Public WiFi that is safe for everyone who walks in
Libraries, council buildings, town centers and airports offer WiFi to anyone who walks in, and the duty of care comes with it. AGS Airports protects passengers at Aberdeen, Glasgow and Southampton with Shield. It keeps harmful content off the network to the bar set by the Internet Watch Foundation, stops threats at the lookup and gives every site and network its own policy.
Guest WiFi policy
- Adult contentBlocked
- GamblingBlocked
- Safe Search on Google, Bing and YouTubeEnforced
- Streaming at busy timesLimited
Allow list
bookings.examplemenu.exampleBlock list
rival-venue.exampleWhat is at stake
Open to the public means open to everyone
Anyone can join
Public WiFi carries a duty of care to every user, of every age.Threats on shared networks
Phishing and malware domains reach whoever is connected.Many sites, one standard
Every building needs the same protection without new hardware at each.
How Shield fits
One standard, applied site by site
- Public WiFiFamily-safe categories and Safe Search on Google, Bing and YouTube.
- Staff WiFiThreat defense first, with its own lists.
- Per siteAllow and block lists per venue, set centrally.
- ReportingBlocked URLs, threat analysis and usage in one dashboard.
See everything Shield stopsPublic sector WiFi on Purple Access
Proof
Standards you can point to
- AGS Airportsprotects passenger WiFi at Aberdeen, Glasgow and Southampton
- IWFfiltering meets the bar set by the Internet Watch Foundation
- Friendly WiFistandard met for family-safe filtering
- Cyber Essentialscertified, alongside ISO 27001
FAQ
Questions we hear from teams like yours
Can every site share one policy?
Yes, or each can have its own. Policies are set per SSID, VLAN and venue.
Is there hardware to install at each site?
No. Shield works at the DNS layer, with no appliance and no agents on devices.
What does Shield log about members of the public, and can our DPO sign it off?
Shield works at the DNS layer, so it sees the domains a device looks up, not the content of what it sends. Purple holds ISO 27001, GDPR, CCPA and Cyber Essentials certification, and we send the documentation your DPO and information governance board need before you start.
We cannot change DNS without change control. How do we trial it?
You do not need to. A Shield expert plans a pilot on one SSID with your team or your ICT provider, through your change process, and you see the results before anything wider changes.
Other industries
Offices
Protective DNS: a threat layer behind the office firewall
Threat defense behind the firewall, with staff and guest networks kept apart.Hospitality
Family-safe, faster guest WiFi with protective DNS for pubs, hotels and venues
Family-safe guest WiFi and faster pages for pubs, hotels and family venues.Education and student accommodation
Safeguarding on every student and resident network
Safeguarding per network and per VLAN for schools, campuses and student accommodation.
Decide what your WiFi reaches, free for 30 days
Tell us which networks you run and who is on them. We map a policy to each one: guests, staff, students, residents and paid tiers. Then point one network at Shield and see what it stops for 30 days, before you pay anything. Running change control? We plan a pilot on one SSID with your team instead. No hardware, no agents on devices.
- We map your networksA Purple expert maps your networks, your venues and the people on each, and answers your questions on bypass, outages, data handling and integrations.
- You get a policy for each oneGuests, staff, students, residents and paid tiers, each with the policy it needs.
- You prove it, then get your tailored quote30 days free on one network, or a pilot on one SSID planned with your team, then Shield priced standalone or as an add-on to your Access plan.
Your policy map
Tell us your networks. We map a policy to each one.
A Purple expert comes back with a policy for every SSID you run, from the team that has run content filtering on WiFi since 2012 and runs WiFi for 80,000+ venues in 90 countries.