Your insurance policy covers less than you think it does.
Every cyber insurance policy has a compliance clause. If your club does not have current, documented IT and security policies, your insurer can limit your payout after a breach regardless of your coverage limit. Jonas Compliance closes that gap.
Private clubs carry more risk than they realise.
You hold member credit cards, home addresses, family details, and event histories. You have vendors accessing your systems, seasonal staff rotating through, and a board that may not know what a compliance gap looks like until a claim is denied.
Board members can be held personally liable
When a data breach leads to litigation, boards are named alongside the club. Directors who cannot demonstrate reasonable governance over member data face personal exposure. A documented compliance posture is one of the clearest ways to show due diligence.
Governance riskYou hold more member data than you think
Credit cards. Social Security numbers for background checks. Home addresses. Family member names. Medical considerations for dining. Private clubs are sitting on a significant amount of personal information, and most have no written policy governing how it is stored, accessed, or disposed of.
Member data exposureSeasonal staff are your biggest vulnerability
Summer hires get system access and are gone by September. Without a written offboarding policy, old credentials linger. Without a device policy, staff are logging into club systems from personal phones with no security controls. Most clubs have never documented either.
Access control gapEvery vendor integration is an open door
Your tee time platform, POS system, event software, and payment processor all have access to some part of your environment. If you have never sent a vendor a security questionnaire, you do not know what their controls look like. Neither does your insurer.
Vendor chain riskAI is already in your club. Governed or not.
Staff are using AI tools for communications, scheduling, and data entry. Without a written AI use policy, there is no rule about what data can be pasted into a public AI tool, who is responsible when something goes wrong, or how decisions made with AI assistance get documented.
AI governance gap"We're too small to be a target"
Attackers are not here for millions in the bank. They are after member credit cards, Social Security numbers from background checks, and a network to use as a jumping-off point. With AI automating attacks, there is no reason to target large organisations specifically. The instruction is simply to probe everyone and come back with victims.
Size is not protectionYour $2 million policy might pay out $200,000.
Cyber insurance policies include compliance clauses that allow insurers to reduce payouts if your club cannot demonstrate that security controls were in place at the time of an incident.
The difference between your coverage limit and your actual payout is determined by how well your policies are documented and current. Clubs with complete, up-to-date policies recover more. Clubs with gaps recover less, sometimes significantly less.
Jonas Compliance costs a fraction of what a single day of custom policy work would run. It is cheap insurance on your insurance.
Your insurer sent you a questionnaire.
Do you actually meet it?
Every year, insurance companies send clubs a renewal questionnaire. Do you use MFA? Do you have a remote work policy? Do you follow your own procedures? Most clubs check yes and hope for the best.
When a claim is filed, the insurer checks those answers against what actually happened. If your policies do not support what you said, the payout shrinks, or disappears.
Jonas Compliance reads the questionnaire for you and tells you exactly where you stand.
See how it worksSee exactly where your club stands.
The free basic assessment takes about 10 minutes. Answer a guided set of questions about your club's current environment and receive a graded score by category with a prioritised action list.
Your Jonas representative is notified when you finish. If you stop partway through, they will follow up. The grade tells a clearer story than any conversation.
Sign in with Microsoft or Google
No new account. No new password. Uses credentials your team already has.
Answer 10 minutes of guided questions
About your environment: remote access, backups, staff, vendors. Plain language throughout.
Get your grade and your roadmap
A score by category and a prioritised list of what to address first. Take it to your board, share with your insurer, or use it as your starting point.
Everything your club needs to document, prove, and maintain compliance.
Not a checklist. Not a template library. A working compliance system built around how your operation actually runs.
Digital fire drills for your team
Walk your GM, CFO, and key staff through structured scenarios: ransomware, data breach, system failure. Graded outcomes with NIST-aligned guidance. Your team knows exactly who calls who before something happens, not during it.
Every document in one place, with a full history
Edit policies inline, download as PDF, share with your insurer, or publish to your website. Full version history shows every change, who made it, and when. Invite your managed service provider and they get their own login to answer the sections that fall under their remit.
Most clubs think they are covered. The ones who have done the assessment know exactly where they are not.
What Avalon Yacht Club found when they looked.
- No written policy for seasonal staff device access or offboarding
- Cyber insurance questionnaire had three questions the club could not confirm
- Marina vendor had never been sent a security questionnaire
- ✓ Generated a seasonal staff offboarding policy in under five minutes
- ✓ Uploaded the insurance questionnaire and closed all three gaps automatically
- ✓ Sent their marina vendor a security questionnaire for the first time
“As a smaller club with no ability to have a significant in-house IT team, Jonas Compliance was a game changer for us. It was like paying a Senior Director of IT security for much less than minimum wage, with the confidence that they don’t have a personal investment in saying we are safe without examining any possible deficiencies.”
An annual plan. Everything included.
Until now, this meant hiring a consultant, paying thousands per day, and starting from scratch every year. Jonas Compliance makes it accessible, affordable, and something you can actually maintain.
The platform your club can trust with the details that matter.
A compliance platform is only useful if clubs can be honest in it. Jonas Compliance was built from the ground up to protect the details clubs share, because the AI is only as useful as the information you give it.
Nothing is logged, nothing is stored
All AI traffic routes through AWS Bedrock to Anthropic. Every token is dropped after the response is returned. Even if the infrastructure were audited, no club data would be found.
Sign in with what you already have
Use your existing Microsoft or Google account. No new credentials, no new passwords.
Built by certified cybersecurity professionals
The platform was developed by professionals holding CISSP, OSCP, OSWE, and OSCE certifications. Not a software team that added compliance as a feature.
Standards that stay current without your effort
NIST, CISA, PCI DSS, and insurance industry standards are updated in Jonas Compliance continuously. Your policies stay current as requirements change, without you having to track any of it.
Ready to close the gap?
Start your annual Jonas Compliance plan today. Sign in with the accounts your team already has, complete a short setup wizard, and have your first policies generated before the end of the week.