SECURITY

The app belongs to
the company.

Not to whoever built it. Every app runs on the same foundation: single sign-on, roles and permissions, a real people directory and one audit trail. Nobody sets up servers, nobody wires permissions, and it all runs on German and EU infrastructure.

Book a demo → Why ownership is the point
CRMAPP SUPPORTAPP HRAPP BILLINGAPP ONE IDENTITY Single sign-on · people, teams, managers ONE PERMISSION MODEL Roles · fine-grained rights · enforced by the platform ONE AUDIT TRAIL Who changed what, in every app, in one place HOSTING Germany · GDPR-first · managed backups and updates FIG.00 — 4 APPS · 1 FOUNDATION
FIG.01

Built by a person. Owned by the company.

Nobody sets up servers or wires permissions. Every app runs on the same foundation: single sign-on, roles and permissions, a real people directory and an audit trail. Hosting, updates and backups are managed, and it runs on German and EU infrastructure.

The important part is ownership. The app belongs to the company, so it does not leave when the person who made it does, and permissions decide who uses it rather than who happens to have the link.

  • OWN Company-owned, with a named successor when people move on
  • AUTH Users, roles and fine-grained permissions
  • LOG One audit trail and one security model
  • EU Hosted in Germany, GDPR-first, with SSO included
Roles & permissionsAcme Ltd
AdminManagerMember
View customers
Edit invoices
Manage people
Install apps
FIG.02

The test is what happens when someone leaves.

This is where employee-built software normally goes wrong, and it has nothing to do with how good the app was. Someone builds a genuinely useful thing. It runs on their account, in their tool, with a login only they remember. They move on, and a working part of the company quietly becomes an archaeology project.

On Cordango, the app was never theirs. It sits in the company tenant with a named owner and a successor, its users come from the company directory, and its audit trail did not live in an account that just got closed. Someone takes it over the same afternoon, without anyone asking who has the password.

The builder leavesTwo foundations
# on a personal ai builder account closed app goes with it data in someone else's project ? who owns it now nobody knows # on cordango app still the company's access revoked with their account owner reassigned, same afternoon
FIG.03

One security model, not one per app.

SEC-01

Identity from the directory

People, teams and managers are the company’s, not a fresh user table per app. Single sign-on means one account to grant and one to revoke. A leaver loses access everywhere at once.

SEC-02

Permissions the platform enforces

Rights are checked underneath every app, on every read and every write. Not implemented per app by whoever built it, which is how an app usually ends up with a gap nobody noticed.

SEC-03

One audit trail

Who changed what, when, across every app, in one place. You do not gather evidence from five tools with five different log formats and three of them missing.

The same model runs everything on top of it: dashboards, cross-app widgets, personal views and the API all answer to it.
Why a personal view can never widen access →

FIG.04

German hosting, and a short answer for procurement.

Cordango is built and hosted in Germany, on EU infrastructure, GDPR-first. Backups, updates and patching are managed, so “who keeps this thing current” is not a question that lands on the person who asked for the app.

The practical effect on a review is that there is one system to assess rather than a growing list of small tools each with their own hosting, their own login and their own data processing agreement. When someone builds a new app, nothing new needs approving. It is the same platform it was last month.

  • DE Built and hosted in Germany, EU infrastructure
  • GDPR One data processing agreement, not one per tool
  • OPS Managed backups, updates and patching
  • SSO Single sign-on included, not an enterprise upsell
What review has to assessPer new app
# a new tool per process + a vendor security review, DPA, hosting + a login another account to offboard + a data copy somewhere new # a new app on cordango nothing new same platform, same review
MORE

The rest of the platform.

NEXT

Let people build.
Keep the control.

See what a generated app inherits before anyone touches it: your directory, your roles, your audit trail.

Book a demo → Privacy & GDPR