Good morning, everyone. Welcome to Zscaler's Virtual Analyst Day. I am Bill Choi, Head of Investor Relations and the host for today's event. It has been nearly three years since our IPO, when we shared with you the notion that in the mobile and cloud-first world, users should access the cloud directly without going back to the data center and having security in the cloud. Since then, our vision and the approach has received very stro ng validation from the market in what Gartner now calls SASE, a Secure Access Service Edge, and also ZTNA, a Zero Trust Network Access. We believe we're just getting started, and we're very excited about our future. This we will discuss in the next three hours of this analyst meeting. If you look at our agenda here, we have four segments. Jay will discuss Zscaler's vision and strategy. Amit and Patrick will dive deeper into technology and products. After that, we'll take a five-minute break, then continue with Dali and Chris discussing our go-to-market engine. We'll end the presentations with Remo stepping through our addressable market and financials. If you want to read more about our executives, you can select the speaker bio icon on the bottom of your screen. Let me discuss today's format. We'll take a few questions after each segment. I will moderate this Q&A session based on your questions, which you can submit on the Q&A window on your screen. Feel free to submit your questions anytime during the presentation, as this will help us compile the list of questions. I ask that you save your TAM and financial related questions until after Remo has concluded his final presentation. At that time, we'll move over to a dedicated session for interactive Q&A with all of our executives. Today's presentation contains forward-looking statements. These statements are not guarantees of future performance, but rather are subject to risk and uncertainty. All forward-looking statements are based on information available to us as of today, and we assume no obligation to update these statements to reflect events that occur or circumstances that exist after today. Now, I'll turn the session over to Jay Chaudhry, CEO, Chairman, and Founder. Bill, thank you. In the next 20 minutes, I'll give you a high-level view of our vision and strategy for Zero Trust Exchange, the platform we pioneered. There's so much to cover. It's such a big platform with so many customer engagements. In the interest of time, I'll move rather fast and high light a few things. As you know, we pioneered this market. We're a leader in cloud security, especially doing Zero Trust based architecture. I'm going to share with you our audacious goal, which is really to have 200 million users and 100 million workloads run on Zscaler platform. Our innovation is second to none, that Amit is going to talk about. Our go-to-market machine, the work we've done in the past 12 to 15 months, has gotten in very good shape. It's firing on all cylinders. With our open culture, with exchange of ideas and execution focus and customer focus, is really becoming a big, big differentiator for us. If you look at the stats, some of these numbers, I don't need to go through everything here. Look at the value with our customers, the licenses, like 20 million some seats. NPS score of 76. Our scale, there's nobody who comes close to handling the type of transactions volume, 150 billion. Some seven billion security, essentially, incidents or security threats that we block every day. Small number of tickets for such a big volume that we end up doing. Very, very proud of that. The third area is look at the growth numbers. Remo will talk a lot of those later, I won't spend time on it. As I'm saying, exceptionally good numbers on billing side, revenue side, NRR, and all areas. With that, our overall mission, making cloud a safe place to do business and enjoyable for users. We do this by securely connecting any user to any applications or application to application, or even device to device type of stuff, with Zero Trust being the center. It's the opposite of traditional network security architecture, which actually slows things down, which really is expensive and slow. All right. Now, let's see. One second. Here. Audacious goal, 200 million users plus 100 million workloads. We've done a fair amount of work in this area, looking at where we are, where we need to go. With 20-plus million users today, we're just getting started. Our opportunity to grow falls in many areas. It starts with lots of new customers. We've got about 25%, just under 25% of Global 2000. Lots of upsell opportunities. We've got big platform and lot more functionality being added, not just features, but many new areas being added. Then we are expanding into new markets as well. We are going down market in some of these areas, and this down market for smaller enterprises, in addition to what we're doing for the federal market expansion and new markets like Japan for us. There are multiple tailwinds that have been helping Zscaler. We started out very early on leveraging Internet. Network transformation, going direct to the Internet has played a big role for us. Work from anywhere has been a big tailwind that'll last for a long time. In addition, you got public cloud migration applications. IoT/OT is just beginning and guess what, 5G. We're excited about the work we're doing with 5G. We think it can bring the further next level of disruption to make a big difference for companies to be more agile, to be more competitive, and a big revenue opportunity for Zscaler. I'm going to give you my view of our strategic objectives. A look at how we look at our objectives to grow our business in four buckets. Market leadership we've run on technology, highly differentiated, helping our customers. Operational excellence, because a cloud has to run, cloud must run well. We've got ability to attract good talent and develop good talents. I'm going to dig into each of the four areas now. Leadership. Wow, look at this chart. I don't recall having seen a Magic Quadrant chart where you are the only leader. For us, it's not just the leader in a year, it's a 10th year in a row. I mean, it's taken a while, the Secure Web Gateway Magic Quadrant is not just about a small piece of web filtering or what some legacy vendors try to downplay by calling it URL filtering. It is the whole suite of offerings from Secure Web Gateway to CASB to Zero Trust firewall as a service, browser isolation. It has expanded. It is the Magic Quadrant when it comes to going direct over the internet. By the way, many times I get asked questions about legacy firewall being competing us in this area. Look at what Gartner said. They've decided not to include any firewall vendors because to do proper content inspection for security, you must have a proxy architecture. Hopefully, that answers many of the questions where people think that firewalls are a good secure web gateway. Zscaler is the market leader, whether you're looking at customers who have presence in every country around the globe, or you're looking at customers with tens of thousands of locations, or customers with millions of users, or customers having tons of Office 365 traffic. We are the leader. We are the choice of customers to handle all those situations. If you look at verticals, almost all industries, some of the largest companies in each vertical depends upon Zscaler for their digital transformation. You can take conglomerates. It's seven out of the top 10. You can look at beverages, chemical, eight out of 10, or you can have household and personal care, six out of 10. All these leaders depend upon Zscaler. We're very proud of our market leadership. Let's move to the next area, technology differentiation. You know I've been asked this question so many times that how different are you from legacy vendors who offer network security? I've tried to give examples of DVD players versus Netflix or Tesla and electric car versus traditional cars. I'm going to take one more attempt to differentiate by giving you a good illustration. In this diagram, at the bottom, I'm showing you your corporate network in orange color that's connecting the data center and the branches. It's protected with a castle and moat model with a firewall. You're trying to protect the network, so you indirectly protect users and applications. You're building a perimeter. As your applications move out to the cloud, you extend your network to the applications because applications must be on the network. Now, when your users are working from home, what do you do? You extend your network over to the users. If you've got 50,000 users working from home, your network is extended to 50,000 homes. If your network is in 25, 30 public cloud vendors, different locations, and 50,000 users, your network is all over. Now, what implications does that have? Well, first of all, attack surface. Anything that opens to the internet is an attack surface. Every firewall facing the internet can be discovered, can be attacked. Not a good idea. Number two, it is a flat network, so users can go anywhere. Guess what. If one person gets infected, the entire network can get infected. No wonder companies have to worry about this kind of architecture. This is what network security does when you try to do protection for the world of cloud and mobility. I'm sure there'll be lots of questions on SolarWinds. Yes, SolarWinds came through a pretty sophisticated supply chain attack. How does it spread in the company? Well, through a flat network. In the Zscaler world, with Zero Trust, we have fundamentally different design. We don't secure the network. We are about securing users and applications because data sits with them. It's all about securing data. What are the design principles with Zscaler? Well, number one, you treat applications as destination, your data center, nothing but a destination. Your users are not on your network. When your users need to go and access applications, they go over the internet, and they go through our switchboard. Once we validate them, once we apply policy, we connect the right user to right application and right service. Period. It's that simple. In this approach, your applications are hidden behind Zscaler switchboard. They're not exposed, they cannot be discovered, and they cannot be attacked. There's no lateral movement because you don't have a massive flat network. In this new world, you don't really have to have a network other than your network sitting in your data center, maybe in the headquarters and the like, but internet is becoming your corporate network. This is the biggest difference that Zscaler brings. Zscaler architecture compared to legacy network security vendors is like trying to compare Tesla with internal combustion engine cars. Of course, both can take you from place A to place B, but that's where the similarity ends. I don't think I need to say any more about this. With our platform, the technology innovations we are driving is about securely connecting anything to anything. The four key areas of functionality, you are pretty familiar with Zscaler Internet Access and Zscaler Private Access. Lastly, we launched Zscaler Digital Experience to figure out user experience. These three things together are empowering our users, and they're also securing them. The fourth area we expanded, we announced at Zenith Live last month, was Zscaler Cloud Protection. This is extending our Zero Trust from user to application, to app to app, cloud to cloud, machine to machine, and more. Very exciting area. Touching base on go-to market. Dali is going to cover a lot more about it, we are starting with thought leadership. When you've got disruptive transformational solutions, you just can't say, "Order so many of these." We work with customers at the C-level. We land through consultative sales, through architectural workshops. As we're working closely with our customers hand in hand, we're able to expand, again, with consultative showing ROI and business value to our customers. No wonder our customers love us, and I touched base on NPS score of 76, where the score of an average SaaS company is 30. The third area, operational excellence. I have said before, building technology like Zscaler from a clean slate was a massive piece of work. Running and operating a cloud at 150 billion transactions a day is no trivial task at all. It also gives you some big benefits of security effect, just like networking effect. Renewable energy, which is we are committed to, and an architecture that can scale, like we had to scale last year. This is a big barrier to entry for anyone. The fourth area I talked about, attracting and developing talent. I very much know that for us to grow with such a great technology and such a great sales execution, we've got to be able to keep on hiring the best of best. The core values we have been using for quite a while have become extremely important for hiring and retaining our talent. This is ranging from customer obsession to open communication, to teamwork, innovation, and passion. Diversity and global workforce is an extremely important measure for us as well. Culture. Making sure we are totally focused on customers. Customers come first. In fact, just came from a meeting with CIO and CTO at just starting this because customers are extremely important for us. Diversity and inclusion, because diverse backgrounds bring new, innovative, great thinking. Hiring talent is not enough. Developing them, promoting them, being able to work with them are all priorities. We have a number of programs put in place in the company to make sure it happens, it happens well. What's the proof of the work we are doing in this area? Well, whether you read great place to work surveys, or you look at Glassdoor ratings, or you look at employee engagement surveys of Zscaler, the numbers are fantastic. On employee engagement, 87% overall satisfaction, far better than most of the companies I know of. The Glassdoor ratings of Zscaler, look at it. You can compare it to a whole range of companies. We pick a few samples along with it. We're very proud of our overall rating as a company. Then you see a few other areas that are listed in this table. Our customers have a very positive view of the company. Even compensation, they feel we are paying them well, and they recommend Zscaler far more than any of the lots of other companies out there. We are very much a global company from day one. I started as a global company. That's why some 50% of the revenue for Zscaler comes from outside the U.S. We follow the sun model for R&D, for customer support, as well as sales operations. With global presence, we have reach to global talent rather than being tied to the Valley and a few big cities. It is a strategic advantage for us. All right. Let me finish my last slide. We can get into Q&A. If I'm to summarize why we are winning, why we're so confident to really pursue an audacious goal we put forward, it's because market is moving to the kind of Zero Trust technology we built from day one. We have lots of customers. It's a proven model. It's not something new and cool we brought in. Our positioning, where are we set in the traffic path, we can add more and more services around it. Our scale, our cloud effect is so proven, it would be very hard for someone else to be able to come and do what we do. What we've done with go-to-market to take it from here to here in the past 15 months is remarkable. I'm very proud of it. I talk about culture, we are driving, our great teams, great people, and our balance sheet, our unique economics, because the right architecture, all that stuff is giving us some very good advantage. I feel very comfortable, very bullish about being positioned for success. With that, Bill, over to you. Okay. First I want to apologize for some technical difficulties we had. We lost Jay for about a minute or two when he was going over the legacy architecture and the flat network and the vulnerabilities there. We've received a question here that will allow us to answer part of this. This is regarding SolarWinds, Jay. The question is, "SolarWinds was a supply chain hack. How would a Zero Trust solution like the network security help in this situation? That's right. SolarWinds has been one of the most sophisticated supply chain attack. That means it went in through supply chain. In that case, yes, something like ZIA would have bypassed it. Once it'd gotten there, how does it spread? First of all, if you've got a flat network, you could be really in trouble. Being able to connect to applications only through Zscaler exchange will limit where all this can go. That's number one. Number two, in almost all cases, when breaches happen, data exfiltration goes to the internet. It has to get back home to some command and control center. If your internet bound traffic goes through our ZIA exchange, and if you're turned on SSL inspection and you're doing data loss prevention, we can stop all of that. We probably have better protection than anybody else in this area. Doing Zero Trust is the number one thing you can do. Obviously, for Zero Trust, identity plays a big role. That's why we integrated identity to our Zero Trust. One last thing. When we have all logs of any application or any process talking to any other application or process, there's tons of analytics using machine learning we are doing, and we'll be doing more and more of it to make sure that any unusual behavior can be caught. Even if someone gets in, unusual behavior is one indicator that people are trying to do things they shouldn't be doing. Great. We also have another question that's oriented with SolarWinds. The question is, "Can you talk about any changes in the tone of your conversations with customers since the SolarWinds breach? A lot. We think this is one of the biggest things. Maybe this has caused bigger impact than the Target breach several years ago. Target breach shook things up. That's the first time when C-level, even the CIO, got fired. Here, every customer is shaken up. I have reached out. I've talked to many customers. We have about six-plus dozen meetings lined up with CSOs of some of the largest companies who want to talk to us to make sure they've taken all the right precautions and steps in place. We know that they know that we are actually the switchboard to go in and out with this, making sure the posture and all that stuff is set up right. That's number one. Number two, we're seeing really the push for Zero Trust becoming bigger and bigger. In the past one year, I've seen a lot more awareness and understanding of Zero Trust deployment. That's really our core strategy. When I talk to C-level, about seven out of 10 bring up the notion. When I ask them, "What are your key priorities?" Zero Trust comes up without asking them for it. Great. Next question regarding your audacious goals. What are the big heavy lifting needed to get to that 200 million users and 100 million workloads, and when could you potentially achieve that? Yeah. First of all, we've seen great success so far. One of the big motivations behind this audacious goal was to align the entire company from development to sales and all towards one goal, so we are all effectively walking towards the same goal together. That's number one. Number two, really to get to this goal, if you look at overall market sizes at all, Remo is going to walk through some of the data. When you find that all the market that's available, this audacious goal is not actually overly audacious. We thought through it quite a bit. To get your goal, you start with, do you have the market? Remo will go out to the numbers. I would say yes, we do. Number two, do you have a real platform and offering that really can get you there? Very comfortable with what we have and how rapidly we're building. Three, do you really have a sales machinery, go-to-market machine that can execute it? Very happy with that. Sorry, there's one more. Can you support your customers? Can your cloud scale to deliver the service? Because it's not a matter of shipping a box and you're done. We're very good in that area as well. Very happy and excited. Great. Another question is, if the opportunity can be as big as you say, that will surely attract a lot of new competitors to this market. Potentially it could draw competition from the big public cloud companies. What are your thoughts about that competition? A good question. Every vendor tries to figure out where all they can go, where all they should go. The success depends, number one, on the core competencies of the company. Big cloud providers have core competencies in building big cloud application development, SaaS, and the like. Our core competency is in being the switchboard, the exchange, connecting things to things after inspection. I would say we've got a big advantage in the core competence. That's number one. Number two, every customer has multi-cloud strategy. Okay. We are the switch element that connects very well to all of those partners. It's similar to databases. Azure has databases, AWS databases, Google has databases. A company like Snowflake being able to say, "I can really provide you the service irrespective where you run." I think we're pretty well-positioned as independent security company. That's number two. There's one more. Yes, big companies can sell some of the security services. I have talked to many customers who told me that they don't feel comfortable in a fox watching the henhouse. Okay. They want independence between the application and data provider and the security provider. We believe we are well-positioned to grow and succeed in this market well. Okay. Can you give us an update on your hiring progress and give us a sense of how difficult or easy the hiring environment for Zscaler is today compared to six months ago? I made a comment during our last earnings call that Zscaler has become a top destination for top talent, okay? That's because of several reasons. One, our approach to hiring, training our leaders to go through a proper process has become much better. We are d oing a good job in recruiting, interviewing, hiring, all of those things. Number two, our brand awareness has gone up quite a bit. Customers love us. I've talked to so many candidates who said, "I reached out to Zscaler after talking to the CIO, who said Zscaler is a great place, it's a great company with great services." We are tracking our aggressive hiring plan for fiscal 2021 very well. In fact, we have increased our hiring plan twice since the start of the year. Because we feel bullish about the opportunity, and Remo and I have said many times, we will pursue aggressively the market opportunity in front of us. Top line is very important for us, though Remo and I both are very mindful of the bottom line all the time. Okay. You talked about 5G being a big revenue opportunity for Zscaler. When do you think it would be material for Zscaler? I believe in going after opportunities that disrupt incumbents. I think 5G will bring next level of big incumbency. We got some serious work going in this area, but I'm used to investing in the long run rather than looking for investing in something to give me revenue in six months. I looked at offerings just like a pharma company looks at its drug pipeline. There's growth engine A, growth engine B, then there's something in trial and something in just research. Keeping the pipeline this way is how I look at it. I think 5G will take time. It'll come in certain areas first, but we will be there to educate the market starting now, and revenue will come. I'm not worried about the product areas. While I want to build more, we've got so many offerings on our platform today to grow our revenue multi-fold. We'll keep on investing in the long term while driving sales in the short term with a lot of offerings we already have on the plate. What do you think is still the single biggest investor or analyst misconception regarding Zscaler's multi-year opportunity? It surprises me that after all the discussion we have, they still compare us with network security vendors. I try to talk about DVD players and Netflix and Tesla versus others. When things are architecturally different, you can't just add on some features and make enough money. You need to start with a clean slate. I think that's the biggest advantage we have and biggest misconception we have. Wonderful. All right. There are a lot of questions in the Q&A box, but as we mentioned, we'll have dedicated time for Q&A at the end of our presentations. I know we've had, like I said, technical difficulties here. We will have replay video within several hours. Also, the presentations will be made available on our IR website once we're all done. Next, we'll move on to discuss architectural differentiation and new products. Our speaker will be Amit Sinha, President and CTO, and Patrick Foxhoven, Head of Emerging Technologies and CIO. Interestingly, Amit and Patrick have been both with Zscaler for over 10 years at this point and lead the innovation engine that's powering our results and competitive modes. With that introduction, I'll hand over to Amit. Hope you can hear me. I wanted to spend the next 20 minutes taking you through our technology and platform differentiation, and some of the key messages I want to drive is, one, how we've built our scalable global platform, and it has a significant barrier to entry. On that platform, we are delivering rapid innovations because it's really extensible. Over the years, it's grown, and now we have unparalleled security and visibility with the vast amounts of data that's fueling our AI and ML engines and also delivering cloud effect. The bigger the platform gets, the smarter it gets. Finally, as we grow the platform, we get strong economies of scale with lower support and operations cost. We'll dive into some of these topics. Jay shared our overall data center map in one of his slides, and I wanted to reiterate some of the salient points there. We've built this platform across 150-plus data centers, and it's not built on any single service provider. We choose the best data centers that serve any geography. We bring in the best transit providers and internet exchange connections that provide the best connectivity options for customers in that region. The cloud has grown, and we now are at north of 150 billion transactions per day. 5% of those transactions, approximately 7 billion, have policy and security issues that we stop and protect our customers with. The cloud is getting smarter at a very rapid rate. It gets about 200,000 unique security updates on a daily basis. We provide strong SLAs for our service at five nines, and I'm very proud that 75% of our platform now runs on renewable energy. Over time, we've added a lot of security hardening to the platform, and there's no compression algorithm for experience. We've gone through a lot of opera tional compliance, both for the platform as well as how we run it. We're now FIPS compliant, ISO 27001, FedRAMP, SOC 2, and many other regulatory requirements have been met. To put 150 billion transactions in perspective, I thought it's important to put it on internet scale. Here you're seeing a simple graph, and they're not apples to apples, but it'll give you an idea of the scale at which we are operating. There are about 700 million tweets on Twitter on a daily basis. Maybe that number is a little down since our president was banned. On YouTube, we have about 6.9 million daily views. Google, it's estimated, does about 7 billion searches daily, and that's 150 billion transactions per day on that same scale. We are operating at a massive scale, and it takes a really scalable platform to be able to deliver this. Let's talk about how we have grown to $150 billion. This graph shows what I call the Moore's Law for Zscaler. We've been doubling our transaction rate, in terms of usage, about every 20 months or so. The reason we are able to sustain this growth is because of our core multi-tenant architecture. It's designed to scale with business. When we add 500 gigabits per second of capacity in Chicago, all 4,500 plus customers can benefit from it. Think of it as building a high-speed rail versus customers in individual cars. The multi-tenant architecture is the core of this growth engine that allows us to scale with demand. It is also globally fault-tolerant. As I mentioned, we're not using any single provider. The platform proved its elasticity during COVID-19. Between January and March of last year, we had a 10X surge in ZPA traffic, and the platform handled it beautifully. Over time, we've added a lot of engineering into the platform to allow it to scale both horizontally as well as vertically. One very important distinction between how we built this platform and how some of our legacy competitors try to achieve this is the fact that we're not built on any one service provider. We've not built this platform on AWS or GCP. Zscaler service is fundamentally destination neutral and built as an edge cloud service. Let me explain how that works. Our users, our workloads can be anywhere in the world, and they can connect to the nearest of the 150 Zscaler data centers. For example, if a user wants to go to Office 365, they come to the nearest Zscaler data center, we peer with Microsoft directly in most of the sites worldwide, and they get a straight path to the destination, Office 365 in this case. Legacy competitors try to take their firewalls, for example, virtualize it, run it in GCP. Here's what happens when you try to connect to Office 365. You connect to Google, you go deep into G oogle's core to run your virtual machine, come out, then go to Microsoft to access the destination. As you can see, building a Zero Trust Exchange requires you to be fundamentally destination neutral, and it has to be built as an edge cloud service with complete compute capabilities available in every location, and not just some of the core compute regions that service providers like Google and Amazon give you. I mentioned that all our data centers now are striving towards renewable energy. This is the latest snapshot. About 76% of all transactions we processed last week were based and powered by renewable energy. Our mission is to get this to 90+% by 2025. Not only do customers get global protection, they also can dramatically reduce their carbon footprint. The fact that the data centers th emselves are green is one thing. The other important factor to remember is multi-tenancy and our high-performance software gives 10x efficiency to the processing that we do, which dramatically reduces their carbon footprint compared to providing this service based on legacy appliances. Over the past decade plus, we've shown a rapid history of innovations. Pretty much every year, we've launched what I would call a full company on the platform. We launched the first multi-tenant platform back in 2008. Since then we've added DLP, SSO capabilities, inline CASB, cloud sandbox, firewall, and DNS security. In 2016, we launched Zscaler Private Access. We added Microsoft integrations. We've started doing significant things with AI, ML, and enabling our partner ecosystem. We've added browser isolation, API-based CASB, Zscaler B2B, and last year we launched Zscaler Digital Experience and Cloud Protection. It kind of shows how extensible the core platform is. All of this while, we've been going through that exponential growth that I showed. We achieved 1 billion transactions per day in 2011, 10 billion in 2014, 50 billion in 2018, around the time of our IPO, and we are operating at 150 billion transactions per day. You can see all the accolades and some of the milestones we achieved during this journey. We became a visionary in the Gartner Magic Quadrant in 2010. Fast-forward to 2020, we were the only leader in the Gartner Magic Quadrant. Along the way, we became ISO 27001 compliant, and in 2019, we achieved FedRAMP compliance, which is extremely rigorous and shows the operational maturity that we have obtained. One of the questions that people often ask me is, how extensible is the Zscaler platform? I wanted to show how much IP we have created and how easy it is for us to add new IP to the core platform, which is extremely extensible and why. If you look at the lines of code, this is a good sense of how much IP has been created. We're sitting at about 10 million lines of code. To put that in perspective, 10 million lines of code, what is that? If you look at the Mars Rover project, there was about 5 million lines of code. Linux 2.6 was about 5.2 million lines of code. A massive amount of IP has been created. We've now filed over 200 patents that have been granted or pending. If you look at how we've grown the service, the core platform is about 2 million lines of code. When we added Zscaler Internet Access use cases and services on top of it, that was another 4 million lines of code. To add ZPA, the amount of work that we had to do was lesser because it leveraged a lot of platform components. Similarly, by the time you add ZCP and ZDX, you can see the amount of extra work on the platform keeps going down because newer products are leveraging a lot of the IP that the platform already provides. I wanted to spend some time and give you a little more color on the breadth and depth of the Zscaler platform. You're all familiar with Zscaler Internet Access. That was a core platform we launched, and it provides a lot of use cases. It sits between users, workloads, and public internet destinations, making sure nothing bad comes in, nothing good leaks out through that Zero Trust Exchange. The use cases that we are able to provide are threat prevention, full native SSL scanning capabilities, cloud sandbox, DNS security. We provide complete access control capabilities through our cloud firewall. Users can optimize bandwidth, they can prioritize, for example, Office 365, and make sure that YouTube and streaming media are not affecting office productivity. Similarly, on the data protection side, we've added a lot of capabilities on DLP, on CASB, using both inline and API-based controls, and we recently added browser isolation capabilities to the platform as well. In 2016, we launched Zscaler Private Access, that allows our customers to connect to private applications using a Zero Trust architecture. In the process, we eliminate a lot of the legacy solutions, whether they are traditional VPNs, firewalls, DDoS prevention, and network segmentation, things that had to be done in the old way of accessing internal applications. ZPA also provides smart capabilities like load balancing, app discovery, and app health monitoring. We are also integrating browser isolation capabilities. Recently, we launched Private Service Edge with ZPA that simplifies access in a site-survivable way. Our customers came back and said, "You're sitting in between all our users' workloads and destinations. In this distributed world where we don't control the end endpoint, we don't control the network. The user might be at home, coming over a Comcast connection to a mission-critical application like Office 365. When problems arise, where are the problems?" Right? ZDX is the perfect solution for it, and we're getting a lot of traction. It gives you hop-by-hop network analytics. It can tell you if there is a problem on the endpoint. Maybe it's your Wi-Fi, maybe you had an update and you're having CPU issues. It can also monitor the response times of your critical apps, whether it's Zoom, whether it's Office 365, or whether it's an internal application. Finally, last year at Zenith Live, we launched Zscaler Cloud Protection. This is a massive new area of investment for us. Patrick's going to give you a deeper view of the capabilities around ZCP. One important point I want to emphasize is our Zscaler Client Connector, which provides a footprint for us to land and expand. It is a single endpoint that supports ZIA, ZPA, as well as ZDX. It eliminates multiple different agents that IT had to manage for firewall and VPN access, for example. Today, ZCC, Zscaler Client Connector, runs on over 17 million devices. It works seamlessly on all platforms, Windows, Mac, Linux, iOS, Android. It provides easy land and expand capabilities. Customers might start off with ZIA. If they deploy ZPA, it's just a license that they need to enable. They don't need to roll out a new endpoint, which can be a friction point for deployment teams. It's extremely lightweight and extensible, using a SASE concept where you keep the endpoint light, you don't reduce performance on the endpoint, and you do all the heavy lifting in the cloud. ZCC is becoming very, very central to our overall platform. Another question that comes up is, once you've done all of this, once you've deployed and embraced Zero Trust, what is the real security benefit? Probably the best way I've seen this characterized is by National Oilwell Varco. It's a Fortune 100 oil and gas company. The w ay they measured security effectiveness within IT was to see the number of computers that got infected and IT had to re-image them. Before they deployed Zscaler, on an average, NOV IT had to re-image anywhere from 50 to 200 plus machines every month. You can see as soon as they deployed Zscaler, the number of machines pretty much vanished and there were little or no infections. There were a few onesie-twosie infections, and they were around new locations that were added or devices that weren't fully enrolled into the service. Another area of significant investment for us is leveraging the big data that Zscaler has amassed. 150 billion transactions is a staggering amount of data. This is metadata. It tells us where a user or workload is connecting, from what type of location, what type of IP, et cetera. We're able to leverage that to solve very important security and usability use cases for our customers. Example, we are able to use big data to improve our security capabilities. We offer smart quarantine and zero-day malware detection. Once you've seen millions of ransomware strains, you should be able to predict when a new ransomware strain shows up, even if you don't have signatures for it. We are using machine learning for content classification. A new website shows up, you don't know what category it belongs to, we are able to leverage our machine learning capabilities to do that dynamic content classification. Similarly, we are using content classification to auto-segment workloads and apps. It's very common for us to see millions of different apps pop up, to manage them becomes complex if you don't use machine learning capabilities. We're able to leverage machine learning and our big data, to detect anomalies. Maybe a user simultaneously shows up in two locations, which is impossible. Similarly, you might have app and user anomalies that are lurking that the machine learning is very effective at detecting. Finally, we're using machine learning in ZDX to improve end-user experience, find out root cause, look at correlations. Maybe a particular location in the world is having a systematic problem. Maybe a group of users that have a certain type of an app is having a correlated set of problems. Our customers want to co mpare themselves to peers, all of these are powered by our machine learning capabilities. Another data point I wanted to share with you is the number of points per day. We talked a lot about transactions. Transactions is the metadata. Think of points per day as statistics. For every user, we are collecting thousands of statistics. The number of times they went to a particular destination, for example. For every workload, we are collecting thousands of statistics every second, and that results in just north of 300 trillion points per day. That's a massive amount of information. With 300 trillion points per day, we can fire up anomaly engines that can give you very detailed assessment of anomalies by user, by location, by workload, by across countries, compare them to different organizations in the same peer group, et cetera. One other interesting point I want to share is the efficiency of the software stack we've built. There have been many cases where Zscaler has replaced high-performance legacy appliance solutions, and one good metric to remember is the power of our software delivers about 10X efficiency. In fact, if you look at some of our deployments, we've taken a rack full of 10U appliances and replaced it with what would be an equivalent of 1U worth of Zscaler hardware. The reason for that is, again, the relentless engineering and true to our name, Zscaler, we've been scaling the capabilities of what our platform can do, both horizontally as well as vertically. This is showing you the vertical scale capabilities that we've delivered from 1U worth of server capacity. Back in 2013, if we were doing 1X of unit processing, architecturally, we refined it with multi-instances, with load balancers, with active load balancers, and the same 1U can now deliver 12X of processing capabilities just by the sheer power of Zscaler software. That directly translates to our gross margin and COGS strength that we have talked about in the past. Finally, let's talk about supporting the platform. The graph on the left shows our quarterly transaction volume. You can see that it is following that Moore's Law, growing exponentially. What is interesting is while those transactions have grown through the platform, we've been able to reduce our unit economics when it comes to supporting. The graph on the right is showing the number of support tickets for a billion transactions in any quarter. You can see a while back, we were at seven tickets per a billion transactions, now we are at about 2.7 tickets per a billion transactions. That results in two things. One, our higher NPS score, you have lesser problems because the platform has become mature and robust. Number two, it drives down the cost of supporting as our customer base grows. Hopefully, that gave you some insights. I wanted to reiterate the key messages. We have built this massive, scalable global platform. There's no compression algorithm for experience, for architecture. It offers a significant barrier to entry for folks who try to replicate what we've done. You've seen the pace of innovation, the extensibility of the platform. You've seen the unparalleled security and visibility with the vast amounts of data that we now use to power our AI and ML engines. You've seen a little bit of the economies of scale, how the platform is getting more efficient, more cost-effective from a support and operations perspective as we continue to grow. With that, I'd like to hand over to Patrick Foxhoven, our EVP of Emerging Technologies and our CIO. Patrick's going to give you a deeper view of Zscaler Cloud Protection. Patrick, over to you. Thank you very much, Amit. We wanted to give you just a quick 10-minute deep dive into the newest area of our platform, like Amit gave a good introduction to what we're calling Zscaler Cloud Protection. Let me kind of set the stage. If you think about the origins of Zscaler and the history of how we started, I don't think it's unfair to say that we've pioneered bringing Zero Trust to what I would call north-south traffic flows, meaning between users and applications or public internet destinations. We're doing the exact same thing just for kind of an adjacent set of traffic flows. While ZIA and ZPA have been very focused on north-south traffic, what we're doing in cloud protection is extending the same principles of Zero Trust to east-west traffic flows. That's not users to applications, but machine to machine, server to server, east-west traffic flows, workload to workload. The reason why I'm making that comparison is because while it's a new area for us to go into, the underlying principles of doing a Zero Trust Exchange that we're characterizing on the right are exactly the same. How you scale an offering, how you secure it, all the underlying foundational points of north-south or east-west traffic flows applying a Zero Trust Exchange to remain the same. While it is a newer area for us, we've actually already addressed the foundation required to be able to tackle some of these solutions. Let me give you a deeper view of under the cloud protection umbrella, there's three key parts to the solution today. The first one is on the top left, this is what the industry calls Cloud Security Posture Management or CSPM. This is all about addressing the proper configuration or compliance of when you deploy workloads to the cloud. I'll go a step deeper there in a moment, that's one piece of the pillar. The second piece is the underlying communication itself when you're talking about providing security for the workloads, how that communication occurs is very important. This is getting into not the configuration or governance of the environment, getting into the real-time or runtime protection of communication between different workload components. That can be whether it's going from one app to another app or from a cloud provider to a cloud provider or even that cloud workload environment to the internet. This touches on actually a couple of different parts of our platform, which I depicted down at the bottom. This is not only our core ZIA and ZPA offerings, but then new components like what we're calling a Zscaler Cloud Connector, which I'll provide an overview here in a moment of as well. Last but not least, the third part of our Cloud Protection package is doing workload segmentation itself. Taking the Zero Trus t concepts that you're probably familiar with from north-south traffic flows, keeping a user off the network, but doing the same exact kind of extreme segmentation to the actual workload payloads themselves and how they communicate. We'll go deeper there in a moment as well. These three pillars are kind of what make up the Zscaler Cloud Protection solution overall. It's at the end of the day, comparing it to ZIA and ZPA, this is all about securing users to application access without exposing things. I don't think it's very debatable that this momentum or this trend is here and is only accelerating. Just like in the ZIA and ZPA offerings, the advent of users working across all kinds of devices from any location, the same kind of mega trend is happening to how workloads happen, which is in essence saying a lot of applications are moving from the company-owned data centers to the cloud providers, to the IaaS providers. There's a quote here at the bottom that I think is quite good from Gartner, which is they make a very bold claim that say almost every company on the planet will have at least some form of multi-cloud deployments hosting their applications. They say 98% by the end of 2021, which is quite a bold prediction, but I think it's true. It's here and it's happening. When companies migrate their resources to the cloud, one of the benefits of the cloud is to have simplicity. What's unfortunately happening is it's actually introducing the reality of these migrations is introducing a lot of complexity. Let me walk you through what this looks like. You don't want all your resources or all your applications running in one data center or one provider, so you do multi-cloud deployments inherently. To do a deployment within even a single cloud provider, you need to be in multi-region, and you also have to be within a region, go across different availability zones or individual locations. What that looks like on the right, we're not trying to make too much of an eye chart here, but let's say it's an organization that is large and they're running in AWS and Azure. They're going to likely deploy a workload in usually three, four different regions to start with, so that's times two for each provider's environment. In those regions, those map out to individual locations. You probably want to do at least four locations within a region for availability. It starts to introduce a lot of complexity, and I'm going to depict this in showing how organizations choose to secure those environments today. The high level theme of this slide is, I think the big challenge is organizations are taking the same principles of how you would deploy an application in a company-owned data center and what that network model and architecture would look like, and they're trying to apply the same building blocks or concepts in an IaaS environment, and it doesn't make a lot of sense. Let me show you why. If you recall that last slide with all the different availability zones and regions and multi-cloud provider deployments, if you zoom into one, in terms of what they look like, it's usually, in this case, I'm showing an AWS availability zone. You've got a VPC where one workload is running, and if you're doing extreme segmentation, often you'll firewall everything within that VPC from anything else. If you've got another workload, you often will deploy that across multiple different VPCs. As that grows, you have to introduce these concepts of adding things like transit gateways. As you have traffic coming in or out of this environment, you'll create an outbound VPC that secures these workloads as they go out to the internet. Often, another pair of firewalls get deployed there because it's shared among all. Same thing happens when users need to come in. You have an inbound VPC that's in front of this transit gateways to allow people to come into where the workloads are running. You've got, obviously, multi-cloud provider deployments where you may need applications or resources in AWS talk to Azure or talk to the corporate data center. There's often this concept of bi-directional or site-to-site VPN VPCs that get introduced. Because you have all this complexity and complications, you have to have a management layer to orchestrate simple things like all those firewalls that you deploy in these VPCs, as well as just keep sanity around this overall network architecture. This comes at a lot of expense and complexity, and what often happens is we'll see things like workloads get deployed in these environments, and because the barriers of that happening are very low, you could instantiate these things very quickly. Sometimes DevOps even circumvents corporate security policies, and we've seen not just the cost and complexity be a concern, but also how high risk this kind of an architecture is. Let me extrapolate that even further, in terms of how complicated it is, and depict what that network looks like. You'll see this diagram on the right looks an awful lot like what a traditional MPLS or corporate hub and spoke environment looks like. You have an any-to-any like connectivity model because the principles are secure the network where the applications are running, which means you have to extend the network to where they are, also extend the network for the users to get access to them. That is quite crazy in my mind because this comes with a lot of risk. This is, one, a huge attack surface. Everywhere that you have a firewall deployed and listening, it's potentially a point of entry to this environment. We've all seen lateral threat movement being such a huge risk. The model on the right is more or less a flat network with just a bunch of firewalls with access control policies. There's still attack surface there and there's still risk, especially as things get misconfigured or overly permissive in terms of what they're allowing. Our approach to this kind of craziness is to simplify it, meaning extend the attributes of our Zero Trust Exchange and deploy what we're calling Cloud Connectors. Those are the little blue Zscaler clouds that run within the VPCs. You deploy a Cloud Connector or two for redundancy, and you can completely dissolve that transit gateway, all those different VPCs for traffic coming in, out, scrubbing. You can replace that with what we're already doing today. Customers already are deploying us in this manner, even before we had the Cloud Connectors where they have a workload environment and it needs to connect to the internet, have it go through our ZIA offering and get the full security stack capa bilities of that traffic to secure it as it goes out to the internet. We're obviously already often providing inbound access from a user coming into the private applications with our ZPA offerings. A newer area is leveraging these Cloud Connectors that we have and allowing traffic flows to be not just north-south or user-to-app, but server-to-server, site-to-site, cloud workload to cloud workload. That's what we're depicting on the bottom with those new cloud icons as well, is we've got these Cloud Connectors. While it's a new area, it's leveraging a massive foundation that we're doing already, and we're already doing this in a lot of cases already. We're extending the biggest new areas, Cloud Connectors and governance with CSPM and so forth. If I show you the same model depicted in terms of what the network looks like, getting rid of all the spaghetti lines that you saw on the prior slide. The principles around what we do here is, this is all about securing users and data with a Zero Trust Exchange. You're not securing the network. You'll see there's not really a network here. If you believe the internet's becoming the new corporate network, that's why we're not depicting any flat network anymore. It's users, devices, locations, things that have outbound connections to us. We are providing as a service the capability that they were trying to replicate on their own in the traditional ways. When you embrace a model like this, you're dramatically minimizing the attack surface. It can become completely dark or invisible, so to say, when you truly embrace this kind of an architectural model. As a result, because there is no network, there's a massive reduction in risk of traffic moving laterally within this environment. With my last slide, just to kind of solidify what we're doing in our cloud protection capabilities. You'll see that I'm drawing out at the bottom our ZPA offering is securing users going into where the cloud workloads are running. In the top right, number two, we're securing communication or traffic flows to the data center. We're also securing data center to data center, site to site cloud communications with our ZPA offerings. Fourth, when you have workloads in there and they go out to the internet, we're using our ZIA offerings to secure that as it goes out. I think the reason why we made this a fourth pillar of our platform is it's rounding out a very holistic, good approach to delivering Zero Trust -style solutions to not just users, but to workloads. With that, I think I'm going to hand it back to Bill for Q&A. Okay, wonderful. A bunch of questions here. Why don't we start with you first, Patrick? With workload communication, how and where does a customer start with deployment? Sure. Yeah, one thing that's important is the customers who we're targeting to start with workload communication are likely already ZIA, ZPA customers. They understand us already. They may have already been deploying, like I mentioned, these workloads that they've moved out to an AWS or Azure of the world. They might have already created tunnels there and had that go through our ZIA policy engine to do all the security capability that we do in ZIA. What ends up being a little bit new is in the use case of when it's a data center going to the cloud rather than having a dedicated link, you're introducing the traffic going through our Zero Trust Exchange. There's a little bit of plumbing, deploying the Cloud Connectors in those environments and introducing that. This is all about extending their existing solution to what we're doing and showing how simplified things can become. I'd also add that it doesn't have to be a boil the ocean approach. You can selectively introduce from a workload. You don't have to replace everything overnight at once. Okay. Hey, Bill. Jay, if I may add. This is by and large a new area. Customers are struggling to figure out how to expand their workload. It's not much of a replacement opportunity. It's an area that's needed badly. It's like when customers would say with ZIA, "What all are you replacing?" When AutoNation added 360 branch offices as local breakout, that was a greenfield opportunity while they had two data centers with ZIA had to go through. Think of a lot of this workload communication is a new area customers are trying to figure out, and we are there with a very good and attractive solution while they have struggled to do the old firewalls type of stuff to do it. Another question for Patrick. What does a large enterprise typically spend on building one of those transit gateways with firewalls? How much could someone save by moving to a workload communications? Yeah. They spend a lot. In a large enterprise, it can be $ hundreds of thousands or more. What we see more often, though, is cost is a secondary factor in that equation. The challenges are their existing approach is limiting their adoption of cloud infrastructure, accelerating the migration of things out to these providers, and capturing all the benefits that are associated with that. Our primary value in ZCP is simplifying the infrastructure while improving security and obviously providing scale so that things like performance don't suffer. We think there's a huge need for that in and of itself. We're, in essence, removing a lot of complexity. Hopefully, those two slides I shared that. We're removing a lot of VMs for security appliances and the need to even build things like transit gateways and virtual routers and virtual firewalls and peering costs and a lot of different models. Hopefully, the simplification is way more impactful there than anything else. This would be for Jay and also open to others, if you could comment is, when you talk to CIOs, why has cloud workload and infrastructure protection security lagged so far behind in investment so far? I think customers have been trying to find the right solutions. When you start in a new area, you try to do what they've done before till some new innovative technologies come along. People have tried to do virtual firewalls, just like Patrick shown, now they're all feeling that this doesn't work. We are going in at a time when the pain is already known, legacy solutions have failed. It's great. We are finding tons of interest, but from timing point of view, it's easy for us to start with our existing customers because we have lots of credibility with them. We are very bullish about the opportunity to solve these hard problems and help them with the digital transformation. Build applications in the cloud, if they can't be secured properly, is no good, especially as we're finding that cyber is becoming a bigger and bigger issue. That's a problem we're solving in the most elegant solution. It's just like with ZIA, ZPA for the users, this is going to do the same thing for workloads. Okay. The next question could be Amit or Jay, if you want to also speak to it. Why hasn't anyone else caught up with your architecture? Does the customer really care about architecture versus getting the price, performance, functionality they need? Amit, you want to start? Yeah, absolutely. I'd say architecture matters tremendously. If you do not have the right architecture, you cannot build and sustain a service. Jay talked about Tesla versus the internal combustion engine-based systems, right? You cannot transform that overnight. You need to start with a clean slate. The kind of growth that we have shown would not have happened if we did not have a multi-tenant architecture. The kind of security capabilities that we have shown would not happen if we want a proxy-based architecture. If 95% of the content of the world is encrypted, if you're not looking at content, you're not going to be able to provide the capabilities. Finally, I'd say, if you don't have the right architecture, you cannot deliver good gross margins because it is going to get more and more expensive from a support perspective, from an operations perspective. All of those are very important, and if you do not do it right, it's going to hurt you in the long term. Yeah. If I were to add a couple of things, I think it depends what you are trying to do. Sometimes you're writing, you're building simple uni-dimensional applications, the architecture could be simple and barrier to entries could be low. Take for example, SaaS application, travel and entertainment application. What does it take? Not a whole lot. Look at ERP, right? NetSuite started in 1999 as the cloud-based, cloud-native ERP application. How many cloud-native ERP applications are out there? I can think of two, NetSuite and Workday. When ERP is the most important application, why don't you think there should be lots and lots of vendors? ERP is the hardest SaaS application to build. It hooks into everything. It's tough. In the same way, there are some uni-dimensional applications in security that are easy to build. Doing email security in the cloud is relatively simple. It got done as the first application. Doing identity is a well-confined, well-defined uni-dimensional area. That's where we had 50 vendors in that space, market consolidated, and it's a mature market. Doing what Zscaler does, to sit in traffic path, to enforce all policy, requires that you eliminate the need for all those point products, from firewall to web proxy, to DLP, to sandboxing and the like. You can't have your traffic go from cloud A to cloud B to cloud C to cloud D. It's not really practically doable. What we've built is hard, and I can tell you, when I started Zscaler, I mean, it was a massive undertaking. Had I not done four companies successfully, I would not have had the guts to take such a big undertaking. Also, the VCs will also think twice about a major undertaking like this because they need to look for ROI. I had the luxury of putting my own money and taking my own risk to do it, which allowed us to build such a massive platform. It gives us a big advantage. Incumbents naturally start with, "If I got this technology, how do I repurpose it to do something else?" It's great that that's what they're doing, because building architecture from clean slate is hard. Okay, we're back. We'll get started on the next segment, which is go-to-market and marketing demand generation. As many of you know, our next speaker, Dali Rajic, joined Zscaler as CRO back in September of 2019, right around the time we held our last Analyst Day, and has since built a high-performance go-to-market engine that is driving our top-line results. Following Dali, we'll hear from Chris Kozup, who joined us two months ago as CMO. With that introduction, I'll hand over to Dali. Thanks, Bill. I'm assuming everybody can hear me all right. Great. Let's get going. Thanks everybody for being with us today. I think before we get going, I want to make sure we do the safe harbor statement and give everybody a moment to take a look at this and then dive right in. Here's some of the key messages that I want to make sure we get across today. I'm very proud of what we've done over the last really 12 months. I think it's been really centered and focused around building a sophisticated and synchronized go-to-market engine. There are certain elements that we're going to touch on here around productive capacity, around how we engage with customers to really help them transform. Those are big words, but if there isn't a framework behind it's very difficult to achieve this. How do we make sure that during these really dynamic times, we're not just providing great solutions, but maximum customer sat, maximum value, maximum retention with all of our customers. Lastly, how do we make sure we drive new logos at velocity with all the right levers inclusive of the different areas and paths to revenue such as channels and enterprise. I think it's important to understand what our go-to-market model looks like, why it's scalable, why it's repeatable, and why we're able to really get all of our people to execute across the same excellence, whether or not you're in Des Moines, Iowa, whether or not you're in Tokyo, Japan, Munich, Germany, it doesn't matter really. It's one framework that is built around the customer lifecycle engagement, around value creation, around making sure that we focus on business outcomes with the unique capabilities that we have. It absolutely is a competitive differentiator for us. Now, if you take a look at pipeline generation, this is where it all starts. We have clear strategies built out across the team on how we generate pipeline in a very scientific and very customized way. Again, not product pitch centric, but outcome and business impact centric. The framework and the life cycle really applies the same, whether or not you're a prospect or you're a customer. Because as a prospect, we're selling for the first time. With a customer, we're upselling on an ongoing basis. As you can see, it really is around identifying problems, making sure that architecturally we define how to resolve those. What sequence? A question came up earlier, how do customers know? The answer is they don't know many times, which is why it's our responsibility to help them articulate what the best path forward for transformation is. The other thing that we also do is we make sure we capture, identify what is the value that we can drive for these customers, and how do we actually get there, and how do we prove out we're uniquely qualified to deliver it compared to somebody else? Obviously we have to deploy with success. We have to make sure that we run quarterly business reviews with these customers to identify. Are we adopting, are we value realizing, and are we getting ready for an expand with Zscaler? All of this means that the transformation roadmap that we put together for customers continues to evolve, continues to expand as their business requirements change. We're there along with them every step of the way. The one thing that's very unique about us is the access to executives, senior executives, compared to any other vendor out there in our industry, and quite frankly, compared to anybody that I've ever worked for in my career. Because we have this access, it is critical that we keep the thought leadership, the mind share close to us, which we do via executive briefings that we run on a consistent basis. Some of you might have questions of what happens as you add additional products? What happens as you add additional capabilities? The answer is you simply plug them into this model because this is a use case, outcome-based go-to-market model. This is a model that has the entire ecosystem integrated into assisting at the right time with the right activities, very carefully measured. Underlying all this is a revenue ops engine and systems that allow us to understand how we're doing across every single step of this lifecycle engagement. That means we understand how well we're doing, what the transitions and conversions are, regardless of where you are in the world and regardless of what your tenure is with the company. We have an enablement team that allows us to continue optimizing the quality. It is an integrated, outcome-based go-to-market engine that has all of the ecosystem and overall corporate elements as part of it, with very precise and intentional activities at the right times. I wanted to just list a few examples here of some of the value that we provide to our customers. Now, many vendors will say, "We provide business impact. We provide business value." The question is, can you actually measure it? Can you quantify it? Can you then value realize? Can you make sure that the customer is absolutely agreeing and willing to speak to the measurable, quantifiable impact that you provide? We have dozens and dozens of cases. Some obviously we can't list. We have a few of those listed on our website as well. What it means is to the earlier question, why can't others duplicate this? Because our ability to solve for unique use cases allows us to drive unique business impact, which we identify throughout the sales process, get the customer to validate that they're relevant for them, and that then differentiates us based on where the customer is trying to go and transform to, as opposed to feature function comparisons and matrix, which might have been yesterday's world. The other thing that is really critical for us to discuss is, if you have this sophisticated, synergistic, harmonious framework, what does that really mean in regards to making sure that you can bring people in and get them active and productive very quick? If you take a look at what we have really done over the last 12 months is build a recruiting engine that allows us at all levels to, at velocity, really go after top candidates. Not just go after top candidates, but fill reqs on time and decide, do we want to make some additional investments to go faster? Now, when you hire all these people, the number one thing you have to do is make sure that you get them to productivity faster, make sure that you get them busy fast. We've made some great progress in time to productivity for new reps because of the systematic, programmatic Go-to-Market engine. Between bootcamp ones, bootcamp twos, meaning you start, you have a certain section of knowledge that you got to acquire, then you have a next section of knowledge. It's all built in layers. The goal being, as you start, I want you busy week one, but you're not an expert week one. What are the activities that I can make sure you can do? How do I align the ecosystem to help you with your knowledge gaps? How do I build an engine that keeps revving as you keep ramping? That includes understanding, as I said earlier, from a revenue ops standpoint, volume of activity via leading indicators. We understand on a weekly, monthly, quarterly basis, and out quarters what the activities are that are going to lead to a healthy outcome down the line. What are the healthy conversions? How do we measure them? How do we impact the quality of those via the right enablement? The other thing that we're doing is making sure that our leaders are enabled, that our leaders get the proper training on how to run this system, run this model like a GM, how to ramp their reps, how to make sure that they impact the development on a most positive basis. What this means is that we've built an engine where we control all the elements within the engine, understand where we have quality gaps, and understand how to impact those quality gap s. Because in order to drive this, you have to have the right leadership team, you have to have the right revenue ops engine, you have the right enablement engine, and we have all three at a world-class level. That means as we add more paths to revenue, more use cases, more products, we simply click it into this. Nothing changes. It's just an expansion of additional areas of value for us to investigate. Every time we sit down with customers, whether it's a prospect, as I said earlier, whether it's a customer, it really doesn't matter. We have an architectural roadmap that we put together in collaboration with. There are different phases that are naturally grouped together on how we look at a customer's transformation, because we have to be prescriptive because they're asking us to be. What it also means is you're seeing the high level here. All these phases have many sub-phases of different use cases that we have helped customers solve for different problems we help them solve, different quantifications of value of those problems. What we're essentially doing is not just building a roadmap on what the stages and steps for customers should be, how we de-risk them, how we're with them step by step, every path of this journey and all their phases. Rather, we're also mapping out different points for us to upsell, cross-sell into these accounts. Now, in all these phases, there are other things that have to do that are maybe not Zscaler-centric, but that's where our ecosystem of tech partners comes in. That's where our ecosystem comes in of companies we collaborate with. We're still the core experts in helping guide customer decisions on how to transform, how to get into the cloud as fast as they can, and how to become a digital-first business. All of these phases present multiple entry points for us into accounts, and all the sub-phases also present multiple upsell points into these accounts. What this means is the following. As we see it, if we take a look at the new logo acquisition that we've had over the running quarters, Jay and Remo mentioned it in their earnings calls, last two, as a matter of fact, that our new logo acquisition is very strong. If we just look at the accounts that we have today as customers, and if we quantify bottoms up, what we think the upside is just in those customers, our math comes out to approximately 6x upsell opportunity across ZIA and ZPA alone, whether that's with additional users expanding to the enterprise on ZIA, whether that's going up in bundle height, meaning more value bundles, which we also commented more customers are starting to migrate to, whether it's including data protection, which is absolutely starting to increase in our business, or whether it's including ZPA for all as opposed to just for a sub-segment of customers realizing VPNs and firewalls are a thing of the past. It's a really great opportunity for us just in our account base, because as we mentioned, we're not interested just in selling into our account base. The entire engine that we built is structured around new logo velocity as a core element. Part of that new logo velocity also is achieved through partners. We've talked about our Summit Partner Program. The confidence is absolutely increasing across the partner community. Is the velocity, as you can see. I want to make a distinction in what we're calling out here. This is a value-based partner model, not a volume-based partner model. That means we're engaging with partners early. That means we're account planning with the most strategic partners. That means we're going after specific problems to solve specific customers, specific verticals. That also means they're making co-investments with us. That also means they're building out their resource pool. They're building practices around us. What it culminates into is deal-registered business, especially deal-sourced business, meaning partners coming to us, bringing us new logos, and then we're engaging together. This is an important lever we're going to continue accelerating on, and we're going to continue improving upon as we keep scaling our business. I'm very bullish on this path to revenue and on what this is going to mean for new logo acquisition and for us scaling our business. The other area that we're also focusing on, it was mentioned a few times, is our tech alliances. Our tech alliances at the core enable us to uniquely differentiate with our unique integrations with these partners. They allow us to gain access into different sides of the house that maybe we're not in yet. They allow us to accelerate deal cycles. They allow us to supersize deal cycles because we're part of a broader story in addition to our broad platform story. We are also not just building out our technical capabilities within here, but also have started building out a specialist team that is focused just on accelerating velocity through these tech alliances so we can add additional value and additional impact to our customers. If you take a look at how we're constructed and how we think about the world out there, our core space where we live is the majors and the large enterprise, and we've seen tremendous success there. We've seen tremendous mind share there. We've seen tremendous access to the C-level executives there, and we've seen tremendous velocity there as far as new logos are concerned. What we've also done is built out the enterprise team, and quite frankly, it's a sizable TAM. What we're finding is that this segment is quite attractive because it's coming at us. Partners are bringing it to us. It's allowing us to close deals in shorter cycles. It's allowing us to close deals with more junior resources. It's allowing us to get a much, much broader reach, in a low-cost way. It is a segment that we're going to continue investing in so that we, quite frankly, own the market thought leadership and mind share across executives and companies in what we consider key vectors of transformation. What we also discovered was that on the commercial side of the house, we saw a lot of velocity coming our way. We're not going to turn away any POs. Not just that we see velocity come our way, but we saw really partners bringing us velocity. We have a commercial team. We're being very careful about how much gets invested in there, but we are absolutely fielding velocity coming at us. If you take a look at this pyramid, what this also did for us is, this is in essence a farm system that we're building out. We're hiring people early in their career across commercial. We're grooming them to move up into enterprise, who we're grooming to move up into large enterprise, who we're then grooming to move up into majors. This has a positive impact on velocity, on momentum, and getting people game-time ready out of the gate as soon as they're promoted because they're not new to the company, know process and fully understand Go-to-Market model and value proposition for our customers. This is what drives really all of our segmentation, all of our planning, all of our strategy. We know who we are, where we're going to focus, but we're also going to make sure we capture as much of the TAM as we can in the most cost-efficient way possible. Just closing out, I hope walking through this briefly is going to give you really an understanding of how we're formulaically impacting productive capacity and the productive capacity model. If you don't know this inside out and have science built behind it, at some point it breaks. We're very confident ours won't. We are showing you how we're driving business transformation in a prescriptive way with our customers, quantifiable, competitively differentiated. We're also with that, bringing customers close to us as a trusted advisor, as their partner for their transformation at a pace that they're not accustomed to, with new things coming at them that we're expert in and they're not. Lastly, it's all culminating in great velocity around G2K. Quite frankly, all the other logos as well. Chris, sorry for probably eating into your time a little bit, but let me transfer it over to Chris Kozup, our new CMO. That's great. Well, excellent. Thank you, Dali, and thanks everybody for being here. I'm certainly very excited to be here as Zscaler's new Chief Marketing Officer. My goal in the next 10 minutes is really to talk about how we are leveraging marketing as a key driver for growth. I would say my focus primarily is in three core areas. Those areas are really how do we build awareness to open more doors through our brand, through the strength of our brand? How do we grow pipeline, and do that with a much more segmented, focused, demand generation execution? Ultimately, how do we deepen customer loyalty through a series of structured programs, specifically with the CXO audience? What I want to do now is just take you through each of these. I'm going to start with brand. Now, from a brand perspective, Zscaler has successfully established itself already as a leader in Zero Trust. Our brand has become synonymous with how we help customers really look at digital transformation, and then achieve that through a highly differentiated way, which is all about the Zscaler Zero Trust Exchange. You've heard already today a lot about that in some of the previous sessions. Now that we've proven out this brand promise and proven out this benefit for our customers, our focus now really goes to how do we amplify that. I'll say first and foremost, we have increased overall brand investment, over 80% increase year-over-year. We're really focused on a very highly targeted execution of things like advertising and search, all of the paid attributes that we can actually execute on, really targeting both CXOs, but also security architects and practitioners as well. Then, of course, as I'll talk about and Dali alluded to, we have a very strong focus on how we build our brand within the CIO environment, the CISO environment, and the CTO environment as well. It's not just about paid execution. Also, what we call organic execution is equally as important. Zscaler sits on a wealth of expertise, a wealth of knowledge. We have a great ThreatLabz team, which is our team of highly experienced security researchers. We use this information to really help guide our customers and our prospects on current and emerging threats. A great example of this is just what we've seen with respect to SolarWinds. Our focus here is how do we actually significantly increase the level of thought leadership that we're taking to the market. Harnessing the power of all of our internal thought leaders, but also using the power of all of our great customers and partners that we have with us. Tactics like public relations, blogging, and the like, these are all great things that we're spending a lot of time to amplify. I also want to call out the fact that Gartner is a great partner for us. We spend a lot of time with Gartner. Given just the transformational value prop that we have, and given the breadth of our portfolio, we actually engage regularly with over 40 Gartner analysts. That's a pretty large number for a company, certainly of our size. I think it underscores just the transformational impact that Zscaler has really across security, networking, digital transformation, and the like. We certainly have, I would say, a lot of great momentum. Sharing with you here some data points that really emphasize a lot of the growth and momentum that we've accumulated over the past year. I'm very proud to say that things like our advertising, for example, is outperforming like companies in our same industry. We've seen significant growth in the consumption of our content in terms of both our blogs as well as the number of folks visiting zscaler.com. This is really just now bringing us to this point where ultimately, of course, my goal is to amplify that even more. A lot of great momentum, but a lot of great runway for us to continue to build upon. I know you've seen this chart. This is certainly a great way that stresses the strength of our brand and the momentum behind our brand. Jay shared this and articulated that we are extremely proud to be the only leader within this Magic Quadrant. As Jay and others have touched on, this really bookends 10 years of leadership for the company and demonstrates the strength that we have in the broader Zero Trust domain. I just have to say, as a marketer, it is extremely rare to see just one company be highlighted as the only leader. It's not the first time, but it is certainly very rare. Great to see that kind of recognition from Gartner. Now, I thought I would take this a step deeper, though, and talk a little bit about some additional perspective on the strength of our brand. This chart shows actual data gathered from gartner.com, which Gartner makes public. The data shows which security vendors enterprises are coming to Gartner to get more information on. In other words, which vendors are enterprises searching for on gartner.com. As you can see, certainly the level of interest here for Zscaler is well above the other players and certainly indicates that we are definitely punching above our weight as it relates to just the demand and interest that we're seeing within the marketplace. Let me transition now and talk a little bit more about demand as the second pillar of really where marketing's focus is. Excuse me. Our focus, much like Dali has mentioned, is our whole Go-to-Market is lining up by segment, and marketing is no exception to that. Marketing is aligning very much to what we do, how we focus on building demand within our major accounts and our large enterprise accounts, and then increasingly what we're doing within the enterprise segment as well. Within the major and large enterprise market, our message here is very squarely focused on how we can help our customers secure their digital transformation. We do that in a highly differentiated way, as you've learned about already, with the Zero Trust Exchange. For these large enterprises, we lead largely with account-based marketing tactics, and we focus very much on the CIO and the Chief Information Security Officer audiences. We're using a lot of digital tools, social selling, purchasing intent tools to actually help our sellers identify the customer need and then ultimately accelerate the sales cycle. These tactics are working. We're seeing already an increase in new business meetings. We're seeing expansion in average deal size, as I'm sure many of the other folks here will discuss through this presentation. Let's build this out and talk a little bit more about then the enterprise segment. Now, our message here is focused much more on cloud security adoption, right? Ultimately, unlike the large and major enterprise segment, this segment is really much more about volume. We're expanding our lead generation programs at the top of the funnel to drive more inbound acquisition of leads and then ultimately qualify those leads to turn them into more sales meetings. At the same time, in addition to our direct motion, we've introduced new partner marketing programs, including a new partner marketing funding program, which is ultimately designed to help our partners really drive greater demand throughout their ecosystem. The net result of all of this, of course, is to see better pipeline conversion through the dollars that we're investing. Let me round out this discussion here by talking about loyalty. Firstly, I want to say that I have been immensely impressed just by the strength of relationships that we have at the C-suite, not just CIOs, but also CISOs and also CTOs. These relationships have allowed us really to drive greater reach within the CXO audience through running programs like events and networking opportunities. We've developed a number of tools to help our CXO audiences really quantify the value of their digital transformation, mobile apps, quarterly business reviews, Dali talked a lot about these, ultimately to allow all of these senior managers, or senior executives, I should say, to better manage their environment. Of course, the goal here is to increase upsell opportunities, to reduce churn within this environment. We've also really done a great job of partnering and leveraging these relationships to help drive greater thought leadership. Also reach other peer groups of our existing CXO customers. A final proof point that I'll leave you with here is that we're really extremely proud of just the fact that at our recent customer event, Zenith Live 2020, we had over 40 CXO speakers that joined us to share their experience with our attendees. In my prior lives, having just five would've been fantastic, 40 is amazing. Obviously very, very proud of that as well. Let me just close out here, and highlight again the key takeaways. First and foremost, the amplification of our brand promise is resonating, and this is leading to more at-bats with new customers. Our demand gen execution is aligning to segment, which is improving the productivity of our campaigns. Our strong relationships with CXOs, we view certainly as a competitive differentiator, but obviously is also helping us reach new audiences. That's it for me. Bill, I will pass it back to you. Okay, great. The first question would be to Dali. You mentioned a metrics-driven process. What are the key metrics for you that define success for your team? First of all, it starts, Bill, if I just take it back to the core, it starts with the team, right? Do we have the right people in the right spots? We have an incredible team in place, and it's expanding. We got to make sure we have the right capacity to drive the right volume. In addition to that, you need to start developing systems to track activity, not just pipeline. It's too late by the time you get to pipeline. We track and focus heavily on leading indicators that we can understand on a weekly, monthly, quarterly basis, because it allows us to gain valuable insight in quarter, out quarters, and most importantly, it allows us to understand how we can impact ACV and revenue growth, and allows us to impact the quality of our activities. Our employees' success, to me, is really my number one objective, and their well-being. In order to achieve that, you got to have the right training programs in place so everybody understands how to manage to leading indicators, everybody understands why they're so critical, and how to impact them. Most importantly, you got to have the development strategies in place so people can run their business like a GM, metric-centric and metrics-oriented, regardless of geographic location. High-level, this is really how we are tracking and what we're tracking as far as health of business. Okay. Next also back to you. As you've launched a number of new products, what plans do you have in place to successfully sell a broader portfolio? How do you keep sales cycle from slowing down as deals get bigger and more complex? I think we had a similar question last analyst call where the question was, hey, if you have a sophisticated go-to-market framework, does that not slow the sales cycle down? I think we've proven that it doesn't. The sales engine that we've built, the go-to-market framework that we have built is focused on selling outcomes. We solve problems for customers based on what's in our portfolio. Quite frankly, customers are looking for a partner to help them solve problems at a broader scale. As we add more solutions to our portfolio, as we add more capability to our portfolio, our motion doesn't change. We still drive outcomes, we still solve problems for customers, we still have an ecosystem that surrounds the rep and the SC so we can have meaningful, impactful conversations with customers regardless of tenure of that rep or that SC. If you look at it from this standpoint, CXOs today have cost pressures. They need the tools consolidate. They need to figure out, how do I get into the cloud faster? How do I transform faster? We have such broad capability, and the broader it gets, again, our motions don't change, Bill. Think about it. Yeah. Bill, if I may. Sorry, Jay. I was going to say, the North Star at the core of everything we're doing is the Zero Trust Exchange, and our products are all developed to be delivered over a consolidated, synergistic platform, as Amit alluded to earlier. We're purpose-built for the cloud, and quite frankly, we're not glued together like some of those other legacy players out there, and it really shows in our conversations with our customers. Sorry, Jay. No worries. If I may add, if our sale was geared towards technical audience to start with, generally technical audience is smaller sphere of decision-making influence, then trying to sell a broader portfolio will be much tougher. Our three biggest CXOs who are involved in Zscaler, CIO, CTO, who is often head of infrastructure, and CISO, they have a broader span of control and decision-making. In fact, it gets easier. When we start a discussion in area A, they'd say, "Oh, can you help me in area B?" That's where a lot of these discussions have taken us from ZIA to ZPA, now they're taking us to Zscaler Cloud Protection. Transformational C-level involvement is helping us actually make it easier to sell the broader platform. Dali, beyond capacity adds and some of the tweaks down market and onboarding, where does the incremental innovation come from? In what ways do you continue to elevate your game? If you look at our model and if you look at our lifecycle engagement framework and what we discussed, it was built for continuous evolution. It was built for continuous upleveling. The playbook that we use today gets evolved six months from now. The next playbook we use tomorrow gets evolved the day after tomorrow. We've built a scalable programmatic engine that allows us via enablement and via revenue ops, not just to understand where we are, but to understand what tweaks we have to do, and then we have the arm to deliver those tweaks. Bill, as we keep going, as we keep evolving, and as we keep driving more value to our customers, we're just going to continue scaling on the foundational elements that we just put in place over the last 12 months. Great. Moving over to Chris. How would you define success as it relates to your efforts with brand building? Well, the first thing I would say, Bill, is that it's never really over, right? We will be always focused on building our brand. I would say that the biggest thing for us is to be recognized by customers without necessarily being prompted as a leader in Zero Trust, right? That is the primary focus that we have. Obviously, having our customers and prospects and the market, in general, recognize that the Zscaler brand is synonymous with Zero Trust, and then also is a necessary catalyst for digital transformation. Those are really the two bellwethers that we'll use to really evaluate the progress that we're making on brand building. On channel, how many channel partners do you have? What is your target number of partners? Bill, as I alluded to earlier, our channel model was built for quality of partners because it's value-based, not volume-based. Think we're looking to deeply engage with key partners. In totality, we have about 700 partners right now. I'd call them 200 focus partners, and I'd say there's about 20 strategic partners. Within that model, if you conceptualize it, there's really three different layers for a strategic partnership and how we engage. Number one, close collaboration, meaning account planning, territory planning. We do that together with these partners. The second element, and this is really a critical one. We're engaging early, not just once a sales cycle is in progress, but we're engaging early and together mapping out who can we help, who can we impact, who is an ideal prospect for us to go after together so that both of us, the partner and Zscaler, can get maximum thought leadership from that entity. Then, of course, with the strategic and focus partners, there's different levels of investment that is required. Based on the investment they're making, they also get different levels of reward based on the execution alignment that we have together. In a nutshell, we're really looking for focus and cloud-native and transformative type partners. The box selling days, I believe, are either coming to a close shortly or shortly, plus a little bit extra. It's calling an entire partner community to have to shift in how they engage and how they drive value, and we're the super highway to do that for them. That's how we're engaging. I hope that answers your question. Yeah. Hey, Dali, if I may add, a number of partners were hoping that the box days will never be over, are realizing that actually it is happening. We are getting more and more inbound interest from partners, and we are being very selective to make sure partners who are interested in transformation solution led sales rather than pushing boxes, those are the ones we really engage and spend time with. It is helping. The one who were slow six, nine, 12 months ago, now actually waking up and making calls to us. Agreed, Jay. This could be for Jay or Dali. What are you hearing right now in terms of reasons customers are accelerating the decision to dive in with Zscaler, but also maybe reasons they might defer? How is this changing from maybe six or 12 months ago? You want me to go first? Dali, you want to start? Yep, please. Yeah. Please do. Here's what I'll tell you, and it's interesting. Was COVID an accelerant? Is SolarWinds an accelerant? What just happened in this market, this is a permanent shift. This is not a temporary blip. What just happened is that the CEO business side of the house turned to IT and said, "I need you to be agile. I need you to get me into the cloud as soon as possible, and I need you to help me transform. I need you to do it in the lowest risk way. By the way, it needs to include network, it needs to include security, and includes also application transformation." Bill, we're the only entity that's purpose-built to do this. We just rolled out, we have a model that helps customers accelerate into this. It is no longer an option is what we're seeing. The evangelical conversations that we maybe had a year ago around cloud transformation and how it's defined, around Zero Trust and how it's defined, those are business conversations today. We're enabling IT organizations to drive quantifiable, meaningful business impact in a very short period of time. That's what I'm seeing on a broad level. Great. Yeah, if I may add a couple of points. I think the biggest change that happened in the past year is the mindset change. With COVID-19 and everyone had to work from home, the CIOs generally realized that some of these things can be done at a faster pace. You know, many CIOs used to think that they need to transform the network from hub and spoke to go direct. They found in COVID-19 that everyone worked from home, they didn't even need to touch the network. They could simply just go direct from wherever they need to go. They suddenly realized that the inertia that is holding them back from doing these projects is no longer a bottleneck. They also realized that transformation, digital transformation, cloud adoption, had to be done at a faster pace because the companies who were far ahead, they fared better than the companies who are not. Increased digital transformation, acceleration, and the mindset change where they're finding that things can be done and learning that the Zero Trust Exchange can actually help simplify stuff. That's what's keeping us busy and accelerating our business momentum. Great. Let's move on to our final presentation. Before we do that, let me recap what we've covered so far. We feel we have the right product. We're rallying behind an audacious goal. We have the ability to execute. Now we want to talk about our big market, the investment for growth that will pay off because we have great unit economics. When we went public a little less than three years ago, we talked about disrupting the legacy approach of network security. There was $20 billion that we attributed to spending on these technologies, mostly hardware appliances. That's what we're disrupting. This was never exactly our TAM. We passed on that at the time. We don't do network security. We're doing a new thing. Today, I'm pleased to have Remo talk about a bottoms-up view of what we believe is our serviceable opportunity with our approach and with our business model. Again, this will be a bottoms-up TAM and what we can generate in revenues for each of our products and the market segments we target. With that context, I'll hand over to our CFO, Remo Canessa. Great. Thank you, Bill, and thank you everybody for being here. As Bill mentioned, it's a very large market opportunity, a lot bigger than what we anticipated before we went public, and I'll go through the numbers with you in a few minutes. Large land and expand net retention rate, 120% last year, 122% this last quarter in Q1. Subscription model based on per-user pricing and per workload, which gives us good visibility into revenue as the revenue's recurring. We talked about the large market opportunity, and that we're going to invest in this market opportunity. Also, the attractive unit economics where the land is more expensive and once you have a customer, then the unit economics become much stronger. Also the long-term profitability getting to 22% in fiscal 2024, which is what we're expecting to do. If you take a look at our annual pricing model, just to give you context, it's for users of 5,000 users, for ZIA. We sell in three bundles, Pro, Business, and Transformation. The pricing at the high-end bundle is $45. In addition, ZIA add-ons is about $30. That includes CASB, data loss protection, and browser isolation. ZPA is similar to the pricing for ZIA. At the high end, about $45 per user. ZDX is relatively new, what we're seeing in high volume type purchases currently is about $25 per user. For ZIA, ZPA, ZDX, for 5,000 users, $145 per user. What we talked about also is with workload protection, Zscaler Cloud Protection, relatively new. We are selling CSPM, we are selling workload segmentation. I want to make sure you understand also, these are net prices to Zscaler. These represent average revenue per user also to Zscaler. CSPM and workload segmentation, for higher volume type deals, we're seeing $40 per workload for CSPM and $60 per workload for workload segmentation. Workload communication is brand new, and it's just starting. A lot of conversations with customers, we're expecting about $55 per workload for workload communication. The workload protection part of our business, we're expecting $155 per workload. When you take a look at our serviceable market, the market we're going after, we're going downstream. We're going downstream more, as Dali talked about, down to that 2,000-employee company. There's about 20,000 companies like that. That serviceable market is 335 million users. That's what we're going after. Having said that, the incremental users, the ones below, which we call commercial, below 2,000 employees, is 267 million users. The strength of our platform, there's no reason that we can't go after that market. That market's coming to us. Our total of our employees, or our revenue for commercial, it's about 10%. It's not significant. It's 90% in our serviceable market and about 10% in that commercial market. There's no reason that we can't go down into that market. Our platform works just as well for a company of 1 million users versus a company of 10 users or 10 employees. In addition, we see a potential B2B users of being around 600 million, similar to the number of employees in the company. These are third-party vendors and customers of customers. This is an early-stage market. It's relatively young. Companies are hiring chief digital officers. This is certainly a market that we can go into in the future. We're making investments. Investments are being made in these markets. From a workload, OT, IoT device basis, the serviceable workloads are 150 million serviceable workloads, and that represents the workloads from the top public clouds, the AWSes, the Googles, and the Azures. That is our focus. Our focus is to go after that large public cloud workload market. In addition, there are 338 incremental workloads. Those are hybrid clouds and other clouds. Something we can play in also, something that we can tap. OT and IoT. Billions of devices interconnected, going back into data lakes, making decisions. That is the market also that the advantage that the Zscaler's created, and people have touched on it, and Patrick really touched on it, which is Zscaler built its own TCP stack, purpose-built for this market. Built the platform to expand in many different directions. You can see with the ZIA, ZPA, ZDX, and ZCP, the platform is expanding. It's integrated. It is multi-tenant. It is across 150 data centers. It is a single pass technology. It is proxy based. It is Zero Trust, and we have 80% gross margin. It is absolutely incredible. This is moving, Bill. Let me see if I go back. When you look at the serviceable market opportunity that we have, and if you take the $145 average revenue per user times the 335 million users, that's $49 billion. If you take the $155 per workload times the 150 million workloads, that's $23 billion. The serviceable market that we're going after is $72 billion. As I mentioned, the long-term opportunity is much greater for Zscaler. Some of the numbers. Customers, we've talked about that our customers are getting bigger. You can see from this slide, in fiscal 2020, customers of ARR of 100,000 or more was 973 in July. As of October, this October quarter, it was 1,057. Customers of greater than 1 million ARR has gone from, you can see, from 108 in July to 120 in October. Again, acceleration we're seeing related to bigger deals. If you look to the right and you look at for ARR of 100,000, you can see the customer count, the customers who have transformation, it is increasing. You can see data protection is increasing. You can see the count of customers with ZPA is increasing. All indications that we're moving the embracement of companies related to the digital transformation. The embracement of our platform, and really being a platform to really service the needs of companies' security and networking needs. G2K customers, we've talked about over 450 at the end of fiscal 2020. You can see the average ARR per G2K customer year-over-year growth, as we talked about, continues to grow, $572,000 per G2K customer this past year. Net retention rate, strong, as I mentioned, 120%. The positives to the net retention rate's going to be new products. ZPA, at the end of Q1, was 13% of our revenue. We are seeing acceleration in ZPA. That is an add-on. All the new products that we have. That'll contribute to it. The negative part to the net retention rate is if as customers buy more upfront, which we're seeing, as well as if purchases are done within the year. The way we calculate it, could have variability. We're proud of this net retention rate, and you can see also the cohort basically being strong. Re-acceleration in billings growth at 64% in Q1. New and upsells historically were 50%-60% new. You can see in fiscal 2018-2019 we were, fiscal 2020, we were not. Fiscal 2020, we weren't primarily related to COVID in Q3, related to existing customers who basically bought ZPA. ZPA, as a percentage of our new and upsell business in Q3, is 43%, largely to existing customers who had to give their employees basically the ability to access internal applications. Q1, back to our historical rates, at 52%. You can see the ZPA broader adoption from 10-14, 29 last year, and it was 27% in Q1. If you take a look at our revenue, it's consistently been 50/50. Significant basically is that when Zscaler, which is interesting, not interesting to me, but it's a great thing that Jay did. It truly was a multinational company from day one, when it was a very small company. That is a cultural change. That's something cultural. You take a look at what Jay presented with Glassdoor and how people within the company work with each other. That's not by accident. That's the culture that's been set up in the company, and it's across the world in every organization and the culture is the same. As I've traveled through the world talking to employees, it is really a significant strength of Zscaler. As I talked about cost of sales, gross margins at 80%, it's the multi-tenant architecture that's purpose-built for this world, which gives us the ability to expand. Amit talked about the ability to add additional applications and features and services at lower cost because it's all going off the platform. We've talked about the accelerated investments on prior calls. It's just a huge market. We're seeing the market come to us. We are enthusiastic and really excited about our prospects, so we're going to invest in it. Hiring last year, as we talked about, for quota-carrying headcount last year, 60% growth in fiscal 20. We talked about that we're going to continue that into fiscal 21. We didn't give a percentage, but we did say it'd be substantially higher quota-carrying headcount. As Jay mentioned, we've increased it since then. With Chris on board, marketing, there's really three legs of the stool when you think about the go-to-market. It's sales and go-to-market with Dali's group, which has done an absolutely outstanding job. Channel, which we're working on right now. Now with Chris on board, marketing. We'll be making investments in marketing in channel also. R&D, eight R&D centers throughout the world. Follow the sun type R&D efforts. 15% was R&D. We'll probably get that up a little bit. We are a technology company. We're an innovation company. We will continue to invest. G&A, 9% and significant presence in finance. About 80% of our finance organization is in India. Medium-term model, no change. We had before, 78%-82% gross margin target in FY 2024, 32%-36% sales and marketing, 16%-18% R&D, 8%-9% G&A, 20%-22% non-GAAP operating margin. The free cash flow a couple of points higher than the non-GAAP operating margin. In summary, the takeaways, $72 billion serviceable market, which we did a lot of work to take a look at. One of the things that Jay talked about, which I didn't have an appreciation before, and he's talked about it several times, is if you take a look back in history and you look at the horse and buggy, and if you try to extrapolate what the total addressable market is for the automotive industry, and if you took horse and buggies and multiplied it by some number, you would have been drastically too low. That's kind of what we're seeing right now in the market we're addressing. The world's changed. It's really changed significantly. Employees are mobile, applications are everywhere, and the infrastructure that's been created was created for a different type of network. It hasn't really changed, and it's going to be tough. What Zscaler's done 12 years ago, as Jay mentioned, it skated to where the puck was and really built this purpose-built platform to really, in my opinion, have a real opportunity to exploit this market. With that, I'm going to turn it over back to Bill. You can see the other things, all the same things that I covered before. Back to Bill. Okay, great. Thank you, Remo. The presentations are now available on our IR website. If you want to take a look at that and look at it while we transition to interactive Q&A session. I'm sure you have a lot of questions regarding that information that Remo presented. Before we do, we'll take a quick five-minute break. We'll see you shortly. Okay. Thank you, and welcome back. Now we'll start our interactive Q&A session. We'll take our first question from Brad Zelnick at Credit Suisse. Brad? I'm trying to start my video here, Jay. Can you guys see me? Yes, we can. Yes. Hey, Bill. Great to see everybody. Thank you so much for a really comprehensive set of presentations this morning. It has really been a great day. Remo, I just wanted to start with you and ask about the build-out for your TAM and pricing assumptions that are in there. What's a practical way to think about discounting assumptions over time, and what have you experienced in terms of average discount trends to date? Yeah. Average discounts per date, there's really not much change that we're seeing. Pretty consistent with what we've seen before. If you take a look at our audacious goals, 200 million users and 100 million workloads, and you do the math based on the per-user pricing, it's about a $45 billion market. Not market, it's $45 billion revenue, for Zscaler. As Jay mentioned, there is going to be competition as we go. It's going to happen. It's just too big a market. What's interesting, Brad, is that four years ago when I talked to Jay, I thought, "Wow, what a great opportunity." Now looking at how the world's changed, it's just a much bigger opportunity. Even if you take 50% of what we talked about, we're still a $20, $25 billion company. Is that reasonable? The key thing is the platform's been created. It is purpose-built from the ground up. Nobody else has it. You take a look at legacy guys, they're trying to retrofit it. It's tough. They're going through a public cloud. We're cloud agnostic. We don't care. We're Switzerland as Jay mentioned. We have the ability, because as Amit talked about, to put additional applications on at a very fast pace. You can see, Every acquisition we did is doing well. Cloudneeti with CSPM, Edgewise with workload segmentation. We did a small AI/ML company acquisition, which is doing very well, and also Appsulate with browser isolation. We have the ability to integrate products into our platform, because the platform's been created. It's a huge advantage, in my opinion. If I may add one thing, Brad, related to your question on discounting. Our price per unit per year has been going up. Actually, it has been going even faster in the past 12 to 18 months. We are seeing an opportunity to grow price per unit rather than thinking that things will be discounted. We think we have a pretty good runway because of the difference in offering a true Zero Trust solution over someone else. The market keeps on moving at a faster pace. Someone tries to come and build what we have in two years, the market will be very different in two years. If we keep on innovating and keep on driving our go-to-market execution the way we are, we think we're in a very good position. Great, guys. Can I maybe just chime in with one quick one for Dali? I don't know, Dali. Thank you so much, Bill. Dali, fantastic presentation. I think I heard you say the word confident several times, and really so much that we heard from you today that just makes a lot of sense. If there are any possible constraints, to the old question of what keeps you up at night, what is it that you see that every day you're really focusing on and managing to when you think about even just the market's ability to absorb everything that you're delivering and anything else that you think about that may potentially you have to manage through to constrain or work through? It's a fair question, and I think you've heard Remo on the calls mention we're accelerating, we're going faster. We have a really good model in place internal in deciding as a team where we want to make investments, then putting a very quick analysis together on what the impact is of those investments. Right now, between the exec team really being on the same page and us understanding where to invest, how fast we can go, I don't see any limitation, that maybe a traditional go-to-market engine would see constantly arguing with CEO and CFO over more money, because it usually comes with a plan of what it's going to yield. The only area where I think we can go faster, I'm going to flip it around. Everything keeps me up at night, which is much to the dismay of my wife. That's how my mind works, because I'm constantly trying to figure out what else, what's next. Then we go to it. Having a really strong leadership team in place that runs the playbook with excellence allows me to step outside of operator mode and think about four quarters, six quarters out, have the conversation at the exec team, and then build a plan backwards how we're going to get there. We've been doing it. Right now, we're going as fast as we can across every vector, and the one area where I think we can go faster, that's the demand gen area, where I think Chris is going to have a really big impact as we're building that out. The channel is starting to click. All the elements are starting to click. The down market is starting to click. We're going to just continue accelerating. Right now, everything keeps me up at night, but I'm not panicked about anything, and I'm not trying to skate around your question. I'm just being direct, actually. Appreciate it. Thank you guys so much, and congrats. All right, great. We'll take our next question from Hamza Fodderwala at Morgan Stanley. Hamza, if you could turn on your video, please. Unmute. Thanks. Can you hear me okay? Yes. Okay, great. Thank you guys so much for taking my question and great presentation. A lot of good details there. I'm wondering, as a follow-up to Brad's question, just around how you guys came up with some of the price points for the workload opportunity in particular. Was there any sort of haircut or estimate that was assumed to reflect how much of that opportunity would be serviced by the existing public cloud vendors? I understand, obviously, you guys have a very core strategic focus here, but there's probably going to be some share of responsibility between you guys, AWS, Amazon, or excuse me, AWS, Microsoft, and Google. I'm wondering if there was any sort of share or estimate that was assumed around that. Hey, Bill, do you want to answer that part? Why don't you start with his direct answer, and then secondly, maybe Jay or Patrick could talk about share responsibility with public cloud providers, please. Yeah. The pricing for CSPM at $40 and workload segmentation, those are deals. Those are actual deals of decent size volume that we're seeing. That's where we think the pricing. That's what we think we're going to get. Workload communication, that's a potentially big market for us. If you think about it, protecting workloads no matter where they go. That's just starting with Cloud Connector. That's the type of pricing we're discussing with customers. These prices that we put out, they're real. Again, these are net prices. For ZIA and ZPA, those are the prices that we've talked about, 4,000 or 5,000 users. Those are actual prices. Even in cloud protection, as Remo said, workload segmentations, which came via acquisition of Cloudneeti, we further integrated CSPM which came through acquisition of Cloudneeti. We have been selling real data. Workload segmentation, it just got launched. Just to let you know, we are engaged with over four dozen customers, and there are lots of pricing discussions that have taken place. The data is based on real data we're seeing from our customers. The second part of your question is, yes, could other cloud provider vendors could take a piece of the market. When we compute TAM is based on total workloads based on our pricing. If we got that, what would the TAM be? Obviously, if we got everything at the current prices, we'll be doing $45 billion per year. You can do it from haircut and say, if they don't do all the stuff, what would that be? That's where Remo gave an example that if we got half of it, we're sitting in the $20 billion-$22 billion range. I think that there are some very interesting pieces. If you look at the big cloud vendors, I do believe they'll have pieces where they can do stuff on their own. When you need to support multi-cloud strategy, do I want security posture of just my AWS workload, or do I also want my Azure and Google Cloud workload as well? That's where our position comes in. Especially if you look at the workload communication with the story that Patrick presented, we think it's so disruptive. It's so cool. It's almost like ZPA. When customers saw ZPA for users to application, they kind of said, "Wow, huh? You mean without my network, without getting on my network? You mean I don't have to have a network?" It's the same thing where your workloads are talking from Azure region east to region west to AWS, wherever. It just becomes so simple. That's what makes us so excited about the opportunity. I do believe that these kind of opportunities won't be spread between 15 vendors. Even if you saw the firewall market, it has been scattered kind of all over. If you look at the proxy vendors, Blue Coat dominated in the high end and so on. You look at the cloud vendors, after these three mega vendors, there isn't much out there. Same way we think the ADCs, where we are doing it with Zero Trust, we should be able to command a very good market share. Maybe just one quick follow-up, if I may. You guys give a lot of details around sort of the TAM opportunity, and obviously it's quite sizable. One of the things that was missing was sort of how you're thinking about sort of long-term revenue or long-term revenue growth. Any reason why maybe that wasn't included for this Analyst Day, and are there any sort of growth levels that you are looking at over the next three to five years? That's about it for me. Yeah. I don't like doing that, Hamza, let me just say a few things. I know the analyst models out there, I think they're 30%, 31% CAGR. Let me just say I'd be disappointed if we're not at that level. I don't want to be making projections. For the guys who've known me for a long time on the call, I'm very conservative, and I want things to play out. It's a huge market opportunity for us, it's really going to come down to our execution. I think Dali said it right, that this is really the best, by far, management team I've been part of in my career, by far, not even close. The way we work together and how we make decisions, and it's business-oriented. Let's see how we go. Like I said, if we're below where the analyst projections are for the CAGR through fiscal 2024, below 30%-31%, I would be disappointed. Okay, great. Thank you. Moving on, our next questioner would be Walter Pritchard from Citigroup. Walter, if you could turn on your video and unmute. Hi, you hear me? See me? Yes, sounds good. All right, great. Just following on the workload protection part, I think this is a newer part of your efforts here. How do you think about the differences in ability to penetrate the cloud native, 150 million workloads versus, I think you talked about 330 something, 340 that were hybrid and other. From an architectural perspective, I guess your strength has not been the presence on the workload. How do you think your, not necessarily having the presence on the workload, but having other things that sit around the workload are going to enable you to take share? It seems like that's what we need to believe to sort of get to meaningful share of those hundreds of millions of workloads. Right. Let me try to give you a view of this workload market requirements. There are actually two clean segments. There's a micro-segmentation piece that people are trying to solve, and there's an overall communication across multi-cloud, multi-region piece they're trying to solve. We believe while the micro-segmentation market requires some level of education and it's a little bit more sophisticated, probably a little bit out there yet. The market for my workloads in AWS East Region needs to talk to my workload at AWS West Region or AWS Asia Pac. That market is ready today. The reason we know about it, because we're talking to the same CIO and head of infrastructure who is trying to build a network security model where they're trying to connect east to west to whatnot. First of all, using traditional network security model that Patrick clearly showed in those diagrams. We are getting pulled into say, "Why can't you deliver this to me sooner and sooner?" That discussion is going on for the last one year. We have the product ready. The customers are calling us, they're seeing it, so we're working with it. It's not some new product going to new customers who talk about it. It's customers who are working with us, who are pulling us in and really showing us that with the Zero Trust, they don't have to do anything. Otherwise, you're seeing a pair of virtual firewalls here, across the board, and it's a site-to-site VPN and whatever like. All that goes away now. It all becomes a very simplistic model. That's what's appealing to the customers. That's probably the fastest growing market I would think we'll see in the workload security. Got it. Just to add onto that, just to make sure I understand. I think you have some of your competitors sort of going at it, have a product for serverless, they have a product for containers. It's sort of a bit of a cover every type of cloud workload. Is it your view, Jay, that you don't need to necessarily have something specific that would cover each category workload? It's kind of higher level that covers segmentation and communication. Yeah. Two things. When we're doing segmentation, in fact, with our workload segmentation, we do have an agent that needs to go on the workload too. That's one level. When you talk about workload communication, where we're using a Cloud Connector offer, I don't need to be on a workload, on a serverless or container. It doesn't really matter. Cloud Connector is a traffic cop. You have a pair of Cloud Connectors for a given VPC, and we can handle all traffic, and traffic can be sent to where it needs to go to. If it needs to go to internet, it gets sent through the ZIA policy engine. If it needs to talk to another workload, it gets sent through ZPA. For workload communication, we don't need to sit on each workload. We are sitting at one place for each VPC, acting as a traffic cop. That part is very simple. The other one you talked about is actually workload segmentation, where we need to sit on along with the workload, which is kind of our Edgewise acquisition, different layers. Walter, if I may. Another way to look at it is, we're not an endpoint security company, right? We integrate well with CrowdStrike and Microsoft. Yet, what we do is we have a small agent, the Client Connector, that allows users to securely communicate with internet-based applications as well as private applications, right? If you replace the user with an app, right, or a workload, it's the same exact concept. If you are an endpoint company, well, you'll try to take your endpoint AV security and try to put it on a host running in Azure or GCP or whatever. We look at workload communication as one entity talking to another entity going through the Zero Trust Exchange. Just like we are able to do it for users want local internet breakouts. Users want Zero Trust connectivity to apps. Similarly, workloads want to do the same thing. It kind of dramatically simplifies the design as you migrate applications to the cloud. That's one piece. The other piece I'd say is the posture management is, again, you don't need to get onto workloads. You need to work with APIs that cloud vendors provide. If I am on AWS, I'd like to know if there are open S3 buckets or maybe some inbound policy that allows access, right? All of those things can easily be found using APIs. That's what we do with our security posture management, which is here and now. Great. Thank you all. Thank you. Next, we'll be taking questions from Sterling Auty at JPMorgan. Sterling? Yeah, thanks. Hi, guys. Wondering, within the context of the long-term gross margin target that you've given, plus all the goals that you've outlined today, how should we think about the pace of investment that's going to be necessary in your infrastructure to give you the capacity to support those growth ambitions? I'll start it, and maybe, Jay or Amit, you can go too. From my perspective, I still think, Sterling, related to capital investment, high single digit of revenue. I don't see much change. I think the efficiency that we've created and will continue to create, I think will allow us just to stay at that type of level. Related to infrastructure and cloud operations, really not much change either. We've got a very strong cloud operations group with a lot of automation, which we continue to build automation. Getting that 78%-82% margin, the thing we talked about was that as we bring on new products and as we want to get them to the market quicker, we may have them in public cloud, and public cloud margins are lower. They're 20%, 30% lower than what our margin's. Our plan is to move those products onto basically our cloud, and then the margins will go up. I think that 78%-82% is a good target range, and investments related to it, I don't see much change to what it is now. Sterling, if I were to add, if you asked me this question four or five years ago when I was doing 5 billion or 10 billion transactions a day, I would be trying to wonder about it. Now we're seeing that every 20 months we're doubling. Going from 75 billion to 150 billion, you're talking about big scale. In the past four or five years, we're seeing that we can scale with the kind of gross margins you're talking about. With the CapEx and gross margin, Remo has given the range. We're comfortable with that in coming years. Yeah. One more thing I'd add, Sterling, is I talked about that multi-tenant architecture, right? At 150 billion transactions a day, multi-tenant, what does that mean? Think of it as a high-speed rail system. Right? I can transport 1,000 people very efficiently as opposed to 1,000 people being in their individual cars and trying to go from here to there. Right? It's a super efficient model. 50% growth is about doubling footprint every 20 months. Even if we double every year, it's three to four years before we get to 10X scale. Right? Do we have a path to 10X scale? Appsulate. We're working on it. Right? We have the ability to take what we have built and 10X it in the next three to four years in terms of utilization. The vertical scaling that we've added, I showed you some data points, and the ability to horizontally scale it with automation, with operations is all there. What gets me more excited is that the unit economics, both from ops perspective as well as supportability perspective, go down. We have very good data points that we shared with you as this continues to grow. Makes sense. Thank you. Okay. Next, we'll go to Alex Henderson at Needham. Okay. I think I've got it open. I appreciate the opportunity to ask a question here. I was hoping you could talk a little bit about when you win cloud workload protection type business. Is it a necessity to have ZIA, ZPA sales first, or are you able to sell the cloud workload protection independently of selling ZIA, ZPA? To what extent does that slow the ramp of that business? I was hoping you could talk a little longer term, how long do you think it will take for the company to get the cloud workload protection to, say, 30% of the company's revenues? Is that a three to five-year process, or is it a much longer process than that? I'll answer the first part, and Remo can cover the second part. You don't have to have ZIA, ZPA to sell cloud workload protection. It's natural for us to deal with existing customers with so much loyalty out there. In fact, a number of deals we have closed for CSPM and workload segmentation have not been our customers because before we acquired these two companies, they actually were already working on some of the customers out there. You're likely going to see a majority of the revenue coming from customers first, and there will be some incremental new logos as well. Remo, second part. Yeah, it's going to take longer, Alex. You take a look at the maturity that we have in ZIA, ZPA. They're humming, right? It's the strength of the business. The workload protection earlier, we talked about this year that we expect our new products to contribute mid-single digit new and upsell. It's going to take longer. Now, having said that, you take a look at the opportunity that we have in workload and IoT, OT, and with the platform that's been created. We can go in those incremental workloads as well as IoT, OT market. It's really what it comes down to. It is such a big market. We have the platform to really exploit it, but you got to pick your spots. Our spots now are basically companies that are greater than 2,000 employees and the large public cloud type workloads. As we go further, and if we do have continued acceleration on the top line, we're not going to be short of investing. One last question, if I could. How much of an advantage is it having both ZIA and ZPA and the workloads tied together when you compete in the broader marketplace? I don't think any of your competitors do both. That is correct. I think when our customers who already have ZIA or ZPA, they see our workloads communication, which is built around Cloud Connector, they're going to say, "Wow, this is a no-brainer for me." When we're engaging with those dialogues, they don't really say, "I am going to look at competitor A or B or C," because they know there isn't any. If you look at the three segments of cloud protection, there's CSPM. Yes, that's a market out there. We'll see competition. Workload communication with Cloud Connector, very unique out there. Workload segmentation, which came through acquisition and then got embedded in our platform. It's pretty unique as well. Thank you very much. Okay, thank you. Our next question will be from Brian Essex at Goldman Sachs. Brian, if you could turn on your video as well. Dan, you stopped it. There we go. Great. Thanks for taking the question. Can you hear me okay? Yes. Great, thanks. Dali, thank you very much for the pyramid and go-to-market strategy. That was super helpful. I guess I wanted to ask, as you look to go down market, how do you think about the trade-off in unit economics? Do you happen to have an indication of how much of your installed base each of those cohorts represents? To the extent that, would also love to get some insight from you is, as you go down market, I would assume that you might have lower attach rates, but is the velocity of your go-to-market strategy enough to accelerate your revenue as you go through that process? Yeah. That's a lot of questions in one, so let me parse it apart. Our focus is large enterprise and majors because based on what we're seeing out there isn't a story, a true story, once proven via use cases out there, to ours. If you take a look at then the down-market economics, our investments on the ecosystem, on demand gen, we're absolutely very scientific around investment to dollar gain to cost. Okay? We're not going to sway off of that. I think to clarify, the down-market velocity is coming at us, and if it's coming at you, naturally, the unit economics are going to be pretty good because the investments you're making with the surrounding ecosystem don't have to be made. This is also where I think Chris and team are going to start really pumping out the low touch, no touch demand gen. The channel is already doing it. What I'm saying to you is, we're not going to forget who we are and where we operate and where the biggest TAM is and where the biggest attach rates are for upsell, cross-sell. We've built an infrastructure to really accelerate into it. At the enterprise level, as I alluded to, the sales cycles are shorter, and the teams across enterprise they're smaller for our customers. They actually have less expertise sitting in-house, hence, they need a true automated cloud-native solution to eliminate the human capital that they would need to have to either deploy or manage legacy infrastructure. That velocity is starting to come at us because they're pivoting and saying, "I need 30 people's worth of work, and I only have 10 people." Right? We're going to continue taking advantage. We're going to leverage channel. We're going to leverage demand gen via marketing. We're not going to go after with calories that should be expended upstream. We're building out the distie models. We're building out additional partner models. We're building out additional demand gen campaigns via web and other strategies. It is a natural progression into those market with low touch to no touch while grooming the next batch of salespeople that we can then productively elevate up into higher quota-carrying positions. We're quite methodical about how we're looking at this, so we don't sacrifice velocity for gross margins. Got it. That's helpful. Thank you. Okay, great. Next question will come from Andrew Nowinski at D.A. Davidson. Andrew? Great. Thanks, guys, a really nice event today. Maybe if you could just start with a quick clarification. You guided $608 million-$612 million for FY 2021. I'm wondering, now that you've done the bottoms-up analysis on the workload protection segment, what% of revenue do you guys assume from that guidance is going to come from workload protection? Not much. Again, it's ratable, right? It's just new and upsell business, mid-single digit. For all our new products, it's not going to be significant. What we're seeing, a lot of interest. It's positive, it's very positive, but I wouldn't expect much this year. Okay. I think if I may add, if you look at the history of ZPA, there's so many skeptics of ZPA three, four years ago. Will it not, right? It took time. We went from zero to about 3% or 4% of new ACV to 10% to whatever, 16% to 28%. We think that this new area has a potential to really do that kind of stuff. We're not trying to forecast, but we've done it once, and we think we can do it over and over. Makes sense. Given your discussions that you've probably had with CIOs, have they reprioritized their spending for 2021 versus maybe their original plans that they had or that they were thinking about at the start of the budget planning cycle in early December, following the SolarWinds attack? If so, what have they told you that they're going to focus or try to reprioritize their spending on this year to avoid becoming the next victim? Absolutely. SolarWinds has shaken up lots of CIOs and CSOs. I mean, it has bigger impact than probably the past many. When Equifax thing happened, we kind of said it is them. Now everyone thinks that, is it me or not? You really think about how do you fix it. Everyone tries to claim that they can do the pieces out there, and there's no one piece, they're multiple pieces. I think I am surprised and happy to see that not only CSOs but CIOs are actually talking about Zero Trust implementation. They do understand that putting people on the network is not a good thing, and discussions with us on Zero Trust implementations have picked up, and have picked up much faster than they were before. Great. Thanks, guys. Okay. Thank you. We'll take two more questions. Next question's from Fatima Boolani at UBS. Fatima. Hello, team. Thank you for doing the session and taking our questions. Dali or Chris, either a jump ball for you. As I think about the distribution strategy and the product and packaging strategy that you have in place for both ZIA and ZPA and now ZCP, I'm wondering what the thought process has been around continuing to keep a discrete set of capabilities as add-on functions. So I think Remo alluded to sort of a bucket of $35 per user in terms of being able to sell CASB and browser iso and DLP. I'm curious what the thought process and strategy is, in keeping those discrete and why not roll them into the rest of the portfolio and just make it more elegant for customers to adopt in a bigger and more comprehensive way. And then I have a follow-up for Remo, if I may. It's a bundling question. Maybe I can start with, and Dali, you can add to it. The question is what we bundle and what we don't bundle, and how do we change bundles, right? Our fundamental principle is when we bundle things together, it gets easier to sell. There must be a broader demand for most of the products we put in that bundle. We learn, we go along and say what bundle needs to be. You've seen us evolve our bundles. Business bundle used to be the bundle. Transformation bundle didn't exist, and we want to wait till we knew there's enough demand for cloud firewall, cloud sandboxing to be really put in the bundle. That's how those things are. Now you see our transformation bundle has become the biggest one. We are clearly watching the market demand for data protection and CASB types of, which is a bundle by itself. Data protection is not one product. It's our DLP with advanced DLP with exact data match, it's browser isolation, it's CASB. It's a pretty hefty bundle. We have taken and added a number of DLP modules in our business bundle and transformation bundle. They're not advanced features, but they get you started with that. As time matures, you can expect us to keep on adding and changing bundles. We have been changing over time, and I don't think I can say when we're going to make the change at the data protection level, but we are watching and monitoring to see when things become the next bundle. That's not just for this area. We look at the same way for cloud protection, ZPA, and the like. Fatima, let me expand on what Jay said, and let me expand specifically on what watching and monitoring means. If you go back to the go-to-market model and how I laid it out and our really close engagement and alignment with customers, the fact that we do architecture workshops, the fact that we map out the different phases for their transformation, and the fact that we realize consistent patterns for customers by verticals, and that we recognize those, and we take that back internal. We're basically having customers and their natural tendencies guide how we construct these bundles. What we're seeing to Jay's point is, the more customers are committing to the greater bundles upfront because they're being pushed to go faster, right? Easy acquisition is important. That was a good question, and less complex acquisition and hence also deployment is important. What we are doing, even if we're bundling it, we're still keeping the value identification, quantification, and realization for each work stream separate. On a use case basis, because that is how you get to articulate and explain to customers why what looks alike from competitors is nowhere close to alike. I'm going to use the word again, and I think I've used it a couple of times. We're very intentional even about how we bundle based on how we engage and based on what customers are telling us they want to do as far as steps and speed of those steps. Fair enough. Remo, just a quick one for you. I know historically you've kind of given us some color around your end market exposure. It's certainly been a very interesting 12 months with respect to what end markets have been under duress, experiencing a ton of economic malaise. On the back of the Sunburst incident, certainly the U.S. public sector is in everyone's consciousness. You've invested a lot around the U.S. public sector opportunity. I'm wondering if you can just give us an update on sort of where you're tracking and how these recent events maybe change and significantly improve your position, in the federal government, where there's been fits and starts of overall cloud adoption. I'll let Jay talk more broadly. Specifically, we were mid-single digits of our new and upsell for federal in Q1, which we're happy with the progress we're making. Related to recently, maybe Jay can give more color on the federal market. It's consistent with what we have said. Getting into federal market requires all the certifications, it's taken two, three years for us to get there. We have some of the most unique certifications. We have built a sizable team. Our pipeline is growing at a very good pace. We expect federal to become a significant part of our overall new business. In terms of numbers and all, I think Remo basically leaves it at a level and say we are bullish in this area in the market without giving you any quantification of it. Fair enough. In the current market, again, we see adoption of Zero Trust getting faster than it was a year ago, even in the public markets as well. I appreciate that. Thank you so much, gentlemen. Because it gets viewed as one of the things you could do. You could do X things for SolarWinds. Zero Trust, where things can have lateral movement to hurt the whole thing becomes one of the most important items. Fair enough. Okay. Our next question is from Joshua Tilton at Berenberg. Joshua? Hey, guys. Can you hear me? Yes. Thanks for fitting me in. You guys gave disclosure, ZIA, ZPA, and ZDX, that fully loaded price per user is about $145. How should we think about what the ARPU is today? How do we think about maybe the timeframe and what's necessary from an investment perspective in order to see that ARPU move closer to the $145 number? Yeah, currently it's about in the high twenties. The reason for that is ZDX is new. ZPA is 13% of our business. The ZIA add-ons, they're relatively new, too. What time frame is it going to get there? Not sure. We are in the high twenties currently. I think the ARPU is high 20s, if you look at the deals we are closing for ZIA, ZPA, and all that stuff, the numbers we use in the computation are based on real deals we are doing. We have been getting far better value, and it's for two reasons. One, obviously, when you do value-based selling, you realize better value. Number two, also with all the product portfolio on, our bundles have also been growing as compared to what they used to be, there's more functionality in it. When you're selling more transformation bundle, obviously your price will go up as compared to if you're selling a business bundle and the like. Yeah, no, that was very helpful. I guess I also just wanted to touch on some of the go-to-market commentary from today. When we think about all the strong performance that we've seen over the last few quarters, how should we think about how much of the success is a function of all the improvements that we've seen in the go-to-market versus just there's so much market coming to you, and it's just not necessary to educate the customer as much as it used to be, because of work from anywhere? Yeah. Let me answer that in a couple different ways. What the macro environment did for us, it removed the throttle limiter, right? The throttle limiter was needing to be evangelical because everybody was hanging on to yesterday's plans and strategies. That's all great, but if you don't have the engine in place to take advantage, then I'll sail by you. Two-thirds of our team is still ramping, okay? We're doing what we're doing. More meetings, pipeline is strong. It's distributed across the geos. We're seeing strong partner participation. Velocity is great, but if you don't want to have. Think of it in this term, h ow many paths to revenue do you have, and what's your excellence in making sure you take advantage of each and every one of those paths? Who we were 12 months ago and the paths that we could take advantage of versus who we are today and the paths to revenue we can take advantage of are two separate entities. You could call it the meeting of two different things at the same time, at the right time, which is actually three. A platform that was purpose-built and ahead of its time, a market that made people realize yesterday does not work tomorrow, and a go-to-market engine that said, "We'll educate you, we'll guide you, and we'll do it across many different dimensions." That we can go as fast as we can. It was really a combination of all these coming together. It's a fair question, but think of it across multiple dimensions that aligned based on how we steered them. Yeah, if I were to add, I would say having a highly scalable go-to-market machine when you're dealing with hundreds of millions of dollars trying to grow at a very rapid pace, that machine plays an extremely important role. Thanks, guys. That was very helpful. Okay. Yeah, we'll take one last question, and that will come from Patrick Colville at Deutsche Bank, please. Hey. Thank you very much for hosting us today. It's been very helpful. I wish you guys had given us a long-term revenue guide, but Remo, maybe next Christmas that'll be the present. Merry Christmas. The public cloud security space is pretty competitive. In CSPM, there are 30 vendors out there. Can you just give us a pitch as to what is Zscaler's competitive advantage in this very competitive space? Good question. That's why we don't look at Zscaler Cloud Protection as one space. Okay. We look at three clean segments. Yeah, CSPM is one market. We call it workload communication, where each workload, no matter where they are, could talk to each other, east, west, wherever, data center. The third one is micro-segm entation type of stuff. Overall, when it comes to CSPM is somewhat like CASB market. Okay. You read APIs, and you figure out, are you really doing a great job against 10 standards, 15, and whatnot. I don't think anyone will have an architectural advantage in CSPM because you go against the same kind of APIs. Having good reporting, good functionality is needed. If you ask me, the biggest advantage we have in number two and three, workload communication we talked to you is an amazing advantage. It's like ZPA for us. Is that market competitive? I don't believe so. I've talked to hundreds of customers who are looking and waiting for our Cloud Connector to be able to deliver communication. That market is here and it's now. Micro-segmentation, as I said before, will take some time. It's a little bit early stage. It'll need some education and whatnot. We have differentiation there. It'll need some education. If you look at the three segments, CSPM will be probably not be as differentiator for any vendor. The other two will be a very distinct advantage because of the architecture. Can I just add to that, Jay, real quick? Patrick, if you look at our go-to-market engine, it's geared around selling platform enterprise value. There can be 70 solutions out there or 90. That's not appealing. What's appealing is selecting one partner that can help you end-to-end across really all of your needs. If we look at how we go to market, it's platform centric across different phases as we mapped out. Right now the conversations we're having with CXOs is around tools consolidation, around simplification, around agility, not around needing to glue together multiple different solutions. That's where we're sitting. That's what we've built to take advantage of not just platform, but also go-to-market-wise. We recognize there's a lot of competition there, but we also recognize what our unique value proposition is, and it's resonating. Okay. In terms of the licensing for this, I appreciate it's very early, but do customers typically license the workload protection suite for all their workloads in their public cloud environment, so they typically start in a specific domain or in a specific vendor, AWS versus Azure, and then move across? Just help me understand how the customer journey has worked so far, just so we can conceptualize it better. Amit, do you want to take that? Look, it boils down to what the critical assets for the customers are, right? They might have started a journey with AWS, and they want to do some basic posture management, and then the next step is they want to secure internet communication for workloads. Maybe the next step is I have my front end in AWS, but my back end is still sitting in my data center. How do these two workloads talk to each other, right? It boils down to specifically what the customer use case is. You don't need to boil the ocean in one shot. You identify critical applications, critical assets, and then you start rolling it out. CSPM, for example, maybe you start with your production workloads in GCP, maybe your developer workloads show up later on, right? It's a step-by-step journey. It starts off with identifying critical apps, what they need to communicate to, and then bringing in the Zero Trust Exchange concept that we've successfully deployed for the users to these workloads that need to talk to each other. I'm going to add again. Sorry, Jay. I'm going to add to you again, Patrick. We've built a model that allows us to land and expand. We can go bigger, we can go smaller. It doesn't matter. We're not going to be stifled by however companies want to buy, because the model is there to receive it and drive it from a velocity standpoint. Yeah. I was going to say that cloud protection may look like a competitive market because you hear so much about it. It is in an early stage. It's like a cottage industry. People are trying to figure out which of these solutions work, which of these solutions don't work. That we are excited about disrupting, and most of the stuff that's being done out there is pretty traditional and legacy. Thank you so much. Okay. Well, thank you. That's all of our questions. I want to thank everyone for your interest in Zscaler. As I mentioned, today's presentation is now available on our IR website. We'll also make the replay available later on today. If you still have any questions or we didn't get to your Q&A in your chat box, I am available at ir@zscaler.com. We will speak with you soon.
Loading workspace