How Reach differs from a VPN

Reach is built around a single idea: get you to the thing you're trying to reach, with the minimum machinery needed to do it. Whether that's a region-locked website or a server inside your office, Reach uses the lightest path that works — not a full VPN that reroutes your whole device.

For individual users — browser-scoped proxy

When you use TYO Reach as an individual, it routes one browser you choose through our gateway. Only that browser's traffic goes through Reach; everything else on your computer is completely untouched.

A traditional VPN tunnels all traffic from your device — every app, every background service, all the time. That's more than most people need, and it brings real costs: slower speeds system-wide, interference with local services, and a VPN client that's always running whether you need it or not.

Reach gives you the part of a VPN most people actually want — appearing somewhere else to open blocked content — without rerouting your whole machine.

For organisations — TCP tunnelling and agent mode

For teams and businesses, Reach goes significantly further than a browser proxy. The desktop agent can:

  • Forward any TCP port — RDP (3389), SSH (22), database ports, internal web apps — tunnelled from localhost on the user's machine through to any host the agent can reach, without any VPN client, kernel driver, or firewall change.
  • Act as a relay (agent mode) — a machine inside your office runs Reach in agent mode; all group members can then reach services inside that LAN from anywhere, because the agent makes the outbound connection and the traffic flows back through it.
  • Receive group policy — gateway selection, browser routing, and port forwards can be pushed centrally by the group owner without users reinstalling or reconfiguring.

This is comparable in capability to Zero Trust Network Access (ZTNA) tools like Cisco Duo or Zscaler Private Access — at a fraction of the per-seat cost and without the endpoint agent weight.

Side by side

TYO Reach (individual)TYO Reach (corporate)Full VPN
ScopeOne browser you chooseAny TCP port, any protocolEntire device
Other apps affectedNoNo (tunnels are opt-in)Yes
RDP / SSH tunnellingYesDepends on VPN
LAN relay (agent mode)YesRequires server + config
Remote-work office accessYesYes (with setup)
Running in backgroundOnly while switched onOnly while switched onUsually always on
Admin / kernel driverNoNoUsually yes
Central policy pushYesDepends on VPN
Best forBlocked content in a browserSecure team access to office systemsWhole-device encryption

Which should you use?

  • Individual — Use Reach when you want to open a website, streaming library, store or service that's blocked or region-locked, without disrupting the rest of your machine.
  • Organisation — Use Reach for RDP, SSH, database access, and LAN relay; it replaces a VPN for the access-to-internal-resources use case with no kernel driver, no always-on overhead, and central policy push.
  • Full VPN — Use a traditional VPN only when you specifically need every app on your device routed, or you need whole-system encryption for compliance reasons.

Next: see Getting started for individuals, or the Set up your team for team setup.