Practice management for Canadian law firms

Built around the trust ledger.

Matters, time, billing and trust accounting — built so the ledger is defensible on the day somebody asks to see it.

Where it runs
Available to firms across Canada. Hosted in Canadian regions.
Trust profiles
Ontario (LSO) and Québec (Barreau), resolved per trust account rather than per firm.
Languages
English and French throughout — money and date formats, not only labels.
A firm holds two kinds of money. Confusing them is professional misconduct, not a bug.

Operating money is the firm’s. Trust money is the client’s. Every list, every balance, every form and every receipt has to make which is which impossible to get wrong.

Two sheets of ruled ledger paper laid side by side, divided by a hard shadowed gap.

The treatment

Trust money never relies on colour.

A doubled edge, a hatched field and a TRUST · FIDUCIE label, everywhere it appears. Three signals, so the distinction survives a photocopy.

Beaulieu v. NadeauFees invoiced · bill 2026-0418
$4,120.00
Operating
Beaulieu v. NadeauRetainer held for the client Trust · Fiducie
$12,500.00
Trust

Greyscale is not an accessibility afterthought here. It is the test the treatment was designed against — it has to hold across a desk, on a printout, and for a colourblind reader.

A client’s balance cannot go negative.

Not per pooled account — per client, per matter. The rule lives in the ledger itself, so it is not a warning that can be dismissed, a setting that can be switched off, or a check that a future change could quietly skip.

The rule, as the ledger holds it

No matter’s trust balance may ever fall below zero. A withdrawal that would breach it is refused before it is written.

Held per matter rather than per client, which is stricter than the regulation asks: if every matter is whole, every client is. Two disbursements raised at the same moment are settled in order rather than against the same stale figure, so the second one sees the first.

Electronic trust transfers need two people.

Requisition, authorisation, execution. The person who authorises can never be the person who requisitioned — the ledger refuses it outright, rather than trusting a policy.

  1. Requisition

    Someone raises the transfer: the client, the matter, the amount, the reason and an expiry.

  2. Authorisation

    A second person authorises it. If the two are the same person, it does not proceed.

  3. Execution

    Only then does the money move, and the record keeps who did each of the three acts.

pendingauthorisedexecutedcancelledlapsed

Required by LSO By-Law 9, s. 12.

Days remaining in the current 25-day reconciliation window
—
days

Reconciliation is a legal deadline.

Trust reconciliation is due within 25 days of month end, and cannot be completed while any unexplained difference remains. RYVO counts the days.

on timedue soonoverdue

The dial runs on your own clock against the real rule — it is the deadline, not a firm’s data.

Then it has to be faster than resenting it.

Ten to thirty time entries a day, and every one of them resented. The whole design question is how few seconds each one is allowed to cost.

Manual entry is built for a lawyer typing six entries in a row at five o’clock without touching the mouse.

Nobody records time while the work is happening.

So there are two ways in, and they are built to agree with each other. A timer, for work you are inside. A grid, for the day you are rebuilding from memory at five o’clock.

Several at once, and still there tomorrow

Start a timer from anywhere without leaving the page. Run as many as the day demands, because interruptions do not queue. Pausing banks the time instead of restarting it, and closing the tab does not end the clock — they are still counting when you come back.

A timer belongs to the day it began

One left running past midnight is recorded against the morning it started, not the small hours it was stopped in. The date is stamped once, at the start, and never worked out again afterwards.

It hands the time back rather than losing it

Stopped under a minute, it records nothing instead of inventing a minute. Naming no matter, it says so instead of disappearing. Every reason a timer cannot become an entry is put on the screen: a stop button that quietly drops twenty minutes of an afternoon is the failure nobody notices until the bill goes out short.

And the same hour cannot be billed twice

If time is already on the clock for that matter on that day, the grid says so before it saves. When a date falls outside the two weeks the screen is holding, it says the check did not run — rather than letting silence imply that it passed.

Catch-up gridKeyboard first
The shape of the catch-up grid: its columns, a running timer shown inline, and the three ways a duration may be typed.
DateMatterDescriptionDurationBillableValue
Mon Running timer 0:41
Mon 1.2
Mon 1:12
Tue 72m
Tab moves Enter adds a row ⌥↑ copies the row above 1.2 · 1:12 · 72m

Running timers appear in the grid, marked, so the hour already on the clock is not keyed a second time underneath it. A duration is read however a lawyer types it. An hour budget on the file warns; it does not refuse.

A rate that appears without its reasoning is a dispute waiting to happen.

Six levels, highest first. The product walks them and stops at the first that has a value. Every level stays on the screen, including the empty ones — hiding them would make the list look like the answer rather than the reasoning.

Where this rate came fromPress a row to set or clear it

WinsMatter rate

The shape of the walk, not a firm’s figures. No amounts, because the dispute is never about the number that appeared — it is about which level produced it.

Nothing is still a fee

A flat fee of nothing is set. It does not fall through to the next level, because treating zero as absent would bill a file that was meant to be included.

A typed rate stays put

A rate written on the entry survives a change of matter or of activity. Replacing it quietly would lose the figure the lawyer meant, and the next bill would carry a number nobody chose.

No rate does not become zero

If every level is empty, the entry has no rate. It is refused, not defaulted. Inventing a number so the row can save is how a bill goes out at the wrong figure.

Work becomes a bill, and the bill closes behind it.

Tick the unbilled work and it becomes bills — one for each matter, with any discount taken off before tax, because the tax follows the charge. From there the bill moves through five states, and what you may still change shrinks at every one.

01 draft 02 pending approval 03 approved 04 paid void, from anywhere before payment
What is still editable, by state.
Field Draft Pending Approved Paid Void
Line items editable editable closed closed closed
Dates editable editable closed closed closed
Discount editable editable closed closed closed
Note on the bill editable editable editable closed closed
Invoice number editable until the bill is first issued closed closed closed closed
Editable Editable until the bill is first issued Closed

Where a field is closed, the screen names the one move that would open it again — remove the payment, remove the approval, return it to draft — and names nothing at all when no move would. An explanation that offers a remedy which does not work is worse than no explanation.

The number is set once

A bill takes its number the first time it leaves draft, and keeps it — even if it goes back to draft and comes forward again. That is audit practice rather than a rule of the profession, and it is here as prudence, not as law.

Trust cannot pay a bill the client has not seen

Money held for a client settles the firm’s fees only once the billing has been delivered to them. Generated is not delivered; approved is not delivered.

Undoing happens on the record

Voiding leaves the bill in place with a void stamp, returns its work to unbilled, and does not reuse the number. Removing a payment is for a keying error only — no money moves, and it stays on file marked reversed. A credit note reverses the billing without touching the bill it came from.

The reminder is the invoice, again

Offsets live on the firm, or on the contact. When a due date is that many days away, the same invoice goes out with a fresh one-day portal link. A skip is logged. It does not invent a second letter.

Six reports, and not one of them fills in a blank.

Live figures for the firm, over the range you choose. An empty range stays empty — nothing is smoothed, carried forward or estimated so that a page looks finished.

Receivables, by age

What is owed · as at a date

Current
1–30
31–60
61–90
Over 90

Approved bills that still carry a balance, by days past due. Currencies are kept apart rather than converted at a rate nobody agreed to.

Issued, and collected

Revenue · over a range

Issued
Collected

Two different questions, kept apart. What the firm billed in the period, and what actually arrived in it — a single revenue figure quietly merges them.

The shape of each sheet, not a firm’s figures.

Who is producing

Productivity by person: the billable minutes recorded, and how much of that was actually billed. Task productivity sits beside it. A lawyer opening the same report sees their own row and nobody else’s — the narrowing happens where the figures are read, not in the page that displays them.

The owner’s view

Alongside those: a client’s ledger, the balance on every matter, and receivables against revenue. The list of reports is built from the role, so a report someone may not run is not on their screen to be asked about.

Firm ownerall six
Bookkeeperall six
Lawyerthe two on production
Clerknone

Every report leaves as Excel or PDF, for exactly the range on the screen.

A template, a document, a signature, and a record of it.

The vault holds the firm’s paper — filed against a matter, newest first, each filename kept exactly as the person who uploaded it wrote it.

Filing

Choose the matter, then drop the file anywhere on the page. PDF, Word, text or an image, up to 25 MB. A refusal says which of those it failed and files nothing at all — a half-uploaded document is not a document, and nothing is ever left looking filed when it is not.

Templates that keep their versions

A Word file with merge fields in it, filled from the matter at the moment you generate. Each template keeps its versions, so revising the retainer next month does not change what a client signed last month. Archiving one stops it appearing when generating and deletes nothing.

Refused before, not after

Generating checks every field first and lists what it cannot fill: one this matter has no value for, one that is not a field at all, and two custom fields sharing a name — because nothing can tell which of the two you meant, and guessing would put the wrong name in a retainer.

Sharing is a decision somebody makes

A document in the vault is not visible to the client until someone marks it visible. There is no default that shares.

The template

A Word file carrying {{client.display_name}} {{matter.display_number}} and your firm’s own fields. Add {{signature}} and the document it produces carries a signature box.

The document

Generated against one matter and filed straight into the vault, with every field resolved before a single page was written.

The signature

Sent to a contact on the matter who has an email address. They type their name or draw it — or decline, with a reason that comes back to the firm. The link is good for fourteen days.

Signature · Signature

awaiting signatureopenedsigneddeclinedexpired

The certificate

The document as it was sent
fingerprint
The document as it was signed
fingerprint
Which version of the template
recorded
Sent, opened, signed
timestamped
The signer’s address
not kept
The signer’s browser
not kept

Two content fingerprints are the whole basis of the claim, and neither the address nor the browser strengthens it. Both are personal information about someone who never offered it, so neither is kept. The certificate is the firm’s, and it needs a session to download — the signing link cannot hand it out.

The client sees two things. Nothing else is on that side.

No account to create, no password to reset, no invitation to look around. A link that works once and lasts a day.

What the client opens

The portal

Outstanding invoices
Documents shared with them

Approved bills that still carry a balance — issued, due, total, owing, and the invoice itself — and the documents someone at the firm marked visible.

What stays with the firm

Never on that page

  • The matter file
  • Time entries, and what they say
  • The trust ledger
  • Matters nobody shared
  • Every other client

Not hidden behind a setting that could be switched off. Those reads are tied to the one client the link belongs to, and there is no screen on that side that asks for anything else.

The link is single-use and lasts twenty-four hours; sending a new one cancels the last. A session left alone closes after twelve. Paying the bill from that page is still to come — today the portal shows what is owed and hands over the invoice.

Everything hangs off the matter.

Time, trust, documents, the calendar and the tasks are not five products. They are five views of one file, so a balance and a deadline are never sitting in two different tools.

Trust · Fiducie Held on this file, not in a pooled total

The matter file

Open date, limitation date, practice area, and a stage that belongs to that area. Move it to a stage from another area and the file refuses the move.

Time

Every entry, timer and rate on this file. Billed work stays on it, readable, and cannot be edited.

Calendar

Events linked to the file, with recurrence. An edit asks this occurrence or the whole series. The firm’s holidays sit beside them.

Tasks

Lists that belong to the file, not a personal board that forgets which matter they were for.

Contacts

On the file. A client, a counsel, a court — people the matter needs, not a separate address book.

Documents

The vault for this file: templates, the record, the signature, the certificate.

Leads

Before it is a matter, it is a lead. The same book, one step earlier.

Everything in it

The whole day, not a module.

A practice runs on one book, not seven tools that each hold a piece of it. This is the index of that book.

01

The matter file

  • Matters and stages
  • Contacts
  • Calendar, with recurrence and holidays
  • Tasks and task lists
  • Leads
  • A document vault
  • Templates with merge fields
  • Electronic signing
02

Money and trust

  • Timers and the catch-up grid
  • Six-level rate resolution
  • Unbilled work
  • Bills, payments and credit notes
  • Trust ledgers, per client
  • Disbursements
  • Electronic transfers
  • Monthly reconciliation
03

Firm and client

  • A client portal
  • Six live reports
  • An immutable audit log
  • Access by role
  • English and French, throughout
  • Ontario and Québec profiles
  • Sessions close after thirty idle minutes
  • Hosted in Canadian regions
Marked entries carry the trust treatment throughout.

Where the record goes next

The next parts of the same book.

These capabilities extend records RYVO already keeps. Each is planned work, described here before it is released.

Payments

The invoice should be able to finish the job.

A client who opens an invoice should not have to call the firm, ask where to send the money, or copy banking instructions into another screen. The amount owing and the way to settle it belong together.

Pay from the invoice

An issued invoice carries its balance into the client portal. When card payment is enabled, the client can settle that balance from the same page they used to read the bill. The payment belongs to that invoice from the beginning — it is not an unidentified deposit somebody has to match afterwards.

A payment does not quietly rewrite the bill

The invoice remains the invoice. Payment records what was received against it, when it was received, and what balance remains. A partial payment leaves the remainder owing. A completed payment closes the balance. The history remains readable either way.

Trust and operating money still stay apart

Paying an invoice is a payment to the firm. It does not become trust money merely because the same client also has funds held in trust. The distinction RYVO makes everywhere else continues through the payment flow.

Card payment processing is not currently available.

Calendar

The matter calendar should not require a second calendar to remember it.

RYVO already knows the hearing, meeting, limitation date and task that belong to the file. Calendar sync lets those events appear where the people working the file already look for their day.

RYVO remains the record

An event belongs to its matter in RYVO. Sync sends that event outward instead of requiring somebody to create the same event twice. Matter context stays with the file even when the appointment also appears on an external calendar.

Google first. Microsoft next.

The first connection will push RYVO calendar events to Google Calendar, followed by Microsoft 365. The objective is deliberately narrow: remove duplicate entry without turning two calendars into competing systems of record.

A changed deadline should not leave the old one behind

Dates move. Meetings are cancelled. Recurring events change. Synchronization has to carry those changes through rather than leaving an obsolete appointment on somebody’s calendar looking current.

External calendar synchronization is not currently available.

Communications

The conversation belongs to the file too.

A matter can have every document properly filed and still have half its history sitting in somebody’s inbox or telephone. RYVO’s communications layer is intended to bring those exchanges back beside the matter they concern.

An address for the firm

Each firm receives an inbound email path into RYVO so correspondence can become part of the practice record instead of living only inside an individual mailbox. The objective is not to replace email. It is to stop the file from depending on one person’s inbox.

Messages against the matter

Email received for a file can be associated with the relevant matter, alongside its contacts, tasks and documents. The correspondence becomes something the firm can find from the file rather than something someone has to remember how to search for.

SMS without losing the thread

Client SMS will sit inside the same communication history. Appointments, requests for documents and short client exchanges may happen by text; the record should not disappear simply because the conversation used a telephone number instead of an email address.

Inbound email and SMS are not currently available.

Trust controls

Two people approve the transfer. The person executing it should still prove it is them.

RYVO already separates requisition from authorisation for an electronic trust transfer. A second authentication factor adds another control at the point where an authorised instruction becomes an actual disbursement.

Approval and authentication answer different questions

Dual authorisation asks whether two different people agreed that the transfer should happen. A second factor asks whether the person now acting is actually the person whose authenticated session says they are. One does not replace the other.

Put the extra friction where the money moves

A second factor on every routine action would teach people to resent it. A second factor immediately before a trust disbursement protects the action where an additional check is worth the interruption.

The event stays on the record

The transfer record should continue to show the requisition, the authorisation and the execution as separate acts. The additional authentication protects execution without erasing that chain.

Second-factor verification for trust disbursements is not currently available.

Intake

Before it becomes a matter, it should already have a record.

A prospective client usually arrives before there is a file: through a website form, a telephone call or a referral. Public intake gives that work somewhere structured to begin.

A form without an account

A prospective client can submit information through a public form without first becoming a user of the firm’s software. The firm decides what it needs to ask. The response enters RYVO as intake information rather than arriving as another unstructured email.

A pipeline before the file opens

New enquiries move through an intake pipeline while the firm decides whether to accept them. The lead can carry the people involved, the subject of the enquiry, notes and follow-up before a matter number exists.

Accepted means carried forward, not typed again

When the firm accepts the work, the information already gathered should become the beginning of the matter. Opening the file should not mean re-keying the same client and the same facts into a different module.

Public intake forms and the intake pipeline are not currently available.

Electronic billing

Some clients do not want an invoice. They want the invoice in their language.

Insurers, corporate legal departments and institutional clients may require legal bills in LEDES rather than only as a PDF. RYVO will be able to take the billing already recorded on the matter and produce the electronic billing file from it.

The export comes from the bill

Time, rates, people, activities and charges should not be reconstructed in a spreadsheet after billing is complete. The electronic billing export is derived from the same underlying bill the firm approved.

A machine-readable bill is still a bill

Producing LEDES should not create a second version of the financial record. The export is another representation of the approved billing — not another place where the amounts can quietly diverge.

Refuse what cannot be represented

Where required billing information is missing, the better result is an explicit failure than a syntactically valid file carrying invented data. RYVO should identify what prevents the export so the underlying record can be corrected.

LEDES electronic billing export is not currently available.

Receivables

An overdue balance should not require a spreadsheet beside it.

Where the firm’s terms permit interest or late charges, RYVO will calculate them against overdue invoices according to the firm’s configured rules.

The rule comes before the charge

The firm defines how the charge applies. The system then uses that rule consistently rather than asking somebody to calculate it manually each time an invoice becomes overdue.

Show the reasoning

A client should be able to understand why an amount changed. The invoice history should distinguish the original billing from any subsequent interest or late charge and show the dates and basis used to arrive at it.

Nothing retroactive by accident

Changing a firm’s rule later should not silently rewrite the history of charges that were already applied. The record of what happened at the time remains the record.

Interest and late-fee handling is not currently available.

Reporting

The seventh report should not require a developer.

The six built-in reports answer the questions nearly every firm asks. They cannot anticipate every question a particular firm will ask next. The report builder is for that next question.

Start with a named dataset

A report begins from a defined set of RYVO data rather than an unrestricted query against the database. The fields available, their meaning and the relationships between them remain controlled by the product.

Choose the view

Select the fields, filters, grouping, date range and ordering needed for the question. Save the result as a named report so the same question does not have to be rebuilt next month.

Access still follows the person

A custom report does not become a way around RYVO’s permissions. The person running it can only report on information their role is already entitled to read.

Take the result with you

Saved report views should retain the same export principle as the built-in reports: the data on screen can leave as Excel or PDF for the range being viewed.

The custom report builder is not currently available.

Identity

A name on a file is not proof of who is behind it.

Canadian legal work can require a firm to identify and, in applicable circumstances, verify the people and organizations it acts for. RYVO’s identity checks are intended to make that process part of the client and matter record rather than a separate checklist sitting somewhere else.

People and organizations are different checks

An individual and a corporation do not establish identity in the same way. RYVO will distinguish the subject being checked and collect the information appropriate to that subject rather than forcing both through one generic form.

The result belongs beside the client

An identity check is attached to the person or organization it concerns and can be referenced from the matters involving them. The firm should be able to see that a check occurred, its status and when it was completed without searching another system.

Keep evidence deliberately

Identity information is sensitive information. The product should retain what the firm’s compliance record requires, with controlled access and an audit trail, rather than accumulating identity data simply because it can.

A failed check is a result

An inconclusive or failed verification must remain visible as such. RYVO should never turn the absence of a successful result into a green checkmark merely to let the workflow continue.

Identity verification for people and organizations is not currently available.

Who it is for

Four people, one book.

A firm of two or a firm of fifty. The lawyer and the bookkeeper want opposite things from the same screen, and averaging them makes something mediocre for both — so they are designed for separately.

01

The lawyer

Opens the matter, records the time, works the file. The product’s highest-traffic surface is the one that costs them the fewest seconds.

Time · matters · documents · calendar

02

The clerk

Keeps the file moving — contacts, tasks, deadlines, documents out and signatures back.

Tasks · contacts · templates · signing

03

The bookkeeper

Carries the regulatory risk. Bills, reconciles, and answers for the trust account when somebody asks.

Billing · trust · reconciliation · reports

04

The owner

Wants the number, not the spreadsheet. Realisation, receivables, and who is producing.

Reports · dashboard · receivables

See it against your books.

A walkthrough with your own trust structure, your jurisdictions and your reconciliation month. Thirty minutes, with someone who has read the rules.

No account required. Not a per-user licence — a walkthrough against your books is how it starts.