Great. Good afternoon, everybody, and thanks a lot for joining us. The pleasure of hosting CFO of Zscaler, Kevin Rubin. Really appreciate you joining us today. To begin, I will say we'll take questions from the room as we come, so feel free to send it or email. It's going to be a fireside chat format. Just to jump in, I wanted to, just for audience not as familiar with Zscaler story or maybe still know you as the original SASE CM module story, was the most important, I would say, conceptual takeaway from the last quarter was increasingly becoming a control plane, not just for the users and applications, but getting more agents and workloads. Just how should investors really think about Zscaler as a platform identity? Sure. Thank you for having us. Zscaler started as a zero trust platform for users, that included internet access and then, shortly thereafter, private application access, and have since expanded into cloud. Being able to provide zero trust for workloads, and devices sitting in branch locations. More recently, we're going to be announcing zero trust for agents. Providing the same principles that we applied for users, devices, workloads, also providing it for agent-to-agent and machine-to-machine communication. We have our user conference next week in Vegas, Zenith Live, and you'll hear a lot more about AI, agentic, and our integrated SecOps product next week. We'll be talking more about it. Essentially, if you think about zero trust, provide the least permissioning to solve a particular ask or use. Don't give access to somebody to jump on a corporate network, and potentially have lateral movement access to do bad things. We've applied those principles through our Zero Trust Exchange to really provide one-to-one communication paths between users, applications, between workload and workload, between devices and devices. Just a very differentiated approach to network security. Great. Very helpful. Just on the topic of AI, there's been broader debate around frontier models and AI native startups, especially post the Mythos announcement by Anthropic. Just elaborate, as AI traffic expands, as more and more agents are coming online, and even the attackers are moving at machine speed, how does that really expand the need for what you offer, which is like an inline enforcement layer, and how does that opportunity multiply in the agentic era as we go on? Yeah. As Mythos and other similar frontier models demonstrate an ability to identify vulnerabilities at a rate and pace that far exceeds what we've seen today, we believe the best security and the best response to that is hide your applications and limit your lateral movement. Ultimately, your blast radius can go down to one infected device and one only. It doesn't have an opportunity to permeate the rest of your network. If you look at large organizations today, they already have a backlog of patches for existing known vulnerabilities that they are incapable of handling in any reasonable period of time. They go through a process of prioritizing which patches I'm going to apply when, and attempt to do that without disrupting their organizations and their business. What Mythos and other models similarly are identifying is a volume of vulnerabilities that already exceed what they can handle today. You're just piling on top a order of magnitude more set of vulnerabilities, and ultimate patches that would need to get run. It's just incredibly overwhelming. Our approach and our answer to that is, if you adopt Zscaler Zero Trust approach, you end up hiding all of your public-facing applications so they cannot be seen. If you cannot reach the application, you cannot breach it. Hide it, and then only allow those sessions to be activated based on least permissioning. Those are the conversations that we are having with our customers and prospects today in response to just an unprecedented level of identification of vulnerabilities. It's very helpful, Kevin. I know you did highlight the customer conversations with CISOs and CIOs, how that's really shifted post- Mythos. Just in terms of big picture. What are you seeing as the budget trends for broader cybersecurity, right? In light of Mythos, are you seeing CIOs starting to expand and unlock more budgets because of the extra risk or additional risk that AI is driving? Are you seeing, especially to your point around exposure risk, and recently there was findings of almost 10,000 high critical vulnerabilities. How is all of that changing the budget landscape for you? Look, it's incredibly challenging for a CIO who has largely lived within a fixed budget domain for a long period of time, all of a sudden, there's two fundamental dynamics. You've got a need for their organizations to deploy AI and to do so quickly. I don't think I've met a CEO who has told an organization to slow down and go forward with AI slowly. It's let's get it deployed through the organization and take advantage of it as quick as possible. They're reacting to a desire by their business to deploy AI. At the same time, they have to then understand how do I protect this AI use in a way that protects my organization? What we've seen is that companies have rushed to be able to deploy AI technologies within their organizations, and then they're coming back behind that to actually provide security for the ultimate use. We are working with customers via our AI Protect suite of products to be able to provide protection for AI use. We offer the ability to first identify and find all of the AI assets that are being used within the organization, not just the obvious ones that you're intentionally deploying, but applications that are leveraging AI in the background to be able to do more work within those applications. We're able to identify the landscape of threat that you may have within your organization as it relates to AI. The second step is to be able to actually protect the communication path going back and forth between AI. What data do you want to share? What data do you not want to share? We have an AI guardrails capability that will allow you to monitor and inspect that communication in real time to be able to ensure that sensitive data is not being exposed to models when it shouldn't be, and responses back from those models are business appropriate for your particular use. Finally, we have an AI Red Teaming solution that allows you to continually monitor those models and understand how those models may change, evolve, and drift over time. Fairly new products, we announced those as a collective suite of products at the end of January of this year. They're actually doing quite well, and there's a lot of interest around just generally being able to protect AI. Great. Really helpful, and you mentioned about the incremental, so AI security demand in reaction to deploying AI, as you said, sense of urgency deploy across enterprises. We've also heard from some of the channel partners, some of the customers out there that people are closely looking at longer duration architectural re-evolution as well, right? Does frontier AI ultimately also, and is it getting evident in your conversation, accelerate this migration away from, and as you guys have talked about as a lot of these zero trust SaaS vendors talked about, from perimeter-based, firewall appliance-based approach? I suspect that as we play this forward and organizations recognize the exposure that exists with traditional hardware approaches, network security approaches to AI, and what they will have to do to be able to patch and protect their environments, it's only going to increase the validation of moving to a solution like Zscaler. We already have an incredible ROI for customers that choose to adopt Zscaler in lieu of traditional network-based security. As the burden and overhead of continuing to manage that, you called it perimeter-based, I just use the term network security, I think it's just going to make it that much more compelling. We have had significant inbound conversations as this Mythos and Mythos-like exposure has been identified, because companies are realizing that there's got to be a better way for us to protect our environments without constantly having to chase our tails and continually patch and chase these vulnerabilities. We do think that it is a significant tailwind and opportunity for our business. Great. Very helpful. Just on a high level the impacts on your revenue model, right? We all understand, the seat model, of course, will take a backseat as we go into this agentic era. You have talked about how, as you said, right, the AI traffic, the workloads, the agents, all those interactions are likely to accelerate materially. Just how should we as investors think about this model holistically evolving from this human seat based towards more non-seat machine agent based? We've actually been exposing some additional color into the texture of our new ACV in a given quarter, specifically to give insights into how much of that ACV is coming through traditional seat-based pricing versus more metered pricing. It increased in this last quarter to about 30%. We are seeing a continued increase in non-seat-based priced products in the market. The AI and agentic technologies that I mentioned earlier are not seat-based oriented products by the nature of those products. They are much more aligned to consumption and how much traffic is actually being exchanged. For AI, it likely is tokens, right? That will be the unit of value that gets monetized. For some of our other products, it may be just traffic and consumption. For our branch device, by way of example, that starts to look at assets and assets communicating back to other applications and company resources. We have continued to see a just continued distribution of our business away from seat-based pricing. When it comes to agent to agent, we think that that traffic will be significantly greater than what we've seen with user traffic. We expect to monetize that through tokens and consumption as well. Great. Thanks for laying that out for us. Just, I wanted to get back to this, the setup into fiscal 2027, because as you know, the market reaction intensely seemed to focus on the guide part or the early look, as you said. When you think about that prudent, 2027 framing, can you just help us unpack how you're thinking about the execution piece, right? Which is kind of tied to the go-to-market transition, versus there are a lot of moving pieces, as you said, around kind of SecOps, how they're looking at the budgets, the deployment velocity, and then of course, the agentic and AI monetization, if you can help us unpack things. I thought it was important in this last call that we provide an early look as to what we were seeing and giving you perspective on growth rates into fiscal 2027. We wanted to make sure that you were aligned with us in terms of how we saw our business. Against that backdrop, I provided two fundamental factors that were affecting how I looked at this early look into fiscal 2027. One was, we are replacing two senior sales leaders within Mike's organization. You may recall, Mike joined us two and a half years ago. This is his second full year running our go-to-market strategy, soup to nuts. One of his leaders got an opportunity with a AI pre-IPO startup and chose to pursue it after spending, I think, almost a decade with us. Very long-term, tenured, senior leader. He has moved on. Another leader that was a direct report to Mike is also departing the organization. We will be welcoming two new leaders into the organization. One is an internal promotion into this new role. The other will likely be an outside hire. Given that, and given that these are two senior individuals, I just took a cautious approach to what that would imply for fiscal 2027. These are not the only directs to Mike, but he doesn't have a large set of directs as well. Just in the interest of being prudent, we took a cautious approach. The other dynamic affecting our perspective on fiscal 2027 growth is the pace of uptake of the integrated SecOps offering that you'll hear more about next week at Zenith Live. Fundamentally, we will be coming to market with an integrated SecOps solution that will leverage our existing technology from a data fabric perspective, as well as our very high fidelity rich data set. That will be the migration from the old Red Canary product into our integrated solution. What I don't know, and what I'm, again, taking just a cautious view is, what does the pace of that uptake look like going into next year? Those are the two fundamental dynamics as I looked at fiscal 2027 growth. Now, aside from that, we have a significant number of opportunities that could build momentum, and we're very excited about. We've talked about AI, and just the opportunity that exists, whether it's a catalyst to folks choosing to adopt Zero Trust or it's actual providing security for AI, which again, is products that we just recently put into market. They're young, but obviously high-growing products. That's the tension and balance that we had to strike as we thought about the early look we provided. Yeah, no, clearly, as I said, the headline early look seems to obscure some of the healthier sort of underlying signs and signals you just talked about, and especially around the health of the upsell pipeline, the AI pipeline, and the non-seat business. Just, I know historically, you guys have often guided prudently. I remember the times around the Branch Connector launch, around the cloud, before they showed that sort of inflection point, right? Should investors think about central monetization of AI Protect, SecOps, Agentic Exchange, like you have all of those stacked together in a similar way where you have the architecture, you have the demand already there, and just it's a matter of timing and scale of monetization? Just curious, how would you? I think the answer is a little bit different depending on the suite of products. AI is very dynamic. It's changing frequently, as you know. We are very confident in how we're approaching AI, both in terms of securing it as well as partnering with the large frontier model companies. We are part of Glasswing and Daybreak, That does give us a good perspective into what is coming and how we should think about releases like that. We're very bullish about the AI opportunity. It does take time to build products, and markets are fairly early. I think as we think about the SecOps product, to me, it's really a pace-of-uptake question. We know we have customers that are on the existing product. We know that there's incredible amount of value and insight we can provide. How that rolls out and what that uptake looks like, to me, is the measure of success going forward. Not to mention, Cloud and Branch, those are two very well-performing products that build out the suite of zero trust everywhere. Moving from users to those two particular products. Soon we'll have agents. I think there's a lot of opportunity for us to see building momentum going into next year. Interesting you mention about the Project Glasswing partnership and the potential for commercialization and monetization. A couple of partners, some of your larger peers, have talked about some of the frameworks around that. Can you just at a very high level lay it out, like how do you plan to utilize and leverage this partnership to drive the commercialization, and what does that look like as a monetization model? It's a little premature for me to do that here. You'll hear a little bit more from us at Zenith Live next week. We have had access to these models. We are part of these programs. We've been able to run them against our environments, and use those, as well as have meaningful conversations with customers as to how these models may affect them and where there's opportunities. You'll hear more from us going forward. Got it. Just to double-click a little bit on the Agentic Exchange, because the reason I brought it up is you and Jay sounded, and for the right reasons, as the biggest long-term opportunity. I'm pretty sure we are going to hear more about that in Zenith Live. Just as a quick preview, if there is a traffic-based monetization opportunity there. You talked about tokens, you talked about transaction processing layer. Seems like the AI traffic has already exploded and as you see, a lot of numbers and metrics. How should we think about monetizing that? I know you are still figuring out and trying to settle in a more stable model, a more durable model, but just any sense of how to think about that monetization? Yeah. Just to level set, the Agentic Exchange is not actually in market yet. The principles of how we will apply it are very similar to what you've seen us do with other Zero Trust approaches. Again, you will hear more, but the concept is simple. We have over 50 million users today that we apply Zero Trust to through the Zero Trust Exchange. I would expect that number of agents and machine-to-machine connectivity is going to be orders of magnitude greater than that. So the ability to be able to broker those communications, inspect that traffic, and provide protection is going to be very similar to what we've been able to do with the other forms of communication. It represents an opportunity very likely greater than we've seen thus far with users, branches, and devices. Very excited about the potential, and I feel like we've got a scaled track record of providing the Zero Trust approach to other forms of communication. Very helpful. I know we'll definitely wait till Zenith Live for understanding how that agentic traffic translates into more monetizable metrics. Before that, AI product, as you started off with, already is achieving scale, right? It's already at $100 million bookings. Still relatively early compared to all your other opportunities. Just wanted to understand, you gave us a good sense of what's resonating, but across AI Protect, there are bunch of different components, and you have guardrails, and you have ways to protect the prompt, and which is starting to become more significant, or are there multiple levels right now already showing growth, just from perspective of AI Protect? The guardrail product has been in market longest. I think we're actually probably just coming up on a year that has been in market. The Asset Management and the Red Teaming are newer. Red Teaming was part of the SPLX acquisition that we completed a couple of quarters ago. The AI Asset Management, we rolled out, I believe, in January as part of that announcement. Each of those components have had a different shelf life so far. Collectively, we're very excited about the proposition of all of them and think that they do form the basis for what companies need to be able to protect their AI use. Just a quick follow-up. Is AI Protect eventually, and even early signs, are you seeing that becoming a stronger landing motion? I know you are focusing on new logos. You have been talking about some of the adjustments you made in terms of prioritization of go-to-market. Is that going to be one of your big focus areas? I believe you mentioned you're already seeing some traction there. Yeah. The AI suite of products do not require the Zero Trust Exchange or ZIA/ZPA specifically. We are having traction in those conversations. Some of the other products are more tightly embedded with ZIA/ZPA, so it would be natural that that would be the landing point for those products. The AI products do give us an alternative side door, if you will, into introducing Zscaler to prospects. Got it. You did announce an acquisition, Symmetry, very recently. Seems to be very much strategically aligned with your Agentic Exchange framework. Of course, the way you describe and characterize enabling agents, enforcing policy around it, and it seems it's an innovative way of orchestrating the context and identity. Can you just outline how that's differentiated from a lot of these agentic identity, let's say, methods and paradigms out there? Well, I'll answer as a finance guy. It's a fairly technical question. Symmetry has built an access graph that allows us to understand and infer permissions that may have been inherited to an agent through its need to do work. It just provides us yet another differentiated way to be able to understand identity and understand permissioning, so that as we are providing inline policy enforcement, we can ensure that the agents are only accessing permissible assets and/or applications. It's another piece of the Agentic Exchange puzzle. Got it. I'm presuming we'll hear more. You will. on the monetization model. Yes attack strategy at the scene. Okay. Just in terms of Z-Flex, this was one of the, I would say, market quarters for you guys. You closed $480 million worth of TCV this quarter, that was one of the big, I would say, inflection I've seen over the last year. I know you've underscored that it's about flexibility and broader platform adoption. As other larger players out there, I'm referring, have been leveraging this strategy, can you just talk a little bit about what has now resonated this quarter especially with just driving these big uptick of very large deals? Yeah. Anything particular that stands out in terms of underlying driver? Z-Flex is our approach to providing customers that are looking to make large commitments over a long period of time to us, the flexibility to not have to identify each piece of technology and specific counts of everything upfront today. Right. If somebody knows that they are a longstanding Zscaler customer or intend to use our technology over a long period of time, it allows them to have flexibility for the different capabilities that they can deploy over a period of time. If they want to be able to swap into other pieces of technology or flex into other pieces of technology, it provides the vehicle to do that. It gives them fixed pricing across all of our portfolio of products. In most cases. In some cases, we only give them a menu of lesser product. By and large, it gives them fixed pricing that they've already prenegotiated, so they don't have to go through another procurement cycle a year and a half into a contract to procure more. It's already been baked into that contract. It allows them to make those commitments with the understanding that they've got protection if they want to use different combinations of product, or they want to be able to try something else that maybe they didn't anticipate at the time they made the commitment. It's a very flexible way for customers to consume Zscaler. For us, it gives us certainty. It gives us that commitment, so we're happy to provide that flexibility as well in that relationship. We did cross $1 billion in booking this last quarter as a result of the strong Z-Flex bookings in the quarter. I have a quick follow-up thing in the interest of time, there's a question which came up. You do, and you mentioned about your M&A strategy as well. You have over, let's say, $3.5 billion cash in the platform. It's definitely mature and as you said, across the board. How do you think about the capital allocation right here? I know you've been doing a bunch of tuck-in M&As. Mostly it's still organic execution. Are there categories where a larger move would make sense? A lot of your peers have done very big, at least compared to their standards. Is there something that you have in mind or looking at it closely? We have really focused on teams and technology that we feel are highly complementary to the Zscaler platform that we have today. We have not sought to expand into adjacencies or by populations of customers. We've really been very focused on how do we bring complementary technologies to market faster. That's how I would expect us to continue to operate, at least in the near to midterm. Great. That's all the time we had. Really appreciate you joining us, Kevin.
Loading workspace