Access that checks identity on every login

MFA on every session, plus Google or Microsoft SSO, backed by Australian-hosted TYO ID — the zero-trust access story of Cisco Duo, at an SMB price.

MFA
on every login
SSO
Google & Azure
AU
TYO ID identity
Australian-hosted
0
opt-out for members
Identity

Backed by TYO ID, not a platform you don't control

Every Reach account is authenticated through id.tyo.com.au — TYO's own identity service. There's no third-party identity platform in the loop, and no separately-priced tier to unlock MFA.

MFA on every session

TOTP or push approval is required at login. Group admins can require MFA for all members, and members can't opt out of a group-enforced MFA policy — a compromised password alone never reaches your gateway.

Google and Microsoft SSO

Members sign in with Google or Microsoft Azure. Sign-in uses short-lived session tokens, and long-lived credentials are never stored in the client app.

Australian-hosted identity

TYO ID runs on Google Cloud in Australia. Your account credentials never transit a US or EU identity platform.

One identity across every device

The same account and MFA policy cover Windows, macOS, Linux, and Android simultaneously — no per-device identity setup.

vs Cisco Duo

The same identity story, at an SMB price

Duo built its reputation on MFA and SSO for enterprise IT. Reach covers the same identity fundamentals, sized and priced for a team that doesn't have a dedicated security budget.

FeatureTYO ReachCisco Duo
MFA / TOTP on every login✓ Yes✓ Yes
Google & Microsoft sign-in✓ Yes✓ Yes
Consumer + business in one product✓ Yes✗ No
Static egress IP tied to access✓ Yes✗ No
Per-seat price for SMBsLowerEnterprise
How it works

Identity enforced from the first session

Step-by-step setup is in the docs: Set it up →

1

Create a group and invite members

Sign in, create a business group, and invite your team by email.

2

Members sign in with their work identity

Each person signs in with Google, Microsoft Azure, or TYO ID and completes MFA before their first session starts.

3

Access and policy apply automatically

Group access and routing policy take effect from that first session — no per-device setup, no waiting on IT.