Skip to content
Protective DNS

Protective DNS that keeps harmful content and threats off every WiFi network you run

Every phone on your guest WiFi can reach whatever it asks for, and you answer for what it finds. Shield does three jobs in one layer: family-safe content filtering, threat defence behind your firewall, and ad blocking that makes pages load up to 500% faster.

No hardware, no agents, no card. Live in minutes, or piloted on one SSID with our engineers.

Point the network's DNS at Shield and adult content stays off the family table, infected devices stop calling home, and every network runs its own rules, stricter after dark. Run it standalone on any WiFi network or bolt it straight onto Purple Access. No hardware, no agents, nothing installed on a single device.

  • Up to 500% faster pages, ads stripped
  • 241k threats blocked a week at St George's
  • Threats flagged up to 10 days earlier
  • 30-day free trial
  • Filtering to the Internet Watch Foundation bar
  • No hardware, no agents on devices

In the same category as DNSFilter and Cisco Umbrella, built for the guest and public WiFi they were never designed around. Live in minutes, free for 30 days.

Live lookupsAll venues · All SSIDsLive
  • news.exampleOpenAllowed
  • casino-bonus.exampleOpenBlocked · Gambling
  • ads.tracker.exampleOpenStripped · Ads
  • c2-callback.exampleSecureBlocked · Command and control
  • bookings.exampleSecureAllowed
  • phish-login.examplexPSKBlocked · Phishing
  • video.examplexPSKAllowed
  • malware-cdn.exampleOpenBlocked · Malware
241k
threats blocked a week at St George's
10 days
earlier warning than standard blocklists
500%
faster page loads with ads stripped
Command-and-control callback blocked

Shield runs at

  • Whitbread
  • AGS Airports
  • St George's Healthcare NHS Trust
Protect a network free for 30 days

The gap

Your WiFi lets people in. What they reach is still your problem.

Shared networks carry devices you do not manage and people you have a duty of care to. When something goes wrong on them, nobody asks the device owner. They ask you. Can you prove nothing harmful got through? Ask yourself three questions, one for each gap that stays open until something checks every lookup.

One infected device puts everyone at risk

A phone that arrived already infected joins your network and starts calling home to its command-and-control server. Every other user on that network now shares it with an active threat. Shield blocks the callback at the lookup, before the connection starts.

Your firewall is older than you think, and it never sees the guest phones

Firewall hardware and firmware age, and a gap opens long before the next refresh. Shield adds a layer behind the firewall you already run, and covers the guest and BYOD devices a firewall agent never touches.

Harmful content reached on your WiFi is reached in your venue

Public, guest and student WiFi carries a duty of care. Harmful content has to stay off the network for every device, including the ones you will never see, with nothing to install on any of them.

What Shield does

Three jobs, one layer, every device covered

Every app and browser makes a DNS lookup before it connects. Shield answers it. So one layer filters content, stops threats and strips ads on every device on the network, phones you will never manage included.

Family-safe content, on every device

Block adult, gambling and other categories in a click. Safe Search is enforced on Google, Bing and YouTube, every venue keeps its own allow and block lists, and anyone who hits a blocked site sees your branded block page, not the site. Filtering meets the bar set by the Internet Watch Foundation and the Friendly WiFi standard.

  • Category filtering for every device: iOS, Android and Windows, with no app to install
  • Safe Search enforced on Google, Bing and YouTube
  • Allow and block lists per venue
  • A branded block page in place of the blocked site

Bolts onto Purple Access

A different policy for every network you run

Strict where families are, threat-first for staff, safeguarding for students and residents, separate rules for paid WiFi, and stricter after dark. Picture it set once and left to run: it runs every night without you. Shield applies after the connection, so every network and every VLAN carries its own policy.

Open: strict for guests and family areas

Guest WiFi through the Access captive portal gets the strictest policy: family-safe categories, Safe Search and ad blocking. Every guest gets a clean, fast network, and every parent gets one less thing to worry about.

Secure: different rules for staff

Staff on EAP-TLS with MDM, and devices on Passpoint and OpenRoaming, get a policy built around threat defence, with their own allow and block lists.

xPSK: safeguarding for students and residents

PPSK, iPSK and EasyPSK networks carry IoT, communities and concessions. Student accommodation, MDU and elderly care groups each get the safeguarding policy that fits.

Paid and free WiFi kept apart

A paid tier carries its own rules, separate from the free network, and streaming can be limited at busy times to protect bandwidth.

Policies that change by the hour

Every policy changes by time of day and day of week, per venue. Stricter in the evening, different at the weekend, set once and left to run.

See and control

One dashboard to prove it is working, at every venue, on every network

Monday morning, one screen: what was blocked, which threats were stopped and how the network was used, at every venue and on every SSID. When the ops director, a governor or a parent asks whether the WiFi is safe, you prove it.

See everything Shield stops

Need logs in your SIEM, or Shield behind an existing firewall and NAC? Talk it through with a Shield expert.

  • Blocked URLsSee what was blocked, on which network and at which venue.
  • Threat analysisTrack the threats Shield stopped, including devices calling home.
  • UsageRead network usage alongside the policy that shaped it.
  • Policy per SSID and venueChange a policy, a list or a schedule from the same screen.

Proof

Proven at St George's, Whitbread and AGS Airports: around 241,000 threats blocked a week

Whitbread protects its hotel guest WiFi with it. AGS Airports protects passengers at Aberdeen, Glasgow and Southampton with it. St George's Healthcare NHS Trust blocks around 241,000 threats a week with it. And it runs on the Purple platform behind 80,000+ venues in 90 countries, for customers including McDonald's, Harrods and Premier Inn.

Threats means malware, phishing and command-and-control lookups stopped by Shield.

  • St George's Healthcare NHS TrustThreat defence241kthreats blocked a week on its guest WiFi
  • WhitbreadHospitalityProtects its hotel guest WiFi with Shield.
  • AGS AirportsTransportProtects passengers at Aberdeen, Glasgow and Southampton.
10 days
earlier warning of new threats than standard blocklists
500%
faster page loads with ads stripped
80,000+
venues on the Purple platform

Certified, and aligned to recognised security and child-safety standards

  • ISO 27001
  • GDPR
  • CCPA
  • Cyber Essentials
  • Friendly WiFi
  • Internet Watch Foundation

Filtering meets the Friendly WiFi and Internet Watch Foundation standards.

Compare

DNSFilter and Umbrella protect the laptops you own. Shield protects the phones you never will.

All of them filter. Shield is the one built for guest and public WiFi: ad blocking included, a policy per network, nothing to install, new threats flagged up to 10 days before standard blocklists, and the WiFi platform that already runs sign-in and analytics for your venues behind it.

Purple Shield compared with DNSFilter, Cisco Umbrella and a legacy filtering appliance
Compared withWhere Shield winsWhat it is built for
DNSFilterWhere Shield winsBuilt for guest and public WiFi, with ad blocking included, a policy per SSID and VLAN and nothing to installWhat it is built forPure-play protective DNS for managed and roaming endpoints
Cisco UmbrellaWhere Shield winsPurpose-built for WiFi filtering, live in minutes across a multi-site venue estateWhat it is built forA broad secure-access suite, from DNS security to SWG and ZTNA, for large enterprises on quote-based pricing
Legacy filtering applianceWhere Shield winsNo hardware, no firewall change, and it fails closed across multiple data centresWhat it is built forA box at every site that inspects traffic at the network edge

Give every Access network its own policy, live in minutes

Point a network's DNS at Shield and filtering is live. No hardware, no agents on devices, nothing to roll out. On a change-controlled estate, we plan it with your team.

Pricing

Prove it on one network before you pay a penny

Run Shield on its own on any WiFi network, or bolt it onto Purple Access on its open, secure and xPSK networks. Every plan starts with a 30-day free trial.

  • Run Shield free for 30 days

    Point one network's DNS at Shield and see what it blocks for 30 days. No hardware to buy and no firewall change to pay for.

  • Standalone or with Access

    Buy Shield on its own for any WiFi network, or add it to Purple Access. Tell us your venues and networks, and we send a tailored quote.

FAQ

The questions IT teams ask before they switch on Shield

We already have a firewall. Why add Shield?

Because your firewall cannot see the guest phones on your WiFi. Shield is an extra layer behind your firewall, not a replacement for it. It blocks the DNS lookup before a connection starts, stops command-and-control callbacks from infected devices, covers guest and BYOD devices a firewall agent never touches, and flags new threats up to 10 days before standard blocklists.

Can guests get round it with a VPN or encrypted DNS?

Shield answers every DNS lookup on the network it protects, on every device, with nothing on the device to switch off. A Shield expert shows you exactly how your network handles VPNs and encrypted DNS before you trial.

Will Shield slow the network down?

No. It speeds it up. Stripping ads and trackers at the DNS layer makes pages load up to 500% faster, cuts web traffic by 20 to 40%, uses up to 44% less data and makes up to 62% fewer DNS queries.

How is Shield different from DNSFilter or Cisco Umbrella?

All three are protective DNS. Shield is built for guest and public WiFi rather than corporate endpoints, includes ad blocking as a first-class feature, sets a policy per SSID, VLAN, venue and time of day, and comes from the WiFi platform that already runs sign-in and analytics for the same venues. One resolver change, not a suite to roll out.

Do I need Purple Access to run Shield?

No. Shield runs standalone on any WiFi network: point its DNS at Shield and filtering is live. On Purple Access it bolts onto every open, secure and xPSK network. Either way, you start with 30 days free.

What happens to my guest WiFi if Shield has a problem?

Protection does not lapse. Shield fails closed, so an outage never leaves a network unfiltered, and it runs across multiple data centres, so a fault in one does not take your service down and users stay protected wherever they are. You never trade safety for uptime. Shield runs on the Purple platform, which carries 500 million logins a year at a 99.999% uptime SLA.

Can different venues and networks have different rules?

Yes. Policies are set per SSID, VLAN and venue, can change by time of day and day of week, and each venue keeps its own allow and block lists.

Do I need hardware or software on devices?

No. Shield works at the DNS layer, so there is no appliance to rack, no firewall change and nothing to install on iOS, Android, Windows or guest devices.

Can I prove it is working?

Yes. One dashboard shows blocked URLs, threat analysis and usage, by network and venue.

Decide what your WiFi reaches, free for 30 days

Tell us which networks you run and who is on them. We map a policy to each one: guests, staff, students, residents and paid tiers. Then point one network at Shield and see what it stops for 30 days, before you pay anything. Running change control? We plan a pilot on one SSID with your team instead. No hardware, no agents on devices.

  1. We map your networksA Purple expert maps your networks, your venues and the people on each, and answers your questions on bypass, outages, data handling and integrations.
  2. You get a policy for each oneGuests, staff, students, residents and paid tiers, each with the policy it needs.
  3. You prove it, then get your tailored quote30 days free on one network, or a pilot on one SSID planned with your team, then Shield priced standalone or as an add-on to your Access plan.

Your policy map

Tell us your networks. We map a policy to each one.

A Purple expert comes back with a policy for every SSID you run, from the team that has run content filtering on WiFi since 2012 and runs WiFi for 80,000+ venues in 90 countries.