Secure staff 802.1X WiFi and guest WiFi, zero PKI servers to manage
RUCKUS Cloudpath requires IT teams to configure, host, and operate complex certificate authority (PKI) infrastructure. Purple delivers passwordless WPA2/3-Enterprise on cloud RADIUS with managed certificates, while adding branded guest WiFi, captive portals, and venue analytics on your existing access points.
- Cloud RADIUS with EAP-TLS and 802.1X certificate-based security
- Zero PKI or certificate authority servers for your IT team to operate
- Hardware-agnostic: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, UniFi
- Unified staff security, guest captive portal, and venue analytics
Schedule a technical comparison
Book a 30-minute demo to see Purple cloud RADIUS and guest WiFi running on your network hardware.
Join 80,000+ venues. We’ll never share your details.
Why IT teams move from Cloudpath to Purple
Cloudpath requires IT teams to configure, maintain, and update internal certificate authority (PKI) servers.
Purple manages EAP-TLS certificate issuance within RADIUS-as-a-Service, eliminating PKI server maintenance.
Cloudpath focuses strictly on onboarding policy and client device certificate distribution.
Purple delivers cloud RADIUS and 802.1X security alongside branded guest WiFi, captive portals, and venue analytics.
Cloudpath is tightly aligned with RUCKUS hardware ecosystem configurations and licensing.
Purple operates as a vendor-neutral cloud overlay across Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, and UniFi.
Cloudpath offers no footfall tracking, dwell time insights, or guest marketing capabilities.
Purple provides real-time venue occupancy, footfall analytics, automated marketing, and CRM integrations.
Cloudpath lacks public documentation for platform security certifications.
Purple is ISO 27001, GDPR, CCPA, Cyber Essentials, and B Corp certified across the entire platform.
Built for IT, security, and venue operations
Purple gives network and security teams enterprise 802.1X security on cloud RADIUS, while giving venue teams guest captive portals, analytics, and marketing on a single dashboard.
IT & network teams
Deploy cloud RADIUS with EAP-TLS across Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, and UniFi with zero on-premises RADIUS or NPS servers to maintain.
Security & compliance officers
Passwordless 802.1X certificate authentication with automated lifecycle management, backed by ISO 27001, GDPR, CCPA, and Cyber Essentials certification.
Higher education & campus IT
Unified staff 802.1X security, student BYOD onboarding, private PSK (iPSK) networks, and open guest WiFi across multiple campus buildings.
Guest experience & venue teams
Custom-branded captive portals, guest demographic capture, footfall analytics, and automated WiFi marketing campaigns that dedicated PKI utilities lack.
Why 80,000 venues choose Purple
See what secure staff 802.1X and guest WiFi look like on your network hardware.
Feature-by-feature comparison
| Feature | Purple | Cloudpath |
|---|---|---|
| Cloud RADIUS (RADIUS-as-a-Service) | ✓Fully managed cloud RADIUS replacing on-premises RADIUS, NPS, and ISE | ✓Built-in RADIUS server tied to Cloudpath policy engine |
| Passwordless WPA2/3-Enterprise (802.1X / EAP-TLS) | ✓Certificate-based EAP-TLS authentication and dynamic per-user iPSK | ✓Core feature: unique per-device certificate onboarding |
| Zero PKI server management | ✓Certificates issued and managed in cloud RADIUS without running a CA | ✕Requires setting up and managing a certificate authority and revocation lists |
| Identity provider synchronization (Entra ID, Okta, Google) | ✓Direct cloud sync with Microsoft Entra ID, Okta, Google Workspace, and SAML/LDAP | ✓SAML/SSO integration with Entra ID, Okta, and Google |
| Multi-tenant & private PSK (iPSK) | ✓Dynamic per-user iPSK networks for student housing, MDU, and IoT devices | –Supports DPSK, primarily optimized for RUCKUS wireless hardware |
| Hardware-agnostic cloud overlay | ✓Seamless overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, UniFi | –Supports multi-vendor 802.1X, but deeply integrated with RUCKUS hardware |
| Branded guest WiFi & captive portal | ✓Custom captive portal, Passpoint / OpenRoaming, and guest data capture | –Basic guest onboarding web pages, no marketing or engagement tools |
| Footfall & venue analytics | ✓Real-time footfall, dwell time, repeat visitor metrics, and venue heatmaps | ✕No footfall analytics, venue intelligence, or visitor engagement reports |
| Enterprise compliance & security | ✓ISO 27001, GDPR, CCPA, Cyber Essentials, and B Corp certified | –No product-specific security or compliance certifications published |
Book a 30-minute demo to map the migration from Cloudpath to Purple.
One unified platform for staff 802.1X security and guest WiFi
Purple delivers cloud RADIUS and passwordless WPA2/3-Enterprise with EAP-TLS certificate-based authentication, synced directly to Microsoft Entra ID, Okta, or Google Workspace with zero PKI server overhead. On the same platform, you get branded guest WiFi, captive portals, and footfall analytics on your existing Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, or Ubiquiti UniFi access points, backed by ISO 27001, GDPR, CCPA, and Cyber Essentials certification. Book a demo to see it on your network.
Frequently asked
Does Purple offer certificate-based 802.1X authentication like Cloudpath?
Yes. Purple delivers passwordless WPA2/3-Enterprise with EAP-TLS certificate-based authentication managed inside RADIUS-as-a-Service. Your IT team gets enterprise 802.1X security without maintaining complex PKI servers, alongside guest WiFi, captive portals, and analytics on the same platform.
Can Purple replace Cloudpath for campus and enterprise staff WiFi?
Yes. Purple replaces Cloudpath for staff 802.1X authentication and student BYOD onboarding against Entra ID, Okta, Google Workspace, or Active Directory. Migration is seamless: configure Purple alongside as a secondary RADIUS server, transition your SSIDs, and decommission Cloudpath with zero network downtime.
How does Purple handle non-802.1X devices and IoT on campus networks?
Purple provides dynamic per-user iPSK (Private PSK), giving each user or device a unique pre-shared key tied to their identity. This allows gaming consoles, IoT devices, and smart TVs to connect securely on multi-tenant or campus networks without complex 802.1X supplicant software.
Does Purple require RUCKUS hardware or can we run multi-vendor access points?
Purple operates as a vendor-agnostic cloud overlay on your existing access points across Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, and Ubiquiti UniFi, allowing you to deploy secure staff WiFi and guest WiFi without hardware replacement.
What capabilities does Purple add beyond Cloudpath onboarding?
Purple adds custom-branded captive portals, guest demographic capture, footfall and dwell analytics, automated WiFi marketing, and CRM integrations on top of enterprise 802.1X security. Cloudpath is an identity onboarding tool and does not include guest experience or venue analytics.
Where Purple beats Cloudpath
See the product hub and the industries where teams pick Purple over Cloudpath.