Skip to content

Accounting · Insurance · Law

The leak isn’t the work. It’s the chasing.

The organizer that comes back as photographs. The carrier statement nobody decomposes. The pre-bill that sits on a partner’s desk. Corveonic builds deterministic automation around the systems your firm already pays for, and a person approves anything that matters.

The year

Your problem runs on a calendar, not a clock.

A trades shop leaks by the hour. A firm leaks by the season. Three calendars, three different walls.

Accounting

The filing year

  1. Jan 311099s and W-2s out the door.
  2. Mar 151120-S and 1065. Your cutoff concentrates every S-corp on the day before it.
  3. Apr 151040 and 1120. The promise was two weeks; incomplete files made it three.
  4. Sep 15 · Oct 15Extension season, a permanent second busy season, and for many firms a deliberate capacity lever, not an accident.
  5. UnderneathMonthly close and payroll deadlines run continuously, all year.

Season-flattening is the profession’s own stated strategy. The survey behind the utilization figures on this page frames client right-sizing as evening out workflow with fewer busy-season ups and downs.

Insurance

The build into January 1

  1. 120 daysPull the renewal list, assemble policies and endorsements, order loss runs, document what’s missing.
  2. 90 daysCollect updated exposure data: payroll by class code, vehicle schedules, property values. Then the decision: renew with the incumbent, or remarket.
  3. 60 daysBuild the carrier-ready submission, submit to markets, chase underwriters.
  4. 30 daysQuote comparison, the documented recommendation, bind, deliver the policy package plus certificates.
  5. MeanwhileMedicare Annual Enrollment (Oct 15 – Dec 7) and ACA Open Enrollment (Nov 1 – Jan 15) land on the same desks, every autumn.

The cadence is well documented. What the AMS holds is policy records; what the cadence needs is pipeline state. That gap is why the renewal list lives in a spreadsheet.

Law

Not a season: a density

  1. AlwaysCourt calendars, statutes of limitation, service clocks.
  2. Q4Estate planning spikes around year-end tax planning and legislative sunsets.
  3. WindowsImmigration filing windows and lottery dates; family law after the holidays.
  4. The constraintMatter-level deadline density, not a calendar season. That is why the legal analogue of capacity smoothing is docketing.

The one metric that does run on a calendar is cash: work performed in March, billed in May, collected in July. That gap has a name, and a worksheet further down this page.

Measured leaks

What leaks, with the source shown.

Fewer numbers than you’d expect, on purpose. Most figures that circulate in this category don’t survive a source check, so everything below is named, dated and scoped. Where a number doesn’t exist, we say so instead of inventing one.

Track

Accounting

Realization at 100% is a trap, not a compliment

Your realization is probably at or near 100%. That is not good news. Firms under $1.5M in net client fees read ~100% because they bill fixed or per-form and carry no standard rates to write down against, so the leakage is structurally invisible in that metric. It lives in unbilled hours and scope creep instead, and realization only degrades once a firm is big enough to run standard rates.

Said as a partner would: “My realization is 100%. That’s not a good sign. It means I have no idea what I’m giving away.”

~100%AICPA PCPS / CPA.com National MAP Survey 2025, FY2024 data, n = 1,073 firms. Realization at firms under $1.5M net client fees, FY2024. A diagnostic, never good news: small firms bill fixed or per-form and carry no standard rates to write down against, so leakage is invisible in this metric. It lives in unbilled hours and scope creep instead.

Four in ten paid hours are chargeable to no one

Firmwide utilization runs 58–62% across every firm-size band. The complement is the leak: 38–42% of paid professional time never reaches an engagement, and the smallest firms sit at the bottom of the band.

58–62%AICPA PCPS / CPA.com National MAP Survey 2025, fielded May–July 2025 on FY2024 data, n = 1,073 firms. Firmwide utilization, FY2024, not per-position. Date it FY2024, not 2025. Position-level utilization runs 47.8%–70.0%; sub-$200K-NCF firms sit at 48.1%.

The market already prices disorganisation: it just can’t measure it

75.1% of preparers charge a higher fee for disorganised or incomplete paperwork, averaging an extra $145.14 on a sole-proprietor return. A firm that surcharges disorganisation has conceded the premise; it has just never been able to see who is disorganised until the work is already underway.

+$145.14National Society of Accountants Income and Fees Survey, 2020–2021 edition, via the Intuit Tax Pro Center. Average fee increment for disorganised or incomplete paperwork on a sole-proprietor return; 75.1% of preparers charge one. 2020–21 vintage: treat as a floor; fee levels have moved since.

Right-sizing is the profession’s own word

56% of firms culled clients in FY2024, down from 62% the survey before, and the publisher’s own reading is that the wave is slowing because it worked. Client selection is not an outsider’s idea; it is the profession’s stated strategy, and the builds below exist to give it a fact base.

56%AICPA PCPS / CPA.com National MAP Survey 2025, FY2024 data, n = 1,073 firms. Firms that culled clients in FY2024, down from 62% in the 2023 survey. Carry AICPA's own clause: the right-sizing trend is slowing, perhaps indicating past efforts have been effective.

Track

Insurance

Three of the top five E&O loss drivers are clerical

In order: failure to procure or give sufficient coverage; inadequate explanation of coverage; administrative errors, including data-entry mistakes affecting property values and deadline compliance; failure to identify client exposures; failure to communicate policy changes. Three of the five are process failures, not judgment failures.

You will notice no percentage next to any of those. The claims-by-cause data sits behind a member login and we could not retrieve it, so it does not appear here.

3 of 5Big “I” Professional Liability, via IA Magazine, 1 May 2025. Of the ordered top five E&O loss drivers, three are clerical and process failures. Claims-by-cause percentages and severity sit behind a member login and were not retrievable. No percentage may be attached to any of the five.

Certificates consume whole workdays

A hundred certificates at four minutes each is a full seven-hour day. The sharper problem needs no statistic at all: an endorsement retroactively invalidates certificates you already issued. The mid-term change is processed by one person, the cert went out weeks earlier from another, and nothing in the standard stack connects the two.

100 × 4 min = a 7-hour dayIA Magazine, 28 February 2026. Trade-press arithmetic on certificate issuance time. Measure your own minutes per certificate; every published per-COI figure is a vendor's.

The market turned, and the workload didn’t

CIAB’s Q1 2026 survey recorded the first average premium decrease since Q3 2017, at −1.2%, while commercial auto rose 5.8%, its 59th consecutive quarterly increase. In a hard market, rate does the growing. In a softening one, carriers compete for renewals, clients shop, and every account becomes a remarketing candidate: more submissions, more ACORD packets, more portal re-keying, for flat or falling revenue per account.

−1.2%CIAB Q1 2026 P&C Market Survey, released 13 May 2026. First average premium decrease across all account sizes since Q3 2017; small accounts were still rising, at +1.1%. The most time-sensitive figure on this page: re-verify against ciab.com immediately before launch (site needs a real browser).

+5.8%CIAB Q1 2026, via Leader’s Edge, 20 May 2026. Commercial auto, Q1 2026: the 59th consecutive quarter of increases.

Track

Law

Paid for 2.4 hours of an 8-hour day

The chain, on 2025 values: utilization 38%, realization 88%, collection 93%. Work eight hours, record 3.0 as billable, invoice 2.6, collect 2.4. Thirty percent of the workday converts to revenue.

2.4 of 8Clio Legal Trends benchmarks, 2025 values. Paid Clio subscribers in the US, a platform population, not the profession. The chain: utilization 38% → realization 88% → collection 93%. Eight hours worked, 3.0 recorded as billable, 2.6 invoiced, 2.4 collected.

93 days between the work and the money

Median total lockup is 93 days: work performed or invoiced and not yet paid, measured as (unbilled work + unpaid invoices) ÷ annual revenue × 365, revenue meaning billings. Almost no small firm tracks it, and it computes entirely from numbers the firm already has. The worksheet below runs it on yours.

93 daysClio Legal Trends benchmarks, 2025 values. Median total lockup: paid Clio subscribers, US; a platform population, not the profession. Lockup = (unbilled work + unpaid invoices) ÷ annual revenue × 365, revenue meaning billings. Never present it as a trend: the metric's denominator changed between editions, and restated like-for-like the direction reverses. No quartile from any year may be cited.

Half of firms can’t be reached by phone

In a 2024 mystery-shopping study of 500 US firms, 48% were unreachable by phone even after being given a chance to respond, and only 33% answered email at all. Nobody in those firms decided to lose the matter. The call arrived during a hearing, and the structure did the rest.

48%Clio client-intake research, 2024, n = 500 US law firms, mystery-shopped by phone and email. Firms unreachable by phone even after a chance to respond; only 33% answered email at all. Clio's own research. The revenue counterfactual attached to it in the source is not used anywhere on this site.

15% of clients say they never got a bill

Client-side, self-reported, 2023, and the publisher hedges its own headline: clients may have missed or forgotten bills their lawyer sent. We quote the hedge because it is the honest reading, and because the client’s experience of being billed is the part a firm can actually fix.

15%Clio 2023 Legal Trends Report, client-side survey. Consumers who have hired a lawyer at some point, self-reported, 2023. Carry Clio's own hedge: clients may have missed or forgotten bills their lawyer sent. The defensible claim is about the client's experience of being billed, not about firms failing to bill.

The rules we work under

What we refuse to build.

This page carries fewer statistics than the ones it competes with, because most of the numbers in this category do not survive a source check. We hold the product to the same standard as the evidence: what follows are refusals grounded in rules you already work under, which is also why no competitor copies this section without doing the reading.

We won’t tell you what document chasing costs your firm, either. There is no credible published figure, and the one you have seen quoted is a vendor’s spreadsheet built on forum posts. We’ll measure yours against your own utilization report in the first thirty days.

Across all three tracks

  • We do not send Form 1040-series Social Security Numbers outside the United States. 26 CFR 301.7216-3(b)(4). Not as an option, not with consent we obtained for you.
  • We do not put confidential client information into a model that trains on inputs, retains data indefinitely, or has undisclosed subprocessors. Where a model is used at all, it runs under enterprise terms with training disabled, and we publish the provider’s own commitment verbatim rather than characterising it.
  • We do not act without a human on anything that touches a filing, a client deliverable, a trust disbursement or a coverage recommendation.
  • We do not claim to make you compliant. We produce artifacts your own compliance obligations require. The Qualified Individual under 16 CFR 314.4(a) is a person at your firm, and it is never us.
  • We do not publish a case study or a testimonial, because we have none in this vertical and we would rather say so than invent one.

Accounting

  • We do not sign, transmit or file a return, and we do not touch the EFIN.
  • We do not categorise transactions or post to a general ledger.
  • We do not write your engagement letter or set your prices, including a capacity number or a fee for an out-of-scope form.
  • We do not build you another client portal, and we will argue against one. Portals fail when they move work to the client.

Insurance

  • We do not log into carrier portals with your credentials. Your appointment is the business.
  • We do not issue a certificate. We assemble it; a licensed person at your agency releases it. And we do not print special wording that is not supported by an endorsement on the policy: the single most important refusal on this track.
  • We do not decide appetite, compare quotes, or advise on coverage adequacy.
  • We do not assume your E&O risk. Some vendors in this category offer to. We are two people, and an indemnity from us is worth what a two-person firm’s indemnity is worth.

Law

  • We do not build a chatbot that gives legal advice, evaluates a matter, or can form an attorney-client relationship. Nothing we build sends an engagement letter without a named human pressing send.
  • We do not build lead scoring that ranks prospective clients.
  • We do not price our work for law firms per signed case.
  • We do not build a time-entry suggester, and this is the refusal that costs us the most money. Passive time capture is the most-requested legal automation in the market. Under the ABA’s fee rule, a suggested entry that inflates recorded time is an ethics violation, and for an hourly firm better capture plus better efficiency is a wash at best. We sell time capture with a pricing conversation, or not at all.
  • We do not move money in or out of a trust account, and we do not sign a reconciliation.
  • We do not commit a deadline. The system proposes; the lawyer confirms.
  • We do not scrape court dockets or integrate with court e-filing.
  • We do not advertise that anything we build performs like a lawyer. Every claim on this page is framed as assisting lawyers, operating under lawyer supervision, and not providing legal advice.
  • We do not build a consumer-facing document-assembly product without the guardrails N.C. Gen. Stat. §84-2.2 codified from the LegalZoom consent judgment.

What we actually build

Fifteen builds, each with its caveat attached.

Numbered because the order matters: the dependency chains inside each track are not reorderable, and each track names its strongest first project. The caveats are printed inline because they are the most commercially valuable content on this page.

Track one: accounting, tax and bookkeeping

Where we start: engagement to cash. Its output is an AR figure and an exception count you reconcile against your own accounting system in an afternoon. It asks for no faith in our dashboard.

The chain is fixed: the document ledger feeds the capacity queue, and the payment gate is where a fee gets fixed and re-quoted. A vendor who reorders these has not thought about the build.

The strongest first project

Engagement to cash: the payment gate and the AR that follows

You took a deposit up front, and some clients still never sent their documents. Chasing them cost more than the deposit. A deposit is a price signal; a gate is a state machine. The gate doesn’t exist today because it takes four systems agreeing (time, delivery, invoicing and payment) and none of them share state.

What we build

  • One gate state per engagement, from engagement letter sent through paid to delivered, with the upload target and the delivery step both conditioned on the gate.
  • Invoice on signature, with the payment link in the same message as the letter.
  • A release rule you write and we implement: full fee, deposit, or exemption by client tier. We do not ship a default, because a default is us telling you how to price.
  • AR aging with structured dunning that stops permanently on any human touch, and never sends to a client flagged in dispute.
  • An exceptions register: work that started before the gate opened. Every firm has exceptions; almost none can count them.

What the dashboard shows

Gate Board (engagement · state · days in state · fee · invoiced · paid · owner) · AR Aging (0–30 / 31–60 / 61–90 / 90+, reconcilable line for line to your accounting system) · Exceptions (count, dollars, who authorised) · Deposit Compliance, trended by week.

The honest caveat

This is a policy change wearing a software costume, and we say so before the invoice: if the partner won’t enforce the gate, the build produces a very good report about a decision nobody is making. We are not a collections agency, we do not touch the merchant account, and we do not recommend a processor.

The document ledger: what you asked for against what arrived

You asked for fifteen items and got back two. The organizer is functionally dead as a data-collection instrument, everyone in the firm knows it, and the workaround is an administrator manually comparing arrivals against the checklist and last year’s return. No system in the category does that diff natively: a claim you can check inside your own software in ninety seconds.

What we build

  • A structured PBC list per engagement: one row per expected item, with document type, payer or EIN, tax year, and a fixed state: requested, received, illegible, superseded, not applicable, waived.
  • Multi-channel ingest into one queue: portal, monitored email, front-desk scans, phone photographs, with the channel recorded.
  • Matching of arriving documents to expected items; anything uncertain routes to a person, because a misfiled document is worse than a missing one.
  • Reminders that name the specific missing items, in the channel the client already uses. One, then a second, then a human, never an indefinite drip, always inside the 8am–9pm send window, on one shared suppression list.
  • A status view the client can read without logging in, because the login is the failure point.

What the dashboard shows

Item Ledger (client · engagement · item · payer/EIN · state · channel received · days open · reminders sent · owner) · Completeness per engagement, ordered by acceptance date rather than by percentage · Channel Split · Unmatched & Illegible, oldest first, with the source image alongside.

The honest caveat

We do not build you another portal, and we will argue against one: status and requests push to the channel the client already uses, and nothing requires a login to learn what is missing. TaxDome, Canopy and SafeSend all collect documents at scale; the seam is the reconciliation between the checklist and what arrived, and the seam is what we build. And OCR on a phone photograph of a 1098 fails often; expect a permanent manual queue, not a temporary one.

The scope ledger: what you gave away

Your realization says 100% and you have no idea what you’re giving away. The out-of-scope K-1 is discovered mid-return, by the preparer least able to stop and re-quote, and by the time anyone would look, the return is filed and the fee is fixed. There is no artifact, no register, no aggregate.

What we build

  • A structured scope on the engagement letter: included forms, schedules, entities and state filings become a list rather than a paragraph.
  • An out-of-scope register: every form, schedule, entity, state or K-1 that appears in preparation and is not on the list, timestamped, with the preparer and the client. It blocks nothing; a hard block mid-season is a business-stopping mechanism and we do not ship one.
  • A re-quote prompt at the moment of discovery, routed to whoever owns the relationship, carrying the item and your own price for it.
  • The K-1 wait clock: engagements held on an inbound K-1, with the entity and the days waiting.
  • A season-end reconciliation of fee quoted against fee realised, per engagement.

What the dashboard shows

Scope Register (client · item · discovered by · date · your price for it · re-quoted? · billed?) · Quoted vs Realised by partner, sorted by difference, uncomfortable by design · The K-1 Board · Repeat Offenders, against your own threshold, two consecutive seasons.

The honest caveat

If your engagement letter says “prepare your 2026 returns”, there is nothing to be out of scope of, and the first project is a form-level engagement letter: a drafting change, and we say so before the build, not after. We do not write your engagement letter, we do not price your work, and nothing here re-quotes a client automatically.

Signature, e-file reject and delivery chasing

The return is prepared, reviewed and finished. Then it stops for weeks behind a spouse’s missing signature on Form 8879 or a reject nobody triaged. The acknowledgments live in the tax software, the signature status in the delivery tool, the client in email. No system in the firm holds a single answer to which returns are prepared and not filed.

What we build

  • A filing-state ledger, one state per return, with signature tracked per signatory, because “signed” on a joint return is not a boolean.
  • Reject classification by code, with your own resolution note attached to each code: the firm’s institutional knowledge, captured once, versioned. We do not bring a template of resolutions and we do not guess at them.
  • An escalation clock that tightens toward the deadline. A return sitting unsigned in February gets a reminder; the same return in April gets a phone-call task assigned to a named person. The ladder ends at your partner, never at us.
  • The extension decision list, surfaced with enough lead time that extending is a decision rather than a scramble.
  • Reconciliation against the tax software’s own acknowledgment feed, so the two states cannot silently diverge.

What the dashboard shows

Filing Board (return · state · days in state · signatories signed/required · days to deadline · preparer · reviewer) · Partial Signatures, its own view, because it is invisible everywhere else · Reject Reasons, coded, by period and preparer · Deadline Countdown.

The honest caveat

We do not transmit returns: the e-file authorisation is the practitioner’s, the EFIN is the firm’s, and the liability follows both. We do not resolve rejects; that reconstruction is professional work. And a firm still on paper signature gets a smaller version of this build. We say which one you’re getting in week one.

The capacity queue: a slot claimable only when the file is complete

Your cutoff is March tenth, so every S-corp lands on the ninth. A date cutoff concentrates arrivals at the date; the backlog survives. The counter-pattern already exists in the profession: define capacity, and let a client claim a slot only once their file is complete. That inverts the incentive the organizer has failed to create for thirty years.

The cost of not doing it is the best-evidenced harm in the vertical: 78% of accountants exited the season with measurable damage, on an index of 438 respondents, and firms of 6–15 people scored noticeably worse than firms of 51–200.

78%Tax Season Survival Index (Hitendra Patil, Accountaneur Advisory), n = 438, reported by Accounting Today, May 2026. n = 438 accountants and tax professionals; a 26-question index built by one consultant. Name the sample size in the same sentence as the figure, every time.

What we build

  • A capacity model you define: slots per week, by complexity tier, with your own hour budgets. We implement your numbers and supply no default, because a default capacity is us telling you how fast your people work.
  • Slot claim conditioned on the document ledger’s completeness signal: the dependency that makes the whole thing work.
  • A waitlist with a visible position, and a rule for released slots.
  • The extension decision list, shared with the filing ledger, so the returns that will not fit are extended deliberately in February.

What the dashboard shows

The Queue (slots by week and tier: claimed, available, waitlisted) · Load by Week, as a forward projection: the only useful time to know you’re overcommitted is before you are · Tier Budget vs Actual, which is why next season’s tiers are better than a guess · Extension Decisions.

The honest caveat

This is a business-model change, and we lead with that sentence rather than burying it: if the partner won’t cull, won’t say no, and won’t raise prices, the queue becomes a waitlist everyone jumps. It depends entirely on the document ledger: a vendor selling you the queue without asking how your documents arrive has not thought about the build. And the first season’s tiers will be wrong; the dashboard corrects them over a year.

Monthly close: the uncategorized queue and the client blocker

The entire close hangs on one unresolved queue: uncategorized transactions plus missing receipts, and the client is the blocker. Every CAS firm of any size has built the same per-client spreadsheet, by hand, and maintains it monthly. A client who receives forty separate categorisation questions across a month answers none of them; a client who receives one weekly list of forty answers most of it. The batching is the intervention, and the platforms don’t do it because they are transaction-shaped rather than client-shaped.

What we build

  • A per-client question queue that replaces the spreadsheet: one row per unresolved transaction, with the proposed category and the question.
  • Batched asks: one message per client per week, in the channel that client actually uses, with a reply path that needs no login.
  • Feed integrity checks against the statement (duplicate imports, date gaps, month-end balance mismatches) surfaced as exceptions, never corrected silently.
  • Recurring-rule proposals where the same payee has been categorised the same way three times. A human approves every rule, and rules are versioned.
  • A close state per client, from open through reconciled to closed, with dates.

What the dashboard shows

Close Board (client · period · state · days in state · open questions · days since last client response), distinguishing waiting-on-us from waiting-on-them · Open Questions by age · Feed Integrity, with the statement figure alongside · Rule Coverage, with its counterweight: rules that produced a correction.

The honest caveat

If you already run Uncat, Client Hub, Keeper or an equivalent, say so and we won’t sell you this; those products solve this problem, several of them well. We do not categorise transactions and we do not post to a general ledger; both are professional judgment with tax consequences. And we attach no dollar to a faster close: that would be a margin claim on a cost of delivery most CAS firms do not measure, against a benchmark that is paywalled. We would rather say that than borrow a number.

Track two: independent insurance agencies

Where we start: commission reconciliation. Expected against received, decomposed policy by policy, verifiable against your own bank in a single afternoon.

One honesty note that governs this track: the operational ranges that circulate in this vertical (minutes per cert, hours per submission, completeness rates) are published by firms selling the solution. None of them appears in any arithmetic on this page.

The strongest first project

Commission reconciliation: the statement against what you expected

Direct-bill commission is earned before cash arrives, then adjusted retroactively by endorsements, cancellations and chargebacks, and generic accounting software assumes revenue and cash align. The commission lives under a policy number on a carrier statement; the expectation lives in the AMS; the money lands as a sweep in the bank. Nothing joins them, so the join is done by a person, once a month, under time pressure, or not at all. A short payment is quieter than a chargeback: it generates nothing but a smaller number inside a larger total.

What we build

  • Discovery first, paid, about a week: which carriers deliver a machine-readable statement, in what format, and how complete your AMS commission rates and producer splits actually are. It gates every scope estimate afterward; anyone quoting this build without it is guessing.
  • Ingest and normalise statements to one shape: carrier, policy number, insured, premium basis, commission, transaction type.
  • Build the expected side from the AMS: policy, premium, rate, producer split.
  • Match statement line to policy; classify every line: paid as expected, paid short, paid over, chargeback, duplicate chargeback, not paid, unmatched. Unmatched is a first-class state and is never quietly dropped.
  • Age everything unpaid, oldest first, by carrier; total expected against received by period, carrier, line and producer.

What the dashboard shows

Statement Ledger (carrier · policy · insured · received · expected · variance · state · producer · days open) · Expected vs Received, decomposed, displayed as an arithmetic identity you can check against a statement by hand · Aged Unpaid past 30/60/90 · Unmatched Queue, count always on the front page · AMS Data Quality, shipped on day one; if much of the book has no rate on it, you should know before you see the variance.

The honest caveat

We do not log into carrier portals with your credentials; the appointment is the business. If discovery finds no usable statement format for the carriers that matter, we say so and stop; discovery is priced separately precisely so it can end in “no”. Group benefits is materially harder than P&C, because per-member eligibility data largely does not download; scope it separately or exclude it in the contract. And we will not quote you an industry leakage percentage: the figures that circulate are claims, not benchmarks. What we sell is the audit that produces your number.

Certificates: issuance, the holder registry, and reissue on endorsement

A hundred certificates is a whole workday, and one wrong cert is an E&O claim. The requirement lives in a construction contract nobody at the agency has read, so the cert is reconstructed from the last one issued, which reproduces last year’s error indefinitely. And when a policy is endorsed mid-term, certificates already in circulation become wrong, with no system connecting the change to the paper.

What we build

  • A cert holder registry: the entity the AMS does not have. Per holder: required coverages and limits, additional insured, waiver of subrogation, primary and non-contributory, the special wording verbatim, distribution method, expiry.
  • Issuance from AMS policy data rather than from the last certificate, so a stale limit cannot propagate.
  • Reissue on endorsement: when an endorsement changes a limit, a named insured, a location or an effective date, the registry returns the list of certificates that endorsement just made wrong, with their holders. This is the flagship, and the reason to buy the build.
  • A worklist for general-contractor compliance portals: the packet assembled and staged, a person submits.
  • Rejection reason capture, coded; an expiry board driven by holder requirements and policy terms.

What the dashboard shows

Holder Registry, with special wording displayed in full, never truncated · Endorsement Impact (certificates invalidated · holders affected · corrected or not · days since); this view is the product · Turnaround as a distribution, not an average, because the tail is the job site somebody couldn’t get onto · Rejection Reasons · Expiry Board.

The honest caveat

Special wording is a coverage question, not a text field. A certificate that prints “additional insured, primary and non-contributory” without a supporting endorsement on the policy is a misrepresentation of coverage, so a licensed person at your agency reviews and releases every certificate against the actual endorsement, and there is no configuration that turns that off. Applied Epic, AMS360, HawkSoft, EZLynx and NowCerts all issue certificates; the seam is the holder registry and the endorsement-to-certificate join. And a registry built from historical certificates inherits historical errors: the backfill is a real part of the first project.

The submission spine: ACORD data entered once

The same client’s name is typed into the AMS, into a rater, and then into each carrier’s own portal: three to six times before a single quote comes back. The ACORD 125 header data is re-keyed everywhere; a class-code typo cascades into the policy and then into the certificate. And the loss run, requested at 120 days and frequently late from the carrier, is the single most common reason a submission goes out incomplete.

What we build

  • One canonical applicant record, with the ACORD 125 header data as its spine, mastered in one place. Everything downstream reads from it and nothing re-types it.
  • ACORD form generation from that record: 125, 126, 127, 130, 140 and the supplementals your agency actually uses.
  • Completeness validation before submission, against your own rules: class codes present and valid, exposure basis present, loss runs attached and current, schedules attached. A failing submission is held, not blocked.
  • A portal-entry worklist: for carriers with no other path, the data staged field by field, in the order the portal asks, deliberately not credentialed automation.
  • Submission tracking with coded decline reasons; loss run ordering and chase with days outstanding.

What the dashboard shows

Submission Board (insured · line · carrier · state · days in state · decline reason · producer) · Completeness at First Submission: your own rate, measured, not a vendor’s comparison · Market Response by carrier: acknowledgment and quote turnaround, decline rate, coded reasons: appetite intelligence the agency does not currently have anywhere · Loss Run Status · Re-key Count, the number you have never seen and will immediately recognise.

The honest caveat

We do not automate carrier portals with your credentials. The vendors themselves concede the forms have hundreds of fields and change regularly, and credentialed automation against a system that has not sanctioned it puts the appointment at risk. We stage the data; a person enters it. A rater reaches the markets it reaches, for everything outside it, the honest deliverable is faster keying, not no keying, and the in-scope markets are named in the contract. We do not decide appetite, and we do not write the operations narrative: that is the part of the submission an underwriter actually reads.

The renewal cadence and the shadow spreadsheet

The renewal list lives in a spreadsheet because the system doesn’t know you’re waiting on a carrier. Three reasons, all real: the AMS renewal view is buried and built for a bigger firm; the AMS holds policy records, not pipeline state; nothing in it says “submitted to four markets, two declines, one pending”; and the data is stale, because download doesn’t carry everything and endorsements aren’t posted timely, so the renewal owner keeps a shadow copy they trust.

What we build

  • A renewal board that holds pipeline state: stage, markets approached, acknowledgments, quotes in hand, declines with reasons, pending items, and the named blocker. The shadow spreadsheet, made shared, current and auditable.
  • The 120/90/60/30 task ladder generated per renewal, assigned to a named person, with the artifacts each stage requires.
  • Loss run ordering at 120 days, tracked as its own object; an exposure-data request at 90, built from the prior-year application, so the client is asked for changes rather than for everything.
  • The decision log: the documented recommendation, the client’s decision, and the date. The E&O artifact, exportable in full.
  • Data-hygiene exceptions: expirations, premiums and producer assignments that disagree with the policy or the download.

What the dashboard shows

Renewal Board (insured · expiration · days out · stage · markets out · quotes in · declines · blocker · owner) · Data Hygiene as a share of the book, shipped on day one: the honest counterweight, because a board built on stale expirations is a shadow spreadsheet with better fonts · Decision Log · Loss Run Status.

The honest caveat

You are replacing a spreadsheet somebody trusts, and they trust it because the AMS data is stale. Cleaning the AMS is the real first project, and we say so before the invoice. We do not recommend coverage, compare quotes, or advise on adequacy: licensed work, and the producer’s. And we attach no retention number to this: retention cannot be attributed without a control no principal would ever run, and we won’t publish a correlation dressed as a result.

Policy checking against what was bound

Comparing the issued policy against what was quoted and bound (against a checklist that runs past nine hundred points) is the highest-return E&O control in an agency, and the first thing dropped when the team is busy. An entire outsourcing sub-industry exists only because agencies cannot get it done in-house. A control whose only output is the absence of a problem loses every scheduling contest it enters.

What we build

  • Structured capture of what was quoted and bound: carrier, dates, named insureds, locations, limits, deductibles, forms and endorsements, subjectivities.
  • Ingest of the issued policy: declarations plus the forms schedule. Where it arrives as a scanned PDF, extraction runs into a review queue, not through it.
  • A structured diff across the header, insureds, locations, limits, deductibles, and the forms schedule, which is where reduced limits and added exclusions actually live.
  • An exception queue: every difference adjudicated by a licensed person, nothing auto-cleared.
  • The evidence log (which policies were checked, by whom, when, against what, and what was found) and coverage tracking against the 30-days-from-binding standard the profession already sets for itself.

What the dashboard shows

Check Queue with the 30-day line marked · Exceptions by type, quoted value beside issued value · Coverage of Checking, trended by producer and carrier · Time to Check as a distribution · Extraction Confidence, published: a checking product that hides what it could not read is worse than none.

The honest caveat

A diff is not a coverage review. We do not read policy language and form a view on adequacy (that is licensed judgment) and a nine-hundred-point checklist is not a nine-hundred-point automation: we diff the structured fields reliably and flag the forms schedule for a human. We do not assume your E&O risk, and some vendors in this category offer to; we are two people, and pretending our indemnity was worth more would be the least honest thing on this page. If your checking is already at 100% within 30 days, we will say so and not sell you this.

Track three: small law firms

Where we start: lockup. The formula is published, the inputs are the firm’s own, and your bookkeeper can check the arithmetic.

And the sentence most vendors in this market avoid: selling automation to an hourly law firm without a pricing conversation is selling them a pay cut. The governing fee rule is quoted in the compliance section below. It is why this track leads with cash and intake, not with making the legal work faster.

The strongest first project

Lockup: the days between doing the work and holding the money

There is likely six figures of your revenue sitting in work you haven’t billed and bills nobody has paid. Lockup is the one metric in this category that is publicly defined, computes entirely from your own numbers, and almost no small firm tracks. The mechanism inside the firm is a queue with one server: the pre-bill goes to a partner, the partner is billing, the pre-bill sits.

One measured lever, quoted as the vendor’s own data and nothing stronger: Clio’s 2023 numbers associate a bill-approval workflow (a non-lawyer drafts, the lawyer approves) with realization of 89% against 82%. Clio expected the finding to run the other way, and said so. A vendor publishing a result that contradicted its own hypothesis is the most credible thing in that dataset.

89% vs 82%Clio 2023 Legal Trends Report. Realization with vs without a bill-approval workflow: paid Clio subscribers, contiguous US, 2023. Clio's own measurement of its own users, correlational: a 7-point association, not an outcome promise. Grade B as “Clio's own data shows”; Grade C as a promise.

What we build

  • WIP surfacing: unbilled time and disbursements by matter, by responsible attorney, aged. Most firms cannot see this today without exporting to a spreadsheet.
  • Pre-bill assembly on a schedule, not on a partner’s initiative: unbilled entries, disbursements, prior balance and trust position in one reviewable document.
  • A bill-approval workflow with the approval logged (a timestamp and a name) which is what makes the supervision demonstrable rather than assumed.
  • Delivery by email direct from the billing system, with an outstanding-balance summary and a payment link.
  • A reminder sequence that stops permanently on any human intervention, and never runs on a matter flagged in dispute.
  • A write-down register: every reduction between recorded and invoiced, with the reason and who made it. This is where realization actually goes, and no firm of this size can currently see it.

What the dashboard shows

Lockup in dollars first: unbilled work and unpaid invoices, aged by matter and responsible attorney; days second, on one stated definition: (unbilled work ÷ annual revenue) × 365, revenue meaning billings · WIP Aging 0–30 through 90+ · Pre-bill Board, where days-with-the-attorney is the field that does the work · Delivery and Payment, your own collection curve, not a benchmark · Write-downs by attorney and matter type.

The honest caveat

For an hourly firm this moves cash forward; it does not create revenue. Billing faster does not add hours, and the ABA’s fee rule (quoted in the compliance section below) says hourly bills can only reflect actual time. The firm that gains most has already moved to flat or subscription fees, which is why pricing model is part of the engagement, not an afterthought. The responsible lawyer approves and releases every bill; we never send one. And a true solo with nobody to draft a pre-bill cannot use the measured lever; we will say so rather than sell a two-person workflow to a one-person firm.

Intake: the response clock and the conflicts gate

You paid for the lead, and then nobody picked up the phone. The failure chain is structural: the call arrives during a hearing, goes to voicemail, is returned hours later to the prospect’s voicemail, and the prospect has already retained the second firm they called. And intake is where conflicts are created: the part almost every intake vendor ignores. Information taken from a prospective client through any channel can conflict the whole firm out of a matter, which is why the conflicts check belongs at the front of intake, not after it.

What we build

  • One intake record per PNC: channel, source, the situation as described, the adverse parties named, timestamped. Adverse parties are captured at first contact, because that is what the conflicts check needs.
  • An immediate acknowledgment with a real next step (a scheduling link, a named person, a time window) that says in plain words it is automated.
  • Routing to a named human with an escalation clock. Unclaimed past your own interval, it escalates; the ladder ends at your partner, never at us.
  • A conflicts check run at intake against a consolidated party database, assembled from the practice-management system, the contact store and the historical matter list, before substantive information is taken.
  • A matter-opening packet on acceptance: engagement letter from your own template, e-signature, matter number, file structure. A named human presses send.
  • A response-time ledger: time to first human contact, per channel, per source.

What the dashboard shows

Intake Ledger (date · channel · source · matter type · adverse parties · conflicts state · time to first human contact · disposition · owner) · The Response Clock as a distribution, by channel and hour of day: the failure concentrates in the tail and in the hours you are in court · Conflicts Queue, nothing clears itself · Unanswered, count on the front page: the study’s 48%, computed on your own inbox · Source and Disposition: counts only; there is no revenue column.

The honest caveat

Nothing here gives legal advice, evaluates a matter, or can form an attorney-client relationship; every outbound message is logged, reviewable and editable, and a responsible lawyer is notified of any interaction that could have created a relationship. We will not build lead scoring that ranks prospective clients, we will not price this per signed case, and we will not multiply your answer rate by a value per matter: the mystery-shopper study is a real study, and it is enough. Recording an intake call is treated as an all-party-consent event, with the disclosure captured inside the recording.

Trust: three-way reconciliation and the exceptions that precede a discipline file

The trust ledger and the general ledger disagree, and someone has to find out which one is lying before Friday. Most cloud practice-management products give you a trust ledger but not a general ledger, so the firm runs accounting software alongside, and every trust deposit, earned-fee transfer and cost advance is keyed twice. Reconciliation drift is the normal state, not the exception. The detail that matters most: a negative individual client ledger is the arithmetic signature of using one client’s money for another, and it is a discipline trigger even when it is entirely unintentional.

What we build

  • An exception engine, not a trust ledger, and we never move money. Nightly, over the trust ledger, the general ledger and the bank feed:
  • Negative client ledger detection, run daily, with the transactions that caused it.
  • An uncollected-funds watch: disbursements against deposits that have not cleared, flagged before the disbursement, using your own hold rules.
  • The three-way tie-out (general ledger, the sum of the positive individual client ledger balances, and the adjusted bank balance), computed and displayed as three components and their difference, on your jurisdiction’s cadence.
  • Fee-transfer support: every trust-to-operating movement matched to an invoice. Unsupported transfers are exceptions, not errors to be corrected quietly.
  • The reconciliation artifact your rule requires, generated and presented for a person to review, sign and date, with your jurisdiction’s retention period.

What the dashboard shows

Tie-Out: A, B and C side by side with the difference: an arithmetic identity you can check against the statement by hand · Negative Ledger Alarm, count always visible; zero is the only acceptable value and the view says so · Uncollected Funds · Reconciliation Register: the artifact a bar auditor asks for · Unsupported Transfers · Controls: three yes/no fields, and a firm that cannot answer all three has found something out.

The honest caveat

We never move money (no transfer, no disbursement, no adjusting entry) and we do not sign the reconciliation: the rule requires a lawyer’s review, signature and date, and the signature is the point of the rule. We implement your jurisdiction’s rule, not a generic one, and we name which state’s rule we implemented in the contract; cadence, retention and supervision requirements differ materially by state. We attach no dollar to any of this: the consequence of a trust failure is a licence, not a number. And the first tie-out at a firm that has not reconciled properly will find something; that is a question for your own counsel or your bar’s ethics line before it is a question for us. We say that before go-live, in writing.

The worst first project — named, deliberately

Docketing: deadlines as a rules calculation

The firms with the most court dates have the least docketing infrastructure: 78% of small-firm practitioners are in the courtroom, small firms average 33 appearances a year (more than double firms of 100 or more) and only 27% of solos have litigation support software. A deadline is a rules calculation: trigger date, service method, the court’s own rules, the holiday calendar. There is no judgment in the arithmetic. The judgment is in identifying the trigger and confirming the rule, and both of those are lawyer work.

27%ABA 2024 Solo & Small Firm TechReport. Solos with litigation support software; 38% of small firms, against 73% of large firms. Paired finding: 78% of small-firm practitioners are in the courtroom, and small firms average 33 appearances a year (an average; the report gives no distribution).

What we build

  • A deadline engine that computes downstream dates from a trigger a person recorded: service, filing, entry of an order, a hearing set.
  • Every computed date enters the calendar unconfirmed, and an attorney confirms it. There is no setting that changes this.
  • The rule set is yours, versioned, and explicitly scoped: we publish which jurisdictions and rule chains are implemented and, more importantly, which are not.
  • Ticklers at your own intervals before each confirmed deadline, assigned to a named person.
  • A calendar write with provenance: which trigger, which rule, which version, computed when, confirmed by whom.

What the dashboard shows

Deadline Board · Unconfirmed, oldest first, count on the front page: the safety metric, and the first thing on the screen · Rule Set Coverage, with an explicit list of what is not covered · Trigger Capture: matters with recent filings and no trigger recorded, because the engine computes only from what it was told.

The honest caveat

This is the worst first project on this page, and we say so. The liability is asymmetric: a wrong date is a missed deadline, and a missed deadline is malpractice; the rule set is a research engagement before it is a build; and its value section is deliberately empty, because the outcome is a claim that did not happen and we will not invent a probability multiplied by a consequence nobody has priced. Build it third or later, in named jurisdictions, with published coverage gaps, for a firm that already trusts the work. We do not scrape court dockets, we do not integrate with court e-filing, and we do not offer an indemnity for a missed deadline.

Run your own numbers

The worksheet, not the promise.

Every field starts empty, every number in the arithmetic is yours, and nothing you type leaves your browser: no request, no storage, no analytics on the values. The result is allowed to be unimpressive: at low volume, the honest answer is that this probably is not worth buying, and the arithmetic will say so.

Accounting

Days of receivable

Three numbers from your own accounting system, for one closed season. Nothing here is a projection; the dollars are already yours.

  1. $
  2. $
  3. $

The arithmetic appears here once the lines above are filled. Blank is the honest starting state — no field on this page is pre-filled.

Insurance

Certificate hours

Measure your own minutes per certificate for one week. We do not supply the number, and every published per-certificate figure is a vendor’s.

  1. certs
  2. min
  3. certs

The arithmetic appears here once the lines above are filled. Blank is the honest starting state — no field on this page is pre-filled.

Law

Lockup, in dollars first

Three numbers from your billing system and your general ledger, on any chosen date. Revenue means billings; at a cash-basis firm that equals collections.

  1. $
  2. $
  3. $

The arithmetic appears here once the lines above are filled. Blank is the honest starting state — no field on this page is pre-filled.

Context, someone else’s data: Clio’s 2025 median total lockup is 93 days: paid Clio subscribers, US; a platform population, not the profession. It sits beside the field, never inside it.

For comparison, not as a promise: Corveonic retainers run $597–$1,997 a month, plus a one-time setup fee. Pricing$597–$1,997/moCorveonic pricing, signed off 2026-08-04.

The incumbents

You already pay for most of a platform.

This is not an argument that your practice-management system, your AMS or your tax software can’t do their jobs. They can. It is an argument about contracts and seams, made mostly in other people’s words.

The profession is un-adopting the all-in-one

Practice-management software availability fell from 63% to 53% between 2022 and 2024, and solo use fell from 45% to 37%. The ABA blames à-la-carte pricing in its own words: “Gone are the days when case management platforms offered simple pricing options for the entire product.”

63% → 53%ABA 2024 Practice Management TechReport. Practice-management software availability, 2022 → 2024; solo use fell 45% → 37%. The ABA's own stated cause is à-la-carte pricing: “Gone are the days when case management platforms offered simple pricing options for the entire product.”

The category’s own self-diagnosis

In one practitioner’s words, from a public accounting forum: “a lot of platforms will do 90% of everything… it’s like they just said ‘eh close enough’ and left out enough crucial features that are kind of obvious.” The remaining ten percent is the part that touches your margin, and it is the part we build.

The documents aren’t even in the platform

Small-firm documents live in Microsoft 365/OneDrive at roughly 72%, Dropbox 54%, NetDocuments 17%, against Clio at 15% and MyCase at 5%. The practice-management platform is not where the documents live, which is precisely why the integration seams exist.

~72%ABA 2024 Cloud Computing TechReport. Small-firm documents in Microsoft 365/OneDrive; Dropbox ~54%, NetDocuments ~17%, Clio ~15%, MyCase ~5%.

The à-la-carte bill, made concrete

Clio Manage publishes a floor of $49 per user per month; its higher tiers are not in the page text, so we won’t quote a ceiling. Rocket Matter publishes no price at all for its practice-management tiers; what it publishes is the add-on stack: CRM at $39 per user per month, a $147-a-month CRM tier, $399 onboarding, $500 data import, $599 website setup plus $149 a month hosting, and $2 per e-signature envelope, all on top of an unpublished base. And MyCase sells three-way trust reconciliation, a bar obligation, as a $39-per-user-per-month add-on. Prices as accessed August 2026; they move, and we re-check them.

from $49/user/moclio.com/pricing, $49/user floor (tier now named Starter, formerly EasyStart), accessed 2026-08-05. Published floor only. Higher tiers are not in the page text; do not quote a Clio ceiling. Re-verify before launch (§3 expiry rules).

$39 + $147 + $399 + $500 + $599 + $2rocketmatter.com/pricing, accessed 2026-08-01. CRM Core $39/user/mo (annual) · CRM Enterprise $147/mo · onboarding $399 · data import $500 · website setup $599, plus $149/mo hosting · e-signature overage $2/envelope. Every figure is an add-on to practice-management tiers whose base price the vendor does not publish. Never present $39 as a Rocket Matter seat price. Re-verify before launch.

$39/user/momycase.com/pricing, MyCase Accounting add-on, accessed 2026-08-01. A named competitor's paid add-on for “compliance with three way trust reconciliations”. Re-verify before launch (§3 expiry rules).

On the insurance side, the spreadsheet is the tell

The renewal list lives in Excel next to a capable AMS for three reasons agencies will recognise: the renewal view is buried and built for a bigger firm; the AMS holds policy records, not pipeline state; and the data is stale, so the renewal owner keeps a shadow copy they trust. The AMS is not the problem. The join between the AMS, the statement and the bank is.

We don’t sell you another login. We make the systems you already pay for agree with each other, and we build the ten percent nobody ships.

Compliance

The rules we build to.

Most of the work on this page requires no model call at all. Chasing documents, tracking status, assembling packets, reconciling ledgers, watching deadlines: deterministic work over structured data. We design it that way deliberately and say so, because the consent question is a function of architecture before it is a function of paperwork.

US-only processing, and no 1040-series SSN leaves the country

Under 26 CFR 301.7216-3(b)(4), a US preparer generally may not disclose a Form 1040-series taxpayer’s Social Security Number to a preparer located outside the United States. All Corveonic processing and storage is in the United States.

The §7216 contractor notice is signed before any access

26 CFR 301.7216-2(d)(2) is the lawful pathway: a US-based contractor performing programming, maintenance, repair or testing of software used for tax return preparation may receive tax return information without separate taxpayer consent, provided the firm gives written notice describing the §7216 and §6713 requirements and penalties. We provide it signed at engagement. That notice makes us a tax return preparer subject to the same rules.

Your Safeguards obligations don’t shrink because you’re small

16 CFR 314.4(f) requires you to contractually require service providers to maintain safeguards, and to assess them periodically. That is the clause we sign, and we arrive with the artifacts your annual review needs, mapped to the elements of §314.4: encryption in transit and at rest, multi-factor authentication, least-privilege access, audit logging.

Human approval on anything that matters, and every approval logged

Circular 230 §10.22(b) permits reliance on another’s work product where the practitioner used reasonable care in engaging, supervising, training and evaluating that person; Model Rules 5.1 and 5.3 apply the same logic to lawyers supervising nonlawyer assistance, including vendors. So anything that touches a filing, a client deliverable, a trust disbursement or a coverage recommendation requires affirmative human approval, and every approval is logged so the review is demonstrable.

Documentation ships, not assurances

California COPRAC’s current Practical Guidance, which states it replaces the November 2023 version at the California Supreme Court’s request, puts it plainly: “Reasonable efforts require more than reliance on generalized marketing assurances.” So the engagement deliverable is a package: terms of use, data processing terms, a named subprocessor list that goes one level deep to our vendors, our security posture mapped to the relevant controls, and a written description of exactly which systems the automation can reach and what it may do without a human.

Provider commitments are quoted, never paraphrased

Anthropic’s Commercial Terms state: “Anthropic may not train models on Customer Content from Services.” OpenAI states that data sent to its API “is not used to train or improve OpenAI models” unless a customer opts in, with abuse-monitoring logs retained up to 30 days and Zero Data Retention available to approved customers. We publish the provider’s own words and configure to them.

On consent: two verified authorities, and an architecture that doesn’t need to pick a side

The two authorities we build the consent argument on are ABA Formal Opinion 512 (July 2024) and California COPRAC’s current Practical Guidance. COPRAC’s standard is the operational one: “The degree of lawyer diligence and supervision must correspond to the level of system access and autonomy.” A system that does not put client information into a generative model does not have to pick a side in the consent debate at all, which is the point of the architecture above.

And the fee rule, in the ABA’s own words, quoting its Formal Opinion 93-379: “If a lawyer has agreed to charge the client on [an hourly] basis and it turns out that the lawyer is particularly efficient in accomplishing a given result, it nonetheless will not be permissible to charge the client for more hours than were actually expended on the matter.” That sentence names the exact situation automation creates. It is why the legal track on this page leads with cash and intake, and why we treat pricing model as part of any legal engagement.

Fewer than 30% of cloud-adopting firms review ethics rules, privacy policies or vendor terms of service before adopting a vendor. Arriving with the documentation package does the diligence most of the market demonstrably skips, for you, and about us.

under 30%ABA 2024 Cloud Computing TechReport. Cloud-adopting firms that review ethics rules, privacy policies or vendor terms of service. Over 93% rate vendor reputation as important; 23% evaluated the vendor's history.

Where anything we build speaks or writes to a human on your behalf, it discloses itself before any substantive exchange, and the disclosure is captured inside the recording. The line we ship:

“You’re speaking with an automated AI assistant. This conversation is recorded and transcribed for quality and training.”

What happens to client data, in full: see our privacy policy. Privacy policy

New York

New York, specifically.

Corveonic is a New York firm, and this page’s three audiences carry New York obligations most national vendors have never read.

Part 500 reaches your agency, even small and “exempt”

A New York-licensed insurance producer is a covered entity under 23 NYCRR §500.1(e). The §500.19(a) limited exemption (fewer than 20 employees and independent contractors, or under $7.5M gross annual revenue in each of the last three fiscal years, or under $15M in year-end total assets) narrows the obligations. It does not remove them.

The catch almost no vendor knows: the Second Amendment struck §500.12 out of the limited-exemption list. Multi-factor authentication now applies to small, otherwise-exempt New York agencies, for remote access to your systems, for third-party cloud applications holding nonpublic information, and for all privileged accounts. That compliance deadline was November 1, 2025, and it has already passed.

The clocks that keep running

Regardless of exemption: 72 hours to notify the superintendent after determining a cybersecurity incident occurred: at the covered entity, an affiliate, or a third-party service provider. That clause covers vendors like us, and our contract says so before this page does. And every April 15: a certification of material compliance, or a written acknowledgment of non-compliance with a remediation timeline, signed by your highest-ranking executive and your CISO, with supporting records kept five years.

SHIELD reaches the other two tracks

The SHIELD Act (NY GBS §899-BB) applies to any entity holding a New York resident’s private information, which is every accounting firm and every law firm in the state, not only producers. It requires administrative, technical and physical safeguards, and it names one that lands on this page: vetting service providers through contracts.

DFS now issues frequent cyber guidance to its industry: third-party risk in October 2025, a vishing advisory in February 2026, a letter on risks associated with frontier AI models in May 2026. This regulator is paying attention. So is anyone building for its licensees.

FAQ

Ten questions, each conceding something real first.

What this costs: monthly retainers run $597 to $1,997 plus a one-time setup fee, and project work is quoted as a range before it starts. ($597–$1,997/moCorveonic pricing, signed off 2026-08-04.)

See what each tier includesOr run your own numbers first

Bring one broken workflow.

A walkthrough, not a pitch. We’ll tell you what’s automatable, what stays human under your rules, and what it would cost, including when the honest answer is that it isn’t worth buying yet.