Set policy once. It's on every device.

Define your routing policy in one admin dashboard and it applies automatically across the team — new members included. No per-device setup, no IT rollout, no kernel driver.

1
dashboard
5 min
policy sync
client polls and applies
0
IT tickets
0
kernel drivers
Central policy

One place to set the rules

Routing policy lives in your admin dashboard, not on each person's laptop. Set it once and every connected device picks it up.

Set routing rules once in the admin dashboard

Define your team's routing policy from a single web dashboard — no per-device configuration, no scripts to distribute, no config files to keep in sync.

Pushed to every connected device within minutes

The Reach client polls for policy roughly every 5 minutes and applies whatever is current. Change a rule in the dashboard and it reaches the whole team without anyone touching their own client.

Define which domains and apps route through Reach

Choose exactly which traffic goes through the gateway and which goes direct. Video calls, large syncs, and personal browsing can stay off the gateway while the traffic you care about is covered.

Per-group policies, group rules take precedence

Different groups can run different routing policies at the same time. Where a group rule and an individual member setting conflict, the group rule wins — unless you've explicitly allowed an override for that rule.

Zero-touch deployment

New members are covered automatically

There's no rollout project. A new hire installs the client, signs in, and is already on policy.

Install and sign in — that's the whole rollout

Members install Reach and sign in with their work identity. The moment they join the group, the current policy is pushed to their device automatically.

No IT helpdesk call, no kernel driver

There's nothing for IT to configure or push out ahead of time, and nothing at the kernel level for endpoint protection tools to flag or block.

Works on endpoint-protected laptops

The Windows installer uses NSIS and needs no admin rights, so it runs on managed machines where elevated installers are blocked. macOS and Linux need no elevated privileges either.

How it works

Three steps

Step-by-step setup is in the docs: Set it up →

1

Create a group and set the policy

Sign in, create a group, and define its routing policy from the dashboard — which domains or apps route through Reach and which go direct.

2

Members install and sign in

Each person installs the Reach client and signs in with their work identity. No IT ticket, no admin rights, no manual configuration.

3

The client keeps itself current

The client polls every few minutes and applies whatever policy is current in the dashboard — so changes you make later reach everyone without any action on their end.