Both build internal apps from a description now. The difference is what the app starts with.
Retool has moved well past the SQL-and-JavaScript canvas it is remembered for. Its current app builder generates working React apps from a description, its enterprise tier carries organisation-level roles, audit logging, SSO and SCIM, and it can run on your own infrastructure. Anyone still telling you Retool is developers-only has not looked recently.
So the interesting question is not who has which feature. It is what a new app begins with. In Retool you connect the resources an app needs and decide, per app, who may do what with them. In Cordango the company is already on the platform before the first app exists: the organizations, the people, the teams, the roles and the history are there, and a new capability reads them rather than being pointed at them.
Feature availability and pricing change. Every row is checked against the vendor's own current documentation, linked at the foot of this page.
Default means it is there without anyone setting it up. Available means the vendor supports it, sometimes only on a particular plan. Build or configure means it is possible and it is your work. Not a focus means the product is aimed somewhere else.
| Cordango | Retool | |
|---|---|---|
| Building an app by describing it | Defaultthe normal way in, alongside ready-made capabilities | Availablethe AI app builder generates and edits React apps from a prompt |
| Code-level control over the result | Not a focuspurpose-built screens from a shared vocabulary. No canvas, no formula language. | DefaultSQL, JavaScript and custom React, as deep as you want to go |
| Shared company records across every app | Defaultorganizations, people and teams are there before the first app | Build or configurepoint every app at the same source, and keep it that way as apps multiply |
| Organisation-level identity and roles | DefaultMicrosoft and Google sign-in on every plan, SAML and SCIM higher up | Availableorg and object permissions throughout, SSO and SCIM on Enterprise |
| Authorisation inside the app | Defaultenforced below the application, per entity, per field and per command | Build or configureyou decide per app what each group may do with each resource |
| Audit across every app | Defaultfield-level history produced by the runtime, nothing to model | Availableaudit logging on the Business and Enterprise plans |
| Connecting outside systems | AvailableREST and MCP over your own data. A narrower connector set than Retool has. | Defaultone of the widest integration ranges in the category |
| Managed hosting | Defaultbackups, updates and patching are ours | DefaultRetool Cloud |
| Self-hosting and on-premises | Not a focusCordango is a managed service. If you have to own the infrastructure, Retool wins this row outright. | Defaultself-hosted and VPC deployments on Enterprise |
| German or EU data residency | DefaultGerman data centres, sub-processors published | Availablean EU region on Retool Cloud, or self-host wherever you like |
| Taking the result elsewhere | Not a focusyour data exports. The app is a definition on the platform. The compiler and CLI are Apache-2.0, the platform is not. | Availableapp definitions export, and self-hosting keeps the whole thing inside your estate |
| Who has to build it | Defaultyou describe it, or you ask us to build it on the same core | Availablethe AI builder lowers the bar. The deep work still rewards engineers. |
| One contract for the whole platform | Defaultapps are not priced separately. The tenth capability does not add a line item. | Defaultone Retool contract, published per builder and per end user |
Retool’s unit is the app, and an app begins by connecting resources. You choose the database, the API, the warehouse, and then you decide which groups may read and write through that app. Done carefully across a portfolio, that produces something coherent. Done at the pace internal tools actually get built, it produces twelve apps with twelve opinions about what a customer is.
Cordango’s unit is the capability, and it connects to nothing. The organizations, the people and the teams are platform records, and rights are checked underneath every capability rather than configured inside each one. The second capability is less work than the first for the same reason the twentieth is: none of them defines a company.
That trade is real in both directions. Retool will take you places Cordango will not go, because Retool hands you SQL, JavaScript and the deployment target. Cordango hands you fewer decisions.
Retool is the better choice when a technical team wants deep control over queries, logic and deployment, or when owning the infrastructure is a hard requirement.
What we can show you, and what we cannot. Cordango holds no ISO 27001, SOC 2 or C5 certification today, and has not commissioned an external penetration test yet. We would rather you read that here than find it in procurement. Security and permissions at Cordango, and the data processing agreement in full.
Bring a workflow you would otherwise wire up in Retool. We will build it in the demo, on a company platform where the customers, the people and the rights model already exist.