Buying the specialist is often right. This page is about the times it is not.
This page used to argue that every SaaS subscription is another login, another permission model, another silo and another audit boundary. That is not a fair description of the category. Plenty of platforms span many applications with shared identity, shared data and central governance, and a specialist product often carries domain depth it would be foolish to rebuild.
So here is the honest version. Buying the specialist is frequently the right procurement decision: live quickly, maintained by somebody else, and for a regulated or commodity workflow their standard process is probably better than yours would be. Cordango gets interesting when the process is genuinely specific to your company, and when it ought to share the same people, organizations, rights and history as everything else you run.
Feature availability and pricing change. Every row is checked against the vendor's own current documentation, linked at the foot of this page.
Default means it is there without anyone setting it up. Available means the vendor supports it, sometimes only on a particular plan. Build or configure means it is possible and it is your work. Not a focus means the product is aimed somewhere else.
| Cordango | a point solution | |
|---|---|---|
| Live in days rather than weeks | Build or configuregenerating a capability is quick. Getting your data in and the process right is the actual work. | Defaultthe strongest argument for buying, and it is a good one |
| Fits a process that is specific to you | Defaultthe app is shaped like your process rather than the other way round | Build or configureconfiguration, until you reach the end of what configuration does |
| Domain depth you did not have to build | Not a focusCordango builds what you describe. It does not know your industry for you. | Defaultyears of it, in the good products |
| Shares your existing company records | Defaultone organization record and one person record, read by every capability | Variessuites and platform vendors can share a core. A standalone specialist usually keeps its own copy. |
| One rights model with everything else | Defaultchecked below every capability, per entity, per field and per command | Variesa platform vendor may share one across its own products. It will not share yours. |
| One history across everything | Defaultfield-level, produced by the runtime, in one place | Variesper vendor, in per-vendor formats, and some do not have one |
| One data processing agreement | Defaultone DPA and one sub-processor list, published | Build or configureone per vendor, and one review per vendor |
| AI and API across the whole company | DefaultREST and MCP over every capability, inside each user’s rights | Variesoften good within one product, rarely across products you bought separately |
| Somebody else maintains it | Defaultwe do | Defaultthey do, and this is a real advantage rather than a concession |
| German or EU data residency | DefaultGerman data centres, sub-processors published | Variesper vendor. Worth establishing before you sign rather than after. |
| Leaving is straightforward | Availableyour data exports, and active data is deleted within 30 days of the contract ending | Variesper vendor and per contract |
| What the price depends on | Defaultone contract for the platform. Apps are not priced separately. | Build or configureone subscription per tool, and they add up in a way nobody plans for |
The question worth asking about a new subscription is not whether the vendor is any good. It is whether this is a process where being standard helps you.
Payroll, accounting, e-signature: being standard is most of the value. The rules come from outside your company, somebody else tracks them for a living, and a custom version would be a liability. Keep buying those. We say so on the pricing page and we mean it.
The ones that go badly are processes that are specific to you and got a generic product anyway. Somebody configures it until they reach the end of what configuration does, a spreadsheet appears next to it, and eventually a person becomes the integration. That is the case Cordango is built for. The reason is not that generating an app is clever. It is that the app arrives already knowing your organizations, your people and your rights, so it is not a new island.
A point solution is the better choice when the process is standard rather than yours, when domain depth matters more than fit, or when nobody at your company should have to own the software at all.
What we can show you, and what we cannot. Cordango holds no ISO 27001, SOC 2 or C5 certification today, and has not commissioned an external penetration test yet. We would rather you read that here than find it in procurement. Security and permissions at Cordango, and the data processing agreement in full.
Bring the subscription you are about to sign. We will build the part you actually need in the demo, and tell you honestly if buying it is still the better answer.