Reach beyond what blocks your team
TYO Reach gives your whole team one trusted Australian exit IP, MFA and SSO on every login, and routing policy you set once and push to every device — the zero-trust access story of Cisco Duo, at an SMB price and without the rollout project.
Secure access without the enterprise rollout
Most zero-trust tools assume a dedicated IT team and a multi-week deployment. Reach is built for businesses that need the same control without the overhead.
One static egress IP to allowlist
Every team member's work traffic exits from the same trusted Australian gateway IP. Add it once to your AWS security groups, Salesforce trusted IPs, or any IP-based allowlist — it stays current as people join, leave, and move. Learn more →
MFA + SSO on every login
TOTP or push approval is required at sign-in, with no opt-out for group members. Members sign in with Google or Microsoft Azure. A compromised password alone never reaches your gateway. Learn more →
Central policy, pushed automatically
Set routing rules once in the admin dashboard. They push to every member's device within minutes. New members join the group and inherit the policy — no per-device setup. Learn more →
Per-app routing, not full tunnel
Only the traffic you specify goes through Reach. Video calls, large syncs, and personal browsing stay on the local connection. Predictable bandwidth, no VPN-wide slowdown.
Cloud firewall automation
Connect your GCP, AWS, Azure, or Cloudflare account and Reach keeps your firewall rules in sync with the gateway IP — no manual security-group edits when things change. Learn more →
Zero-touch deployment
Members install Reach and sign in with their work identity. Policy is pushed automatically — no IT helpdesk call, no kernel driver, and it works on endpoint-protected laptops. Learn more →
The same zero-trust access, at an SMB price point
Duo targets enterprise and charges per user per month. Reach delivers the same trusted-access use case with simpler setup and SMB-friendly pricing.
| Feature | TYO Reach | Cisco Duo |
|---|---|---|
| Consumer + business in one product | ✓ Yes | ✗ No |
| Zero-touch deployment — no IT helpdesk | ✓ Yes | Partial |
| Static egress IP for SaaS allowlisting | ✓ Yes | ✗ No |
| Per-app routing, not full tunnel | ✓ Yes | N/A |
| Per-seat price for SMBs | Lower | Enterprise |
| TOTP / MFA on every login | ✓ Yes | ✓ Yes |
Three steps to a shared gateway
Create a group and invite your team
Sign in, create a business group, and invite members by email. Each person signs in with their work identity (Google, Azure, or TYO ID). MFA is required from the first session.
Set your routing policy once
Choose your gateway region and define which domains or apps route through Reach. The policy pushes to every connected device and to anyone who joins later.
Allowlist one IP in your SaaS tools
Copy the gateway IP from your dashboard and add it to your cloud firewall or SaaS allowlists. New members are covered automatically — you never update the allowlist again.
Per seat, no bandwidth cap
Business plans are billed per seat per month with unlimited bandwidth — no metering, no per-device config. Start with your first few seats free and add more as your team grows.