Overview
The usecure integration syncs your organization’s Human Risk Management (HRM) data from usecure: training courses and per-learner course results (uLearn), phishing simulation campaigns and results (uPhish), policy documents and signatures (uPolicy), dark web credential exposures (uBreach), and human risk scores. LowerPlane connects via the usecure GraphQL API and only ever reads data — it never enrols learners, sends simulations, or changes policies.Prerequisites
How to Get Your API Key and URL
Request API access
Contact usecure support or your account manager and ask them to enable public API access for your tenant. They will issue your API Key.
Ask for the API Key, not the Client API Key — the queries LowerPlane runs require the former.
Identify your regional endpoint
usecure serves the API from one host per region. Use the one matching your tenant:
LowerPlane appends
| Region | API URL |
|---|---|
| US | https://public-api.us.usecure.io |
| EU (current) | https://public-api.eu.usecure.io |
| EU (legacy) | https://public-api.usecure.io |
/graphql automatically, so either form works.Connecting in LowerPlane
- Go to Settings > Integrations in LowerPlane
- Find usecure under Training
- Enter your API Key and your regional API URL
- Click Connect
https://public-api.us.usecure.io when no API URL is given.
What LowerPlane Collects
uLearn Course Catalog
Every course with its subject, category and difficulty.
uLearn Learner Results
Per-learner, per-course enrol / start / finish dates, scores and grades — mirrored into LowerPlane training assignments.
uPhish Simulations
Campaigns with recipients, sends, opens, visits, compromises and reports, plus per-learner outcomes.
uPolicy Documents
Policies with publication state, version, owner and per-learner signature results.
uBreach Exposure
Breached services per monitored domain, the data classes exposed, and whether each exposure is resolved.
Human Risk Scores
Per-learner risk levels and the company risk score history.
Account Configuration
Which modules (uLearn, uPhish, uPolicy, uBreach) are enabled, plus domain lock and monitored domains.
Platform Administrators
The usecure admin roster, recorded as critical-system access for access reviews.
Automated Tests
Connecting usecure seeds two automated tests:| Test | Scope | Passes when |
|---|---|---|
| Learner should complete assigned security training | Per learner | Every course the learner is enrolled in has a finish date |
| Learner should sign all assigned policies | Per learner | Every assigned uPolicy document is signed |
Deliberately narrow, mirroring what Drata ships for KnowBe4. uPhish, uPolicy,
uBreach and risk scoring are still collected in full — they appear as evidence
and raise findings, they just carry no separate test. Extra tests covering the
same control add dashboard noise without adding assurance.
A course counts as complete only when usecure reports a finish date — enrolment alone is not completion. A learner enrolled in nothing fails the check, since an untrained employee is exactly the gap the control exists to surface. Repeated attempts at the same course collapse to one, so a learner who abandoned a course and later passed it counts as complete.
Compliance Mapping
| Framework | Controls | What It Proves |
|---|---|---|
| SOC 2 | CC1.4, CC2.2, CC5.3, CC7.2 | Security awareness training, policy communication and threat response |
| ISO 27001:2022 | A.6.3, A.5.1, A.5.7 | Awareness and training, information security policies, threat intelligence |
| HIPAA | §164.308(a)(5)(i) | Security awareness and training program |
| PCI-DSS | 12.6 | Formal security awareness program for personnel |
| GDPR | Art. 39(1)(b) | Data protection training and staff awareness |
| NIST CSF | PR.AT-1, PR.AT-2 | Personnel training on cyber risks and threat simulation |
Automated Findings
Alongside the tests, each sync raises findings for:- High phishing click rate — overall compromise rate across campaigns exceeds 15%
- Unresolved dark web exposures — uBreach reports credentials still exposed on a monitored domain
FAQ
How are training completions matched to employees?
How are training completions matched to employees?
LowerPlane matches usecure learners to people in your directory by email address, case-insensitively. Each uSecure course a learner is enrolled in becomes its own LowerPlane training course, with one assignment per learner carrying that course’s real status, score and finish date —
completed when usecure reports a finish date, otherwise in-progress with no completion date. A learner with no matching person is not shown, since an assignment must belong to someone in your directory.What happens if uPhish, uPolicy, uBreach or risk scoring is not on our plan?
What happens if uPhish, uPolicy, uBreach or risk scoring is not on our plan?
Each module is licensed separately. When one is unavailable, the worker automatically retries with a reduced query so the rest of the sync continues — you simply get less evidence, and the two tests are unaffected unless uLearn or uPolicy itself is off.
Why does a learner with no courses fail the training test?
Why does a learner with no courses fail the training test?
Because that learner has not received security awareness training at all. Treating an empty course list as a pass would hide the most serious version of the gap. Enrol them on your mandatory programme in uLearn and the test passes on the next sync.
How often does data sync from usecure?
How often does data sync from usecure?
Data syncs daily by default. You can also trigger an on-demand sync anytime from the integration card in LowerPlane.