A smart internet gateway for your team

One shared exit IP your firewall trusts, MFA on every login, and routing rules that follow every seat automatically. No VPN client to manage. No data cap. Hosted in Australia.

Australian-hosted identityWorks on managed machinesGateway network across APAC — AU · HK · SG and moreNo data cap — per seatNo kernel driver required
What you get

Everything a team needs to stay secure

The features your IT team or security buyer will ask for — built into one lightweight client.

🏛

Static egress IP

Your whole team exits from a single IP address. Add it once to your cloud firewall, AWS security group, or SaaS allow-list — and every team member is automatically covered, no matter where they're working from.

🔐

MFA on every login

TOTP and Verified Push on every sign-in. No session gets through without a second factor. Admins can require MFA for the whole group — users can't opt out.

⚙️

Central policy dashboard

Set routing rules, choose a gateway, and configure per-app splits from the admin dashboard. Every device picks up the policy automatically — no per-machine config, no re-deploy.

Per-app routing

Proxy only the apps that need it — browser, Slack, internal tools — and let everything else go direct. Finer control than a full-tunnel VPN, with none of the slowdown.

🛡

Works on managed machines

Installs without admin rights on Windows via a standard NSIS installer. No kernel driver, no system proxy conflict. Runs comfortably alongside corporate endpoint protection tools.

📱

Desktop and mobile

Windows, macOS, and Linux desktop clients. Android app available now — team policy applies the moment each user signs in. iOS coming.

📋

Per-connection audit logcoming

Every proxied connection logged — user, destination, timestamp. The compliance checkbox your security buyer will ask about. Shipping soon.

🔗

Inward access (ZTNA)coming

Let authorised team members reach services inside your office network from outside — without opening firewall ports or running a site-to-site VPN. No changes to your LAN.

How it works

Three steps — then every device follows

Set it up once. New team members pick up the policy the moment they sign in.

1

Create a group and set policy

Sign in as admin, create a team group, choose your gateway region, configure MFA requirements and routing rules — once, from the dashboard.

2

Invite your team

Send invite links by email. Existing TYO accounts join immediately. New sign-ups follow a guided setup and land straight in the group.

3

Policy follows everyone

Each member installs the client and signs in. That's it — your gateway, MFA, and routing rules apply automatically. Update a rule and every device picks it up within minutes.

How does this compare to Cisco Duo or Cloudflare Zero Trust? Duo Premier covers MFA and device trust at enterprise scale. Reach gives you the core — static gateway, MFA, and central policy — at a fraction of that cost, hosted in Australia, with no per-gigabyte billing and no vendor lock-in to a US cloud.

Pricing

Pay per seat, not per gigabyte

Team members get unlimited data through the gateway. You pay a flat rate per active seat.

Give your team a smarter gateway.