Your team's home IPs keep changing. Your firewall shouldn't care.
TYO Reach gives everyone on your team one static exit IP to whitelist — in your cloud firewall, SaaS tools and consoles — so remote and offshore staff reach IP-restricted resources directly. MFA on every login, routing policy pushed from one dashboard, no rollout project, and it works on locked-down laptops.
Secure access without the enterprise rollout
Most zero-trust tools assume a dedicated IT team and a multi-week deployment. Reach is built for businesses that need the same control without the overhead.
One static egress IP to allowlist
Every team member's work traffic exits from the same trusted static gateway IP. Add it once to your AWS security groups, Salesforce trusted IPs, or any IP-based allowlist — it stays current as people join, leave, and move. Learn more →
MFA + SSO on every login
TOTP or push approval is required at sign-in, with no opt-out for group members. Members sign in with Google or Microsoft Azure. A compromised password alone never reaches your gateway. Learn more →
Central policy, pushed automatically
Set routing rules once in the admin dashboard. They push to every member's device within minutes. New members join the group and inherit the policy — no per-device setup. Learn more →
Per-app routing, not full tunnel
Only the traffic you specify goes through Reach. Video calls, large syncs, and personal browsing stay on the local connection. Predictable bandwidth, no VPN-wide slowdown.
Cloud firewall automation
Connect your GCP, AWS, Azure, or Cloudflare account and Reach keeps your firewall rules in sync with the gateway IP — no manual security-group edits when things change. Learn more →
Zero-touch deployment
Members install Reach and sign in with their work identity. Policy is pushed automatically — no IT helpdesk call, no kernel driver, and it works on endpoint-protected laptops. Learn more →
Reach a machine or a cloud server by identity — not by borrowed IP
Share this PC
Authorised teammates securely reach a machine on your network — an office PC, a server, an RDP box — from anywhere, with no firewall ports opened. A peer-to-peer fast path keeps it near-LAN speed when they're close by, and access is per-share: add or revoke specific people, validated against a real TYO ID.
Remote Targets — cloud servers by identity
Reach your Google Cloud, AWS, or Azure servers directly — no jump box, no CLI, no relay desktop in the middle. Sign in with the cloud you already use (Google Cloud IAP, AWS SSM/EC2 Instance Connect, or Azure Bastion) and RDP or SSH opens automatically. Read the case study →
Built for offshore and distributed staff
Choose which region your team's traffic exits from — Singapore, Hong Kong, Taiwan, Europe, or US-West — and connection modes that adapt to the network, including restrictive ones in mainland China. Read the case study →
Push-to-approve sign-in
Approve logins from your phone with number-matching — the code stays on the computer you're signing in on, and you confirm it on your phone. Closes the MFA-fatigue hole where someone approves a login they never actually meant to.
One device, one entry
See every device on your team's account from the dashboard. Devices are tracked per-machine, not per-login, so a person's laptop and phone show up as themselves — not a growing pile of duplicate entries.
Practice Protect secures the login. Reach secures the login and the connection.
Tools like Practice Protect lock down who can sign in. Reach adds the other half — where their traffic is allowed to come from, and what happens the moment someone leaves.
Conditional access policy
Restrict your gateway to the countries and IP ranges you expect, set office-hours windows, and require a trusted device — enforced at the network layer, not just at login. If a member belongs to more than one of your groups, the strictest policy that applies to them wins.
One-click offboarding
When someone leaves, revoke their access everywhere in a single action from the member list — their Reach key, devices, shared-PC access, and active sessions are all cut off at once, not chased down one system at a time.
The same zero-trust access, at an SMB price point
Duo targets enterprise and charges per user per month. Reach delivers the same trusted-access use case with simpler setup and SMB-friendly pricing.
| Feature | TYO Reach | Cisco Duo |
|---|---|---|
| Consumer + business in one product | ✓ Yes | ✗ No |
| Zero-touch deployment — no IT helpdesk | ✓ Yes | Partial |
| Static egress IP for SaaS allowlisting | ✓ Yes | ✗ No |
| Per-app routing, not full tunnel | ✓ Yes | N/A |
| Per-seat price for SMBs | Lower | Enterprise |
| TOTP / MFA on every login | ✓ Yes | ✓ Yes |
Three steps to a shared gateway
Create a group and invite your team
Sign in, create a business group, and invite members by email. Each person signs in with their work identity (Google, Azure, or TYO ID). MFA is required from the first session.
Set your routing policy once
Choose your gateway region and define which domains or apps route through Reach. The policy pushes to every connected device and to anyone who joins later.
Allowlist one IP in your SaaS tools
Copy the gateway IP from your dashboard and add it to your cloud firewall or SaaS allowlists. New members are covered automatically — you never update the allowlist again.
Free for three months, no data cap
Team plans have no data metering and no per-device config. Start your team free for three months — no card to begin — and we'll agree the plan that fits before you pay anything.