# Security and permissions: identity, audit trail and German hosting

> Every Cordango app runs on the same foundation: single sign-on, roles and fine-grained permissions, a real people directory and one audit trail. Apps belong to the company rather than to whoever built them, and everything is hosted in Germany under GDPR.

Source: https://www.cordango.com/security/
Language: en

SECURITY

# The app belongs to the company.

Not to whoever built it. Every app runs on the same foundation: single sign-on, roles and permissions, a real people directory and one audit trail. Nobody sets up servers, nobody wires permissions, and it all runs on German and EU infrastructure.

[Book a demo →](https://www.cordango.com/contact/) [Why ownership is the point](https://www.cordango.com/security/#ownership)

## Built by a person. Owned by the company.

Nobody sets up servers or wires permissions. Every app runs on the same foundation: single sign-on, roles and permissions, a real people directory and an audit trail. Hosting, updates and backups are managed, and it runs on German and EU infrastructure.

The important part is ownership. The app belongs to the company, so it does not leave when the person who made it does, and permissions decide who uses it rather than who happens to have the link.

-   OWN Company-owned, with a named successor when people move on
-   AUTH Users, roles and fine-grained permissions
-   LOG One audit trail and one security model
-   EU Hosted in Germany, GDPR-first, with SSO included

Roles & permissions Acme Ltd

|     | Admin | Manager | Member |
| --- | --- | --- | --- |
| View customers | ✓   | ✓   | ✓   |
| Edit invoices | ✓   | ✓   | −   |
| Manage people | ✓   | −   | −   |
| Install apps | ✓   | −   | −   |

## The test is what happens when someone leaves.

This is where employee-built software normally goes wrong, and it has nothing to do with how good the app was. Someone builds a genuinely useful thing. It runs on their account, in their tool, with a login only they remember. They move on, and a working part of the company quietly becomes an archaeology project.

On Cordango, the app was never theirs. It sits in the company tenant with a named owner and a successor, its users come from the company directory, and its audit trail did not live in an account that just got closed. Someone takes it over the same afternoon, without anyone asking who has the password.

The builder leaves Two foundations

\# on a personal ai builder ✗ account closed app goes with it ✗ data in someone else's project ? who owns it now nobody knows \# on cordango ✔ app still the company's ✔ access revoked with their account ✔ owner reassigned, same afternoon

## One security model, not one per app.

SEC-01 

### Identity from the directory

People, teams and managers are the company’s, not a fresh user table per app. Single sign-on means one account to grant and one to revoke. A leaver loses access everywhere at once.

SEC-02 

### Permissions the platform enforces

Rights are checked underneath every app, on every read and every write. Not implemented per app by whoever built it, which is how an app usually ends up with a gap nobody noticed.

SEC-03 

### One audit trail

Who changed what, when, across every app, in one place. You do not gather evidence from five tools with five different log formats and three of them missing.

The same model runs everything on top of it: dashboards, cross-app widgets, personal views and the API all answer to it.  
[Why a personal view can never widen access →](https://www.cordango.com/make-it-yours/)

## German hosting, and a short answer for procurement.

Cordango is built and hosted in Germany, on EU infrastructure, GDPR-first. Backups, updates and patching are managed, so “who keeps this thing current” is not a question that lands on the person who asked for the app.

The practical effect on a review is that there is one system to assess rather than a growing list of small tools each with their own hosting, their own login and their own data processing agreement. When someone builds a new app, nothing new needs approving. It is the same platform it was last month.

-   DE Built and hosted in Germany, EU infrastructure
-   GDPR One data processing agreement, not one per tool
-   OPS Managed backups, updates and patching
-   SSO Single sign-on included, not an enterprise upsell

What review has to assess Per new app

\# a new tool per process + a vendor security review, DPA, hosting + a login another account to offboard + a data copy somewhere new \# a new app on cordango ✔ nothing new same platform, same review

MORE

## The rest of the platform.

-   [**Run on Cordango** The live app: personal views, governance, shared context and connected work](https://www.cordango.com/run-on-cordango/)
-   [**Personal by design** One app, different ways to work](https://www.cordango.com/make-it-yours/)
-   [**Connected by default** Apps work together from day one](https://www.cordango.com/dashboard/)
-   [**Agents & APIs** Agents, MCP and APIs across your whole company](https://www.cordango.com/ai/)
-   [**Platform foundation** The company foundation underneath every app](https://www.cordango.com/platform/)
-   [**Sample apps** Explore real apps you can install and make yours](https://www.cordango.com/templates/)

NEXT

## Let people build. Keep the control.

See what a generated app inherits before anyone touches it: your directory, your roles, your audit trail.

[Book a demo →](https://www.cordango.com/contact/) [Privacy & GDPR](https://www.cordango.com/privacy/)
