A smart internet gateway for your team
One shared exit IP your firewall trusts, MFA on every login, and routing rules that follow every seat automatically. No VPN client to manage. No data cap. Hosted in Australia.
Everything a team needs to stay secure
The features your IT team or security buyer will ask for — built into one lightweight client.
Static egress IP
Your whole team exits from a single IP address. Add it once to your cloud firewall, AWS security group, or SaaS allow-list — and every team member is automatically covered, no matter where they're working from.
MFA on every login
TOTP and Verified Push on every sign-in. No session gets through without a second factor. Admins can require MFA for the whole group — users can't opt out.
Central policy dashboard
Set routing rules, choose a gateway, and configure per-app splits from the admin dashboard. Every device picks up the policy automatically — no per-machine config, no re-deploy.
Per-app routing
Proxy only the apps that need it — browser, Slack, internal tools — and let everything else go direct. Finer control than a full-tunnel VPN, with none of the slowdown.
Works on managed machines
Installs without admin rights on Windows via a standard NSIS installer. No kernel driver, no system proxy conflict. Runs comfortably alongside corporate endpoint protection tools.
Desktop and mobile
Windows, macOS, and Linux desktop clients. Android app available now — team policy applies the moment each user signs in. iOS coming.
Per-connection audit logcoming
Every proxied connection logged — user, destination, timestamp. The compliance checkbox your security buyer will ask about. Shipping soon.
Inward access (ZTNA)coming
Let authorised team members reach services inside your office network from outside — without opening firewall ports or running a site-to-site VPN. No changes to your LAN.
Three steps — then every device follows
Set it up once. New team members pick up the policy the moment they sign in.
Create a group and set policy
Sign in as admin, create a team group, choose your gateway region, configure MFA requirements and routing rules — once, from the dashboard.
Invite your team
Send invite links by email. Existing TYO accounts join immediately. New sign-ups follow a guided setup and land straight in the group.
Policy follows everyone
Each member installs the client and signs in. That's it — your gateway, MFA, and routing rules apply automatically. Update a rule and every device picks it up within minutes.
How does this compare to Cisco Duo or Cloudflare Zero Trust? Duo Premier covers MFA and device trust at enterprise scale. Reach gives you the core — static gateway, MFA, and central policy — at a fraction of that cost, hosted in Australia, with no per-gigabyte billing and no vendor lock-in to a US cloud.
Pay per seat, not per gigabyte
Team members get unlimited data through the gateway. You pay a flat rate per active seat.