For remote teams

One gateway IP for your whole team

Your team works from home offices, co-working spaces, and different cities. Your AWS console, Salesforce, and Jira still need to know who's allowed in. TYO Reach gives every team member the same exit IP — your firewall trusts one address, not fifty.

1
IP to allowlist
covers your whole team
APAC
Gateway network
AU · HK · SG and more
0
Kernel drivers
no admin rights required
5
Free seats
to get your team started
The problem

Why IP allowlisting breaks with remote teams

You gave your team flexible working. Now your cloud tools are blocking them.

Home ISPs give everyone a different IP

AWS, Salesforce, Jira, and most cloud platforms let you restrict access to specific IP addresses. That worked when everyone sat in one office behind one router. With remote workers, every person has a different ISP IP — and it changes whenever they move house, visit a client, or work from a café.

VPNs solve the wrong problem

Traditional VPNs tunnel all traffic through a central server — every video call, every file download, every Google search. That means expensive bandwidth, extra latency on everything, and kernel-level drivers that break on endpoint-protected corporate laptops. Your team didn't sign up for that overhead.

Reach gives you that fixed IP back

Every team member's work apps exit through the Reach gateway. External services see one IP — yours. Add it to your cloud firewall once and never update it again, no matter how many people join, leave, or change postcodes.

Core features

What your team gets

Everything a remote team needs to operate with a consistent network identity — without the overhead of a corporate VPN.

Static egress IP for SaaS allowlisting

One stable Australian IP address covers your whole team. Add it to AWS security groups, Salesforce trusted IPs, Atlassian allowlists, or any other IP-based access control — once. It stays current as your team grows, moves, and works from wherever they are.

MFA on every session

TOTP authenticator codes or push approval are required at login with no exceptions. If a team member's password is ever compromised, the attacker still cannot access your gateway. MFA is bundled into every Reach account — it is not an add-on you configure separately.

Central routing policy — pushed automatically

Set routing rules in your admin dashboard once. They push to every team member's device immediately. Define which domains or apps route through Reach and which go direct. New team members join your group and receive the policy automatically — no per-device setup, no IT tickets.

Per-app routing — not full-tunnel

Only the traffic you specify routes through Reach. Video calls stay on each team member's local connection. Large file syncs go direct. Personal browsing never touches the gateway. Bandwidth stays predictable because you are not tunnelling everything indiscriminately.

Works on endpoint-protected laptops

The Windows installer uses NSIS at user level — no elevation prompt, no kernel driver, no IT ticket required. It installs and runs on managed machines where traditional VPN clients are blocked by corporate endpoint protection software. macOS and Linux require no elevated privileges either.

Multi-platform from day one

macOS, Windows, and Linux tray apps plus Android mobile. Your team installs once and the gateway is always available — sitting in the system tray, not a browser extension that gets removed when someone switches browser profiles.

Gateway network

Choose where your team exits

Pick one region for the whole team, or set different exit points per app or per group. New regions are added regularly.

AU — Sydney

Australian egress IP. The right choice for teams whose SaaS platforms, banking tools, and compliance requirements expect domestic Australian traffic. Government portals, financial institutions, and local SaaS tools see a trusted domestic address.

HK — Hong Kong

Low-latency exit for teams working with APAC partners. Useful for accessing region-specific research platforms, tools, or services that are restricted to traffic from outside Australia.

SG — Singapore

Southeast Asian exit point. Route specific apps through Singapore while keeping all other team traffic through Australia. Useful for teams with regional suppliers, platforms, or clients in the Southeast Asian market.

More regions

Additional exit nodes are straightforward to provision — the gateway network expands as demand grows. If your team needs a specific region not yet listed, contact us at [email protected] and we will prioritise it.

How it works

Three steps to a shared gateway

1

Create a team and invite members

Sign in to your Reach dashboard, create a group, and invite team members by email. Each person creates a TYO ID if they don't already have one. MFA is required from the very first session — there is no grace period or optional opt-in.

2

Define your routing policy

Pick your gateway region. Specify which domains, apps, or IP ranges route through Reach and which bypass it and go direct. The policy pushes to all connected team devices immediately. You can update it at any time from the dashboard.

3

Allowlist one IP in your SaaS tools

Copy the gateway IP from your dashboard and add it to your cloud firewall allowlist — AWS, Salesforce, Jira, or whichever tools you use for IP-based access control. New team members who join your group are automatically covered. You never need to update the allowlist again.

Security

Built for teams that handle sensitive data

Reach is a gateway, not a monitoring tool. Your team's traffic is proxied, not logged or inspected.

MFA protects every gateway session

Authentication is required before any traffic can route through the gateway. There is no way for a team member to use the gateway without MFA being active. Credentials alone are not enough — even if a password is stolen.

No traffic logging

Reach does not log the content of your team's requests. The gateway sees connection metadata (destination domains) for routing purposes, but browsing content is not stored or inspected. You are not trading privacy for convenience.

Group policy enforced server-side

Routing rules are enforced at the gateway — not just in the client app. A team member cannot bypass group policy by modifying their local Reach client. Policy compliance is structural, not trust-based.

Where teams use Reach

Common use cases

Cloud console access (AWS, GCP, Azure)

Lock your cloud console to a single trusted IP. No more per-engineer IP allowlisting or security group sprawl. Add the gateway IP once and every current and future team member is covered without any further changes.

CRM and sales tools (Salesforce, HubSpot)

Many CRM platforms support trusted IP ranges for access control. A single Reach gateway IP replaces a constantly-changing list of home ISP addresses that need to be updated every time someone moves or switches provider.

Development tools (Jira, GitHub, Bitbucket)

IP-restricted repositories and project management tools work reliably for every team member regardless of where they're working that day — home, café, co-working space, or a client's office.

Financial and accounting SaaS

Accounting platforms that restrict logins to known IPs work correctly for every team member, including those travelling interstate or working abroad temporarily.

Frequently asked questions

Team admin FAQ

What if a team member works from a different country?

Their work traffic still exits from the same gateway IP regardless of where they physically are. A team member working from Bali, London, or Singapore appears on the same Australian IP as their colleagues in Sydney. Country of residence has no effect on the egress address.

Does Reach slow down video calls or non-work traffic?

No — only traffic you have included in your routing policy routes through Reach. Video calls, personal browsing, and file sync go direct on each team member's local connection at full speed. Teams consistently report no noticeable impact on the traffic they have not routed.

Do team members need admin rights to install the Reach client?

No. The Windows installer runs at user level with no elevation prompt. macOS uses a standard app bundle. Linux uses a user-space tray binary. Reach is specifically designed to run on endpoint-protected managed devices without requiring IT involvement.

Can we set different policies for contractors versus full-time staff?

Yes — create separate groups with separate routing policies. Group rules take precedence over individual member settings. Contractors can be limited to specific domains while full-time staff have access to the full routing policy. You control which rules members can or cannot override.

What happens if the gateway is unreachable?

Reach fails open — if the gateway cannot be reached, traffic goes direct rather than blocking the user entirely. Your team can keep working; the routing policy simply does not apply until the gateway connection is restored.

How is Reach different from a corporate VPN?

A traditional VPN tunnels all traffic through a central server and requires kernel-level drivers. Reach routes only the traffic you specify, runs entirely in user space, and is managed from a web dashboard rather than a server you maintain and patch. It is a smart routing gateway, not a network appliance.

Is Reach suitable for compliance-sensitive environments?

Reach provides a consistent egress IP and enforced MFA — two controls that help with many compliance frameworks. For detailed compliance requirements (SOC 2, ISO 27001, specific industry standards), contact us to discuss whether Reach fits your use case.

Can we audit which team members are connecting through the gateway?

The dashboard shows active sessions and connected team members. Detailed per-request audit logging is on the roadmap for the corporate tier. If per-connection audit logs are a hard requirement for your organisation, contact us to discuss your timeline and needs.

Get started

One IP. Your whole team.

First 5 seats are free. No credit card, no IT setup required.