you need consented guest data flowing into your CRM. Switching platforms later costs more than choosing for growth now.
Sources
- IETF RFC 2865: Remote Authentication Dial In User Service (RADIUS)
- IEEE 802.1X: Port-based network access control
- Regulation (EU) 2016/679 (GDPR), EUR-Lex
- WiFi Alliance: Passpoint
- Wireless Broadband Alliance: OpenRoaming
- W3C Web Content Accessibility Guidelines (WCAG) 2.1
- The Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018
- Purple accessibility statement
Continue reading in this series
Sophos Firewall and guest WiFi: captive portal setup with Purple
How Purple's cloud guest WiFi works with Sophos Firewall and its access points through a standard external captive portal and RADIUS, and where to check support and find the steps.
Aruba Central and Purple WiFi: Cloud-Managed Integration
A comprehensive technical reference guide for integrating Aruba Central with Purple's cloud-hosted guest WiFi intelligence platform. This guide covers architecture, step-by-step configuration of external captive portals and RADIUS, and multi-site rollout strategies for enterprise IT teams.
Microsoft Entra ID (Azure AD) WiFi authentication: Enterprise integration guide
This technical guide provides network engineers, IT architects, and systems administrators with an authoritative blueprint for integrating Microsoft Entra ID (formerly Azure AD) with enterprise 802.1X WiFi infrastructure. Learn how to eliminate on-premises RADIUS servers, deploy passwordless EAP-TLS certificates via Microsoft Intune SCEP and Cloud PKI, and automate dynamic VLAN assignment using Entra ID security groups.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.