Overview

The usecure integration syncs your organization’s Human Risk Management (HRM) data from usecure: training courses and per-learner course results (uLearn), phishing simulation campaigns and results (uPhish), policy documents and signatures (uPolicy), dark web credential exposures (uBreach), and human risk scores. LowerPlane connects via the usecure GraphQL API and only ever reads data — it never enrols learners, sends simulations, or changes policies.

Prerequisites

usecure’s public API is invite only. You must request an API key from usecure support or your account manager before connecting.

How to Get Your API Key and URL

1

Request API access

Contact usecure support or your account manager and ask them to enable public API access for your tenant. They will issue your API Key.
Ask for the API Key, not the Client API Key — the queries LowerPlane runs require the former.
2

Identify your regional endpoint

usecure serves the API from one host per region. Use the one matching your tenant:
RegionAPI URL
UShttps://public-api.us.usecure.io
EU (current)https://public-api.eu.usecure.io
EU (legacy)https://public-api.usecure.io
LowerPlane appends /graphql automatically, so either form works.
3

Store the key securely

The API key grants read access to all learner data in your tenant. Store it securely and rotate it if exposed.

Connecting in LowerPlane

  1. Go to Settings > Integrations in LowerPlane
  2. Find usecure under Training
  3. Enter your API Key and your regional API URL
  4. Click Connect
LowerPlane validates the credentials, seeds the usecure tests, and begins syncing. Defaults to https://public-api.us.usecure.io when no API URL is given.

What LowerPlane Collects

uLearn Course Catalog

Every course with its subject, category and difficulty.

uLearn Learner Results

Per-learner, per-course enrol / start / finish dates, scores and grades — mirrored into LowerPlane training assignments.

uPhish Simulations

Campaigns with recipients, sends, opens, visits, compromises and reports, plus per-learner outcomes.

uPolicy Documents

Policies with publication state, version, owner and per-learner signature results.

uBreach Exposure

Breached services per monitored domain, the data classes exposed, and whether each exposure is resolved.

Human Risk Scores

Per-learner risk levels and the company risk score history.

Account Configuration

Which modules (uLearn, uPhish, uPolicy, uBreach) are enabled, plus domain lock and monitored domains.

Platform Administrators

The usecure admin roster, recorded as critical-system access for access reviews.

Automated Tests

Connecting usecure seeds two automated tests:
TestScopePasses when
Learner should complete assigned security trainingPer learnerEvery course the learner is enrolled in has a finish date
Learner should sign all assigned policiesPer learnerEvery assigned uPolicy document is signed
Deliberately narrow, mirroring what Drata ships for KnowBe4. uPhish, uPolicy, uBreach and risk scoring are still collected in full — they appear as evidence and raise findings, they just carry no separate test. Extra tests covering the same control add dashboard noise without adding assurance.
A course counts as complete only when usecure reports a finish date — enrolment alone is not completion. A learner enrolled in nothing fails the check, since an untrained employee is exactly the gap the control exists to surface. Repeated attempts at the same course collapse to one, so a learner who abandoned a course and later passed it counts as complete.

Compliance Mapping

FrameworkControlsWhat It Proves
SOC 2CC1.4, CC2.2, CC5.3, CC7.2Security awareness training, policy communication and threat response
ISO 27001:2022A.6.3, A.5.1, A.5.7Awareness and training, information security policies, threat intelligence
HIPAA§164.308(a)(5)(i)Security awareness and training program
PCI-DSS12.6Formal security awareness program for personnel
GDPRArt. 39(1)(b)Data protection training and staff awareness
NIST CSFPR.AT-1, PR.AT-2Personnel training on cyber risks and threat simulation

Automated Findings

Alongside the tests, each sync raises findings for:
  • High phishing click rate — overall compromise rate across campaigns exceeds 15%
  • Unresolved dark web exposures — uBreach reports credentials still exposed on a monitored domain

FAQ

LowerPlane matches usecure learners to people in your directory by email address, case-insensitively. Each uSecure course a learner is enrolled in becomes its own LowerPlane training course, with one assignment per learner carrying that course’s real status, score and finish date — completed when usecure reports a finish date, otherwise in-progress with no completion date. A learner with no matching person is not shown, since an assignment must belong to someone in your directory.
Each module is licensed separately. When one is unavailable, the worker automatically retries with a reduced query so the rest of the sync continues — you simply get less evidence, and the two tests are unaffected unless uLearn or uPolicy itself is off.
Because that learner has not received security awareness training at all. Treating an empty course list as a pass would hide the most serious version of the gap. Enrol them on your mandatory programme in uLearn and the test passes on the next sync.
Data syncs daily by default. You can also trigger an on-demand sync anytime from the integration card in LowerPlane.