Your insurance policy covers less than you think it does.
Every cyber insurance policy has a compliance clause. If your club does not have current, documented IT and security policies, your insurer can limit your payout after a breach regardless of your coverage limit. Jonas Compliance closes that gap.
Your insurer sent you a questionnaire.
Do you actually meet it?
Every year, insurance companies send clubs a renewal questionnaire. Do you use MFA? Do you have a remote work policy? Do you follow your own procedures? Most clubs check yes and hope for the best.
When a claim is filed, the insurer checks those answers against what actually happened. If your policies do not support what you said, the payout shrinks, or disappears.
Jonas Compliance reads the questionnaire for you and tells you exactly where you stand.
See how it worksSee exactly where your club stands.
The free basic assessment takes about 10 minutes. Answer a guided set of questions about your club's current environment and receive a graded score by category with a prioritised action list.
Your Jonas representative is notified when you finish. If you stop partway through, they will follow up. The grade tells a clearer story than any conversation.
Sign in with Microsoft or Google
No new account. No new password. Uses credentials your team already has.
Answer 10 minutes of guided questions
About your environment: remote access, backups, staff, vendors. Plain language throughout.
Get your grade and your roadmap
A score by category and a prioritised list of what to address first. Take it to your board, share with your insurer, or use it as your starting point.
Everything your club needs to document, prove, and maintain compliance.
Not a checklist. Not a template library. A working compliance system built around how your operation actually runs.
Digital fire drills for your team
Walk your GM, CFO, and key staff through structured scenarios: ransomware, data breach, system failure. Graded outcomes with NIST-aligned guidance. Your team knows exactly who calls who before something happens, not during it.
Every document in one place, with a full history
Edit policies inline, download as PDF, share with your insurer, or publish to your website. Full version history shows every change, who made it, and when. Invite your managed service provider and they get their own login to answer the sections that fall under their remit.
Most clubs think they are covered. The ones who have done the assessment know exactly where they are not.
What Avalon Yacht Club found when they looked.
- No written policy for seasonal staff device access or offboarding
- Cyber insurance questionnaire had three questions the club could not confirm
- Marina vendor had never been sent a security questionnaire
- ✓ Generated a seasonal staff offboarding policy in under five minutes
- ✓ Uploaded the insurance questionnaire and closed all three gaps automatically
- ✓ Sent their marina vendor a security questionnaire for the first time
“As a smaller club with no ability to have a significant in-house IT team, Jonas Compliance was a game changer for us. It was like paying a Senior Director of IT security for much less than minimum wage, with the confidence that they don’t have a personal investment in saying we are safe without examining any possible deficiencies.”
The questions that come up before a club starts.
These are the ones we hear most from general managers, CFOs, and boards looking at compliance for the first time.
Can our board be held personally liable for a data breach?
When a data breach leads to litigation, boards are often named alongside the club. Directors who cannot show reasonable governance over member data face personal exposure. A documented compliance posture is one of the clearest ways to demonstrate due diligence.
How much member data does our club actually hold?
More than most clubs realise. Credit cards, Social Security numbers from background checks, home addresses, family member names, and medical considerations for dining are all common. Most clubs have no written policy governing how this information is stored, accessed, or disposed of.
Why are seasonal staff a compliance risk?
Summer hires get system access and are often gone by September. Without a written offboarding policy, old credentials can linger. Without a device policy, staff may be logging into club systems from personal phones with no controls in place.
Do we need to worry about our vendors' security, not just our own?
Yes. Your tee time platform, POS system, event software, and payment processor all have some access to your environment. If you have never sent a vendor a security questionnaire, you don't know what their controls look like, and neither does your insurer.
Do we need a policy for AI tools our staff are already using?
Most clubs do not have one yet, and staff are already using AI tools for communications, scheduling, and data entry. Without a written AI use policy, there is no rule for what data can be entered into a public AI tool or how AI-assisted decisions get documented.
We're a small club. Are we really a target?
Yes. Attackers are not targeting clubs based on size. They are after member credit cards and Social Security numbers, and automated tools now probe everyone rather than large organisations specifically.
Why would my insurer pay out less than my policy limit?
Cyber insurance policies include compliance clauses that let insurers reduce payouts if a club cannot show that the required policies and controls were documented and in place at the time of the incident. Clubs with complete, current documentation recover more. Clubs with gaps recover less, sometimes significantly less.
How do we purchase Jonas Compliance?
Your club purchases an annual Jonas Compliance plan through Jonas Software. Contact your Jonas representative, who will confirm pricing for your club and activate your access. Your Jonas contract and your Jonas Compliance plan then renew together, so there is no separate renewal cycle to track.
What does setup involve, and do we need IT?
Setup takes minutes and needs no IT involvement. You sign in with your existing Microsoft or Google account, complete a short setup wizard, and the platform tailors everything to your club from that point on. No new credentials and no new passwords for your team to manage.
What happens at renewal?
Your policies, assessments, and documentation stay in the platform between years. At renewal you review and update anything that has changed at your club, rather than starting from a blank page. Compliance standards are updated in the background throughout the year, so your documentation does not fall behind while you are not looking at it.
Still have a question? Talk to your Jonas representative, or start with the free assessment and see where your club stands first.
An annual plan. Everything included.
Until now, this meant hiring a consultant, paying thousands per day, and starting from scratch every year. Jonas Compliance makes it accessible, affordable, and something you can actually maintain.
The platform your club can trust with the details that matter.
A compliance platform is only useful if clubs can be honest in it. Jonas Compliance was built from the ground up to protect the details clubs share, because the AI is only as useful as the information you give it.
Is anything we enter into the AI stored?
All AI traffic routes through AWS Bedrock to Anthropic. Every token is dropped after the response is returned. Even if the infrastructure were audited, no club data would be found.
Do we need new logins for our team?
Use your existing Microsoft or Google account. No new credentials, no new passwords.
Who actually built the platform?
The platform was developed by professionals holding CISSP, OSCP, OSWE, and OSCE certifications. Not a software team that added compliance as a feature.
How do we keep up when standards change?
NIST, CISA, PCI DSS, and insurance industry standards are updated in Jonas Compliance continuously. Your policies stay current as requirements change, without you having to track any of it.
Ready to close the gap?
Start your annual Jonas Compliance plan today. Sign in with the accounts your team already has, complete a short setup wizard, and have your first policies generated before the end of the week.