America. That's for the benefit of the transcript, so we can pass this. Jay, thank you so much for joining our conference. I really waited for this session because I read an interview with you that you believe that investors, you don't do a good enough job to explain your company to investors. I want to give you the opportunity to explain your company. The first thing I want to start with is, normally I don't ask about the quarter, but I do want to ask about the quarter because I thought there was a difference between the way you performed financially and the way the stock reacted. What is misunderstood by investors in your company's performance? Okay. First of all, as you saw, the Q3 performance was very good. We beat all metrics that the investors look for. Yeah. I think for going forward guidance, the two aspects to it. One was Q4, and second was fiscal 2027. Yeah. The two factors for us to be more cautious about the guidance, one was we had a couple of changes. We had two leaders, important to us. CRO moved for two various reasons. One for personal reason, understood, and second was an opportunity at a pre-IPO AI company. Okay. When leaders leave, we want to make sure that transition involved, and it'll have some impact. That factored in. Second was the Red Canary customer base. We have built a new product combining Red Canary technology with our technology, and that new solution is getting showcased next week at our annual Zenith conference. The uptake of those customers, we still need to understand. Keeping those two things in mind, we set the expectation at what my CFO will call at a prudent level. Yeah. In terms of the external market factors, the market for cyber has never been hotter. Yeah. MITRE has further put fuel to the fire. They're probably the biggest tailwind since COVID for our company. This platform has gotten bigger and bigger. Loyal, happy customers. We have essentially gone through the transitional sales that started about a little over two years ago, and we've gone through most of it, and we look forward to expecting in Q4 and 2027. Yep. Maybe let's start with if you can articulate your target markets. Meaning, what are the opportunities you're going after? No, I'm not talking about the quarter thing. Yeah. It could be a three-year, five-year. Yeah. What are the opportunities you're going after? Yeah Why are you well-positioned for these opportunities? Right. It also relates to the question you asked, what investors don't understand. Yes. Investors understand mature, established market well. A firewall is a firewall. It doesn't need to be explained much. A router is a router. Maybe the feeds and speeds are better. When you bring transformation, you bring totally new changes. It takes some time to explain itself. What happens is the established incumbents fight back because they get disrupted. Yeah. They like to say, "We do that, too." It's like internal combustion engine car companies fighting against electric car, and said, "Forget it. I'm better." Okay. That's the fight that goes on. Take one example. Zero Trust is fundamental. With MITRE, it's becoming more and more important because there'll be more breaches. It's given. You can't be able to patch all the way. Zero Trust will make sure that only certain parties talk to certain parties. The breaches don't spread. The blast radius will become smaller. Many times people think that just because a lot of me too's are trying to say, "Oh, we do Zero Trust, too." This fancy new four-letter word, SASE. We do SASE, too. Okay. First of all, SASE and Zero Trust aren't the same. Yeah. SASE allows SD-WAN lateral movement of light. The second part is Zero Trust started with users. We made user Zero Trust phase one. We made cloud workload Zero Trust. What's my competition for Zero Trust cloud? 30-year-old firewall technology, east to west north, south traffic. We made branches Zero Trust. Each branch is like an island. There's no lateral movement. Device in a branch. We call it zero trust everywhere story. Zero trust everywhere is just beginning to take off. We shared with you at the earnings that now we have over 700 customers doing zero trust everywhere, which means users, branches, cloud workloads, and devices. That same number was 550 last quarter. Big opportunities to make zero trust everywhere. Market number one. There's really not a real competition from firewall vendors out there. It's only probably on the lower end of the market because the high-end customers generally are more savvy. They get it. The second big opportunity is data security. For data security, you need to sit in line as a proxy architecture, inspect the stuff. Firewall vendors don't do data security well. They're not a proxy architecture. We have over half a billion-dollar ARR business. If it were an independent company, it'll be the largest data security company perhaps, and still growing over 30% year-over-year. We do that stuff very well. Okay. Those are one set of areas. Look at the newer areas. Oh, before I go there. The most important Zero Trust, next area is Zero Trust AI agents. Search for Anthropic's white paper on Zero Trust AI agents. It just came out two days ago. I looked and said, "Huh." They wrote what I would have written. Literally. They understand it. Their stuff was agent to agent communication must happen through Zero Trust, not through the firewall. We actually have been building that solution. We plan to launch it next week at a user conference, and there'll be millions and millions of agents, and they need to be secured. That's an opportunity. Securing AI infrastructure and applications and models. We have been building that solution. We did an acquisition, and in January we launched our integrated solution. Our customers want integrated solution, not five different vendors. That solution is taking off quite well. We already exceeded $100 million in bookings for that solution. Big opportunity for us. Agentic SecOps. While there are many players in agentic SecOps, AI actually is useful for building SecOps. There are probably 500 companies, startups in agentic SecOps, maybe more. Yeah. Because they think they can build it easily, the advantage will be to vendors who actually have telemetry and metadata to do it. We are in line. We probably have the most valuable data from communication. We are on endpoints. We have endpoint telemetry. All authentication goes through our via identity telemetry. Our customers are saying, "You got the data. I don't need to pass data to someone to build the same. I want really output that can be done directly with us." That's an opportunity for us by itself. There's no lack of products, and we do product carefully. Yeah. We don't go on a buying spree for, I mean, say A, B, C. They're well integrated. They're part of the story. What makes you be successful in these areas? Meaning, the current position that you have with customers, what are the parts that can be levered into the new areas? Yeah. First of all, Zero Trust Everywhere is expanding from what we have. Yeah. It's very, very natural. When customers go from Zero Trust on users to zero trust everywhere, the ARR either becomes 2x or 3x. Yeah. Okay, similarly, we're natural. If you got Zero Trust, natural to the nest. Data security. We're sitting in line inspecting traffic. Most of the time, data leaks to the internet. We are the natural player to be able to do that. If you think about for agentic style, it's natural that we do that. If you think about the SecOps is driven by the fact that we got all the telemetry and metadata. We can do that, one more point. In minutes, I can figure out some of the new threats. I can do a closed feedback system to the inline system to block those threats in near real time. That doesn't happen otherwise. Very synergistic platform expansion. Yeah. Is there a risk of slow take rate? Meaning, what I'm referring to is the majority of the revenues today are ZIA and ZPA. You have new areas you're going after. Is there a risk of a kind of transition period? If you look at the ARR or emerging growth or new ACV has been growing rapidly. Yeah. We have been giving some stats, for example. Great to see data security grew so well. Yeah. We have seen in the past couple of years, we used to do emerging products, and some of them already emerged. Yeah. We stopped doing emerging. The emerging went from what? 8% or 9% to 30% in two, three years. That's a remarkable expansion thing. If the products are synergistic and the decision makers are similar, it becomes meaningful. If decision makers are very different, it becomes a lot hard. That's how we elect our products. One more thing. As products have expanded, we now do have specialty overlay salespeople who can go deeper in certain areas, but they work with account execs. Got it. Yeah. You mentioned data security, and this has been a focus of yours for quite a few years. Yes. Double-click on this market, meaning what is attractive. Data security is a big space. What is attractive, and what are you addressing within data security? About five, six years ago, we only used to do DLP, inline DLP. Yeah. Our large customers said, "Doing data security with one vendor is hard enough. If I buy three products from three vendors, it'll be impossible. Zscaler, you should focus on building a complete platform for data security." That's when we expanded to CASB, SaaS security, then we added Endpoint DLP, added Email DLP, and we added cloud security, S3 buckets, and all. Recently, last year, we added DSPM, discovery classification data. It is the most comprehensive integrated platform. We think we have a big edge. We have very good uptake by our customers. Yeah Very pleased with the performance. Again, same question I asked you before. What makes you better positioned for this market, given that it is being addressed by other players as well? Not really that much. Okay. Think of which SASE vendor does data security very well. Not a whole lot. There is a class of vendors coming from the startup side. They call them for DSPM. DSPM, one more four-letter acronym [partner]. It's called Data Security Posture Management. At a simplistic level, it does two things. One, it allows you to discover data. Where is my data? Data center, AWS, Snowflake, wherever. Then it helps you classify the data. That's important. It doesn't do data DLP. Okay. You do classification and discovery, then you combine it with a DLP, and then it becomes a complete solution. We came from DLP side, we added DSPM, so we have complete solution. Generally, there's a lot of wording about DSPM is important. It is important, and you hear about some of those vendors. Yes. They will have to do DLP to be successful in data security, and we are ahead of anyone in this area. Got it. The customer engagement track record working with us. DLP should only be done with somebody who is already setting the traffic path. Some new first vendor to come and say, "Put me in the traffic path. Got it. Is a big ask. Got it. I want to go back to ZIA/ZPA just because it's a big portion of your business. How's the growth like, and what are the drivers? When I talk to Cisco or Fortinet, yesterday, I hosted Ken Xie here, and Ken said, "I'm a third of the price." He said, "That's my thing. I'm bundling it together with my firewall. I'm riding on top of the firewall. I'm a third of the price. What kind of a disruption do you see from companies who are trying to bundle firewall with SASE or SSE? Two things. First, if you want product functionality A and you get B, I'm not sure in cyber if someone gives it to me free, I won't take it. Got it. If it doesn't work, so they are all firewall functionality. There's nothing Zero Trust about it. In many product areas, good enough is good enough. Perhaps HR system, no. They are pretty important. Yeah. Not as important as cyber. Yeah. I'm okay with a good enough HR system, but I'm not okay with a good enough cybersecurity. CSOs, CEOs have to think that, "If I get compromised, what's the consequence of it?" That's point number one. Okay. Point number two is that customers are understanding more and more the need for Zero Trust. Yeah. I think the wind is not towards I can give you cheap firewalls. Yeah. Now, it is true that lately, in my view, firewall vendors have been helped from two things. One, the prices have gone up. Like if you raise the price 15%, if you beat the quarter by 15%, what's the big deal about it? Yeah. It's external factor that brought you in. Two is, I think they're also getting some tailwind from the AI data centers being built. Yeah. We are clearly seeing Zero Trust momentum building up. Our growth should not be looked at ZIA/ZPA for users alone. That's a starting point. It's not a core versus non-core. Right. Our product to stay Zero Trust users to branch to cloud. How well is the overall portfolio growing is really important part of it. Right. Overall, we're doing quite well. Is there just because of the fact that there is more competition today on SASE, even inferior solutions? Yeah. Cisco is in the market, and Fortinet is in the market, and Check Point is in the market. These are new players. They were not in this market before. Does it translate into pricing pressure or shorter duration of contracts, or do you see any impact of the new competition? On the high end of the market, which we actually do extremely well. Yeah We don't for two reasons. One, they understand architecture value. Yeah. Many times procurement likes to bring someone in, even just to put pressure on the pricing. This is how many times the dialogue goes in. A firewall vendor goes in and say, "You're spending $20 million with me, Mr. Customer. Just you need to expand, here's $5 million more, and for a $2 million, I'll give you what Zscaler has for free." They're probably paying us $5 million in that account. We are able to go in and say, "Oh, you're spending $20 million on firewall, which is becoming like mainframes. The future is not firewalls. Yeah. What if I bring that number down from 20 to 10 in 15 months or 12 months, and rather than $5 million, you give me $8 million? When the customer sees the math, it becomes a no-brainer. I had been many on these pricing pressure calls have come from time to time, say, "Oh, Zscaler, my budget is down 15%. I'm asking every vendor to bring the price down by 15%." That call happens with CIO from time to time. Yeah. Generally less pressure on security, but many times they come, I can say, "Mr. CIO or Miss CIO, why do you only want to reduce 15%? Why don't I help you reduce actually $5 million or $10 million?" Say, "Really? How?" "Here are the things we can take out." When that discussion happens, CIO is not worried about her saving $500,000. He want to save $5 million-$10 million. We're able to open new areas and new opportunities in the area. Overall, there's not a meaningful change in pricing pressure. Got it. I understand. Can you talk about new customers versus upsell to existing customers? What are the dynamics of gaining new customers versus the other part? Our customers are overall very happy customers, very loyal customers. Upsell is a lot easier. In fact, quite a few times the call comes in, a customer, a CIO or CISO move from company A to B, they call us. Yeah. Say, "Hey, I want to bring Zscaler in." In fact, it's probably one of the most effective lead sources for us. We got hundreds of customers, CXOs who have gone from company A to B to C. Early on Monday, I got an email from a CISO who just joined a Fortune 10 company, and he was in a Fortune 25 company. Before another one, he bought us in company one, company two, and this company three, he wanted to connect, and he said, "Hey, I don't even have to do much work. Zscaler's already deployed here, but I can probably expand it." Expansion is obviously easier when you have a good customer base. New logos do take more effort. Yeah. There have been discussions inside the company over the past few years, do we give more attractive comp plan for new versus old? Part of the discussion was, do I want people to too much focus on new at the cost of upsell? If you are a company with a small portfolio of products, you must get new logos to grow. Yeah. If your platform keeps on growing, you have two ways to grow: upsell and new. We have both of those opportunities for us. If you think about the total customers, about over 45% of Fortune 500, and if you go to the bigger enterprise level, from 2,000 up, 2,000 is our threshold for enterprises, and about 20,000 enterprises, and about 4,500 of customers. That's about 23%. This is a sizable market to go after new. One of the things we're changing going forward this year is, as we add new salespeople, when company is growing, you need to add salespeople. We are more being added between 2,000 to 10,000 space. Yeah. Which is largely new logos because our penetration there is limited. Yeah. We're adding new reps for new logo focus. We are making sales comp plan more attractive for new logos, and we're also going to be more targeted with VARs because at that end of the market, you do need to work with VARs to have proper coverage. I asked you about competition, and I forgot to ask you about Microsoft. I want to go back to it and see, do you feel the pressure from Microsoft? They have very disruptive pricing, but product quality is not the same. How do you see Microsoft in the market? Over the years, Microsoft has been a great partner. We were the one who helped Office 365 local breakout big time. That's when we got the highest level relationship with Microsoft. We're integrated with endpoint, EDR, Identity, Microsoft Sentinel. About 3.5 years ago, they launched a competitive product, and I was not kidding, really telling Microsoft, "You guys even stole my name. Yeah Internet Access or Private Access. At that time, as I talked to Satya, Scott Guthrie, they basically said, "Look, you got a 15-year lead over us. We need to offer the product. Work with my sales team. My sales team's quota is $100 million. Security in a given customer will be $5 million. They're not focused on security. If your product is good, the customer likes it, they'll be fine." 3.5 years later, I don't even recall last time I had to say, "Man, we're competing with Microsoft." My data points are more on the higher end of the market because that's where. Yeah I spend more time, but it is not a meaningful factor. Got it. Working on the portfolio is one challenge, and you've done great. You have very articulate product strategy. The second part of the battle is working on go-to-market. Yeah. Talk about the efforts on go-to-market, the success stories, the challenges. Give us the whole picture of how you evolve your sales organization to address the new opportunities. Yeah. About 2.5 years ago, we made the decision that we need to move from opportunity-centric sales thing to account-centric stuff. We brought Mike, great CRO. He has done a great job in making changes. We made big changes at that time. We wanted leadership and salespeople who knew how to deal with large accounts, borrowing from the ServiceNow model, which was successfully done. Over the past two years, we have actually successfully made all the changes. If you look at the numbers we had delivered over the past two years, they're pretty impressive. Now, they slowed the absolute growth and net new ARR slowed down in 2024. It picked up in 2025. Yeah. In 2026, you saw the numbers. Net new ARR growth has gone up, going from 2024 in the some 0.1%- 7%. The first half of 2026 was what? 10%. The last quarter was what? 14%. Yeah. We're doing pretty good. Now, we want to do better. I'm an ambitious person. I have big aspirations, so really need to keep on moving in that direction. We did have a little setback with a couple of sales changes that we are factoring the guidance, but the market is good. Essentially, as we pass through the transition of a couple of sales leaders and changes, everything is pretty well aligned with that. Got it. GSIs, we made a lot of good progress. They're working, doing some very good deals with us. Got it. Yeah. What are your challenges? I want to ask you other questions, but before that, I want to understand where do you put your focus? Meaning, what are the things that you think you need to address for the next two to three years, five years? In general- Yes I've only two focus areas. Build amazing products, sell and support customers. Okay. Yeah If you look, I think we got the building product and platform, we got it pretty well under control. We have done very targeted tuck-in acquisition, which actually adds some differentiation to our platform. The Symmetry acquisition was especially very, very good. Yeah. On the go-to-market side, I think the number one thing I wonder about fixing is the FUD being created by non-Zero Trust companies to confuse the market. Yeah. I know why they're doing it, because they need to protect themselves. In some ways, it's kind of doing disservice to enterprises who believe that this is real security when it's not. That's one initiative. We have a CMO who's very good now. We got a number of initiatives in marketing to create brand and awareness. That's number one. Number two, I think related to market somehow has discounted the role we are playing in AI security. Yeah. If you really think about that, the biggest thing to be done in AI security, among all these things, is securing agent-to-agent communication. Nobody's better positioned for that. Yeah. A number of other areas. Can you give me visibility into our products? Of course, everyone will do it. It'll become like CASB kind of stuff. Can you do red teaming? Everyone will do red teaming about it. We have it in our portfolio. We have to have it. The hardest problem to solve is communication of agents. That's what we built. We'll be launching it next week. I wonder about why has market discounted us for AI? I know the one thing that comes to mind is this MITRE thing, while we have been part of the Glasswing project from day one, just that when the press release came out at short notice, our name was missing, and we did go, "Hey." Well, they did it on their own time in a short window. We missed out. The following week or so, we're able to go to them, get approval to go out there. We missed the window, and somehow the investors and market felt that only two companies that are listed there aren't actually AI ahead in the market. I think coming quarters will prove that we'll generate some real numbers in AI security to convince investors that we are the real deal. Got it. Most companies in the space are offering some kind of flex programs, and you have your Z-Flex. Right. Talk about the importance of it to the customer, to you, and then what's the take rate of Z-Flex? Z-Flex has exceeded all of our expectations. Yeah. It's probably four quarters or less than four quarters, about three, four quarters. Maybe we start, what is it? For those that don't know, what is Z-Flex? Yeah. Thank you. What's a flex program? As name implies, Z-Flex. It gives you flexibility to buy certain products, and being able to even swap certain products. Otherwise, the customer says, "Zscaler, you got these eight data security product. I'm not sure if I want A or B or C. I'm going to test and test and test." It could take many quarters. Now we're able to say, "Look, you can select X products, and we'll give you the ability to swap." Swap is linked to similar price ranges, so to speak. They can swap. That's number one. Number two, they said, "I want six products, but I'm not ready to roll out all six. It'll take me time. I want to be able to do these four and then do two." We gave you staggered, the ramp product. We had done ramps before. It just formalizes ramps as they are needed. Number three, if I want to buy a new product, there's a credit card already available. This thing removes the procurement cycles back and forth. All that stuff makes it easy. Now, our program's fairly conservative. We basically are recognizing the revenue for the next 12 months or ARR for the next 12 months. Yeah. It's worked very well. We just got past $1 billion in the Z-Flex booking, which is good. It's good for customers. It's good for us. Yeah. The deal size length has gone up. Right. Most of the Z-Flex deals are five-year deals. Is there a risk, and I've seen it with CrowdStrike before, is there a risk that Z-Flex makes it very easy for customers to try and test systems, et cetera, and upon renewal, though, you'll see a slowdown? Meaning companies are trying it, companies are testing it, but maybe renewal rate won't be as strong. What's the risk that what we're seeing today, some of the growth we're seeing today, is really customers trying new products. First of all, Z-Flex is a headwind for ARR recognition. Got it. Okay. Some of that is staggered. Okay. Number two, our focus as a company has been to make sure the products we sold are deployed. I get a personal review on a monthly basis to look for deployed versus undeployed products. Yeah. Many of the compensation of product leaders are linked to deployment. Our customer support team, the deployment team linked to it. I think companies should be careful, but we are already very focused on making sure products we sell. Got it. Get deployed. Okay. Yeah. We officially ran out of time, and I didn't leave enough time for questions, but thank you very much, Jay. It has been great, and I'm always happy to host you at our conference. Thank you. I think if I leave the last word for you, MITRE will probably drive Zero Trust need faster than anything else that's driven out there. We have the right products, and we intend to do the right execution. Absolutely. Yeah. Great. Thank you.
Loading workspace