For freelancers & contractors

A stable Australian IP your clients allowlist once

Working for multiple clients means navigating multiple IP restrictions, geo-blocked tools, and untrusted café networks. TYO Reach gives you a consistent Australian exit IP that gets allowlisted once — and routes only the traffic you choose, so everything else stays fast.

1
IP to share with clients
stable, never changes
AU
Exit location
Sydney, Australian IP
0
Kernel drivers
installs at user level
4
Platforms
Windows · macOS · Linux · Android
The problem

IP restrictions are a constant freelancing headache

Clients need to trust your connection. Café Wi-Fi is untrusted. Research tools are region-locked. Your home IP changes.

Every client has a different allowlist

Client A locks their AWS console to a known IP range. Client B's project management tool requires a specific network. Client C's staging environment has firewall rules. As a freelancer, you're expected to access all of these — from your home, from a co-working space, from a café, from wherever you happen to be working that day. Coordinating per-client IP allowlisting across a variable home IP is a recurring frustration that shouldn't require an IT ticket every month.

Your home IP isn't stable — or professional

Australian residential ISPs rotate IP addresses. Your home IP this month will likely differ from next month. Every time it changes, any client who has allowlisted it needs to update their firewall. Asking clients to do that repeatedly is awkward, error-prone, and creates friction in relationships you're trying to keep professional and smooth.

Café Wi-Fi puts your client work at risk

Public Wi-Fi is the default environment for a lot of freelance work — coffee shops, co-working lounges, airport departure halls. Your client's proprietary code, documents, and credentials all flow over networks you don't control and cannot vet. Routing sensitive traffic through an encrypted gateway reduces that exposure substantially.

What Reach does for you

A smarter way to manage your network identity

Consistent IP, selective routing, and lightweight enough that it doesn't get in the way of your actual work.

One IP address for all your clients

Your traffic exits from a stable Australian gateway IP that never changes. Share it with every client once during onboarding. They add it to their firewall allowlist and forget about it. If you pick up a new client next month, you give them the same IP address you've given everyone else. No spreadsheet of current home IPs to maintain, no reactive "please re-allowlist me" emails after a routine ISP reconnection.

Route client work through the gateway — keep everything else direct

Add your clients' domains and tools to the routing list. Reach sends those requests through the Australian gateway. Your personal browsing, Spotify, Slack, and everything else goes direct on your local connection at full speed. You're not paying for bandwidth you haven't used, and you're not adding latency to tools that don't need proxying.

Secure on café and co-working Wi-Fi

Traffic you route through Reach travels over an encrypted HTTPS tunnel to the gateway. Someone on the same café network cannot intercept your client's source code, credentials, or project files. You don't need to trust the network — only the traffic you've chosen to route is protected, but that's where your actual exposure is.

Access geo-blocked research and professional tools

Some professional research databases, data providers, and SaaS tools have geographic restrictions. An Australian gateway IP unlocks tools that restrict or limit access from certain countries — especially useful when you're working on research-intensive projects or using data sources that are only licensed for Australian access.

A consistent, professional network identity

A stable gateway IP means your client's access logs show the same address every session. It looks deliberate and professional — not like a home ISP address that shifts every few weeks and occasionally appears to come from a different suburb or city.

No kernel drivers — works on any machine

Reach installs at user level with no admin rights required. You can set it up on a client-issued laptop without IT involvement, on a co-working space machine, or on your own devices. The Windows installer uses NSIS specifically to avoid elevation prompts and kernel-level components that break on managed devices.

Getting set up

How to get your stable gateway IP

1

Create a Reach account and enable MFA

Sign up with your email or Google account. Enable MFA immediately — it protects your gateway session so a compromised password alone cannot expose your client work. Your first 500 MB is free with no card required.

2

Note your gateway IP address

Your dashboard shows the static Australian gateway IP assigned to your account. This is the address you share with clients for their firewall allowlists. It will not change as long as your account is active.

3

Add your clients' domains to the routing list

In the Reach app, add the domains for each client's tools — their cloud console, project management platform, staging environment, or whatever requires the IP check. Only those domains route through the gateway. Everything else goes direct at full speed.

4

Share the IP with each client once

Give each client your gateway IP for their allowlist. They add it once. You are now permanently on their approved list, regardless of which café or co-working space you're working from that day.

Use cases

Where freelancers and contractors use Reach

These are the most common scenarios — the routing list is whatever your client work requires.

Client cloud consoles (AWS, GCP, Azure)

Cloud console IP restrictions are the most common allowlist requirement for freelance developers, cloud engineers, and DevOps contractors. One stable IP covers every current and future client engagement. You never need to ask a client to update a security group again.

Project management and source control

Jira, Confluence, GitHub Enterprise, Bitbucket, Linear, and self-hosted project tools often carry IP restrictions at larger clients with security policies. Route those domains through Reach and the restrictions become irrelevant regardless of your physical location on any given day.

Research and data tools

Academic databases, industry data providers, financial data platforms, and market research tools vary by geographic access. An Australian gateway IP unlocks tools that restrict access based on country of origin and presents a consistent address for your research sessions across projects.

Working on client premises

Working from a client's office on their guest Wi-Fi? Their network team may route and log guest traffic through their own monitoring stack. Reach keeps your other client work — code, documents, credentials for a different client — routed through the encrypted gateway rather than visible on the network you're borrowing.

Plans that suit how freelancers actually work

Can I share my gateway IP with multiple clients at the same time?

Yes. Your gateway IP is stable and you can share it with as many clients as you work with simultaneously. They don't conflict with each other — each client independently allows that IP in their own firewall, and all your client traffic routes through the same gateway concurrently.

Will the gateway IP ever change?

The IP associated with your account is stable for as long as your account is active. It is not a residential IP that rotates. If an IP change were ever necessary, you would be notified in advance so you can update client allowlists with time to spare.

Does Reach work on a client-issued laptop with endpoint protection?

Yes. The Reach installer runs at user level with no kernel driver, no admin rights, and no elevation prompt. It is specifically designed to work on managed devices where IT has locked down system-level installs.

Can I use Reach while travelling for a client?

Yes — your gateway IP stays the same wherever you physically are. Working from a client office interstate, an airport lounge, or even overseas temporarily, your traffic still exits from the same Australian gateway. Client allowlists remain valid without any changes.

Does Reach protect against someone at the same café intercepting my traffic?

For traffic you route through Reach, yes — it travels over an encrypted HTTPS tunnel to the gateway before going to its destination. Traffic you haven't routed (personal browsing, etc.) goes direct over the café network. Reach isn't a full-tunnel anonymiser, but it covers the client work that actually matters.

What if a client asks me to use their VPN instead?

That's fine. You can run Reach alongside a client VPN. Reach routes specific domains and apps; a client VPN may route everything when active. In most configurations they coexist without conflict — the client VPN handles their internal network; Reach handles everything else you've defined.

Is Reach a legitimate business expense?

TYO Reach used as a professional internet gateway for client work is typically a legitimate business tool expense in Australia. Your accountant can confirm — but "internet security and access tool for client engagements" sits in a well-established expense category for contractors. This is not tax advice.

Can I update my routing list without any downtime or reconnection?

Yes — the routing list in the Reach app can be updated at any time. Add a new client's domain and it takes effect immediately. Remove a domain and traffic to that site reverts to going direct. No restart required, no gateway reconnection, no service interruption to your other routed traffic.

Get started

Give your next client a stable IP on day one

500 MB free, no card needed. Your gateway IP is available the moment you sign up.