JFrog Ltd. (FROG) Earnings Call Transcript & Summary

May 23, 2023

NASDAQ US Information Technology Software conference_presentation 34 min

Earnings Call Speaker Segments

Pinjalim Bora

analyst
#1

Okay. Let's get started. Hey, everyone. I'm Pinjalim Bora, SMidCap software analyst at JPMorgan. Delighted to have here with me Jacob Shulman, CFO of JFrog. Jacob, welcome to the conference.

Jacob Shulman

executive
#2

Hi, Pinjalim. Thank you for having us at the conference.

Pinjalim Bora

analyst
#3

Let's start with a little bit of an intro maybe about yourself and briefly about JFrog?

Jacob Shulman

executive
#4

Yes, absolutely. So I joined JFrog about 5 years ago, was really a small company, but over the efficient and generating cash flow, which was unusual back then in 2018. What attracted me to JFrog was I saw a significant business opportunity for DevOps adoption. And back then, they already were making significant adoption by large enterprises and that market has just continued to develop nicely for JFrog. JFrog for kind of maybe kind of step back, we're in the DevOps space. Our vision is to enable speed and security when people release software. So our vision is liquid software to enable seamless flow of software from developer key strokes all the way to devices. And kind of stepping it down a bit, every company that releases software has to go through multiple steps. And today, many of those steps are siloed, manual and inefficient. Most of the people know software engineers writing the code and software ran machines. But what in between is the huge industry full of those manual and inefficient vulnerable processes. So JFrog built a platform to streamline all of that and automate. So main value of JFrog is automation. Now every company that releases software has to go through the steps of converting the source code, which is people language into machine language as binary. Machines don't understand English or any other language. Machines understands -- machines understand 1s and 0s. So every company that goes and wants to release software has to build those -- convert people language into machine language into the binaries to incur by open source. And today, 80% to 90% of the application is comprised of open source. Even the best software, you need to build binaries. Then the next step would be to secure this application and physically deliver binaries to those machines that will be running the software. So that's what our platform does. Basically, we're focusing on software supply chain, which is primarily flow of binaries and we automate this flow.

Pinjalim Bora

analyst
#5

Yes. Thank you for explaining that. That helps. I get a lot of questions on what is binaries to start off with. But your core product is Artifactory repository or in other words of saying repository for those binaries, right? Help us understand what is kind of the alternative to it, right? Because software development has existed for several decades now. What is the alternative to using Artifactory repository? And what has -- is there -- has DevOps being a capitalist for people to choose a platform, something like a JFrog?

Jacob Shulman

executive
#6

Yes. So again, coming back, source code has been managed for like 4 years, and JFrog was a pioneer in binary management. So what happened in the last 10 years that required people to adopt tool like ours. There are several things that happened. First of all, change in architecture. People used to build monolithic. So far, they will get million lines of code. We'll take them about a year. We'll take about another 6 months to QA and they maybe they will release it once in 2 years. So that's completely changed. No one builds those monolithic software anymore. People use micro services so significantly increase velocity of software creation. Use of open source. Today, as I said, 80% to 90% of your application is written by someone else. So a company that wants to use this open source, bring it in the form of binary packages. Docker, right? Another change in technology that use of containers and containers form of binaries. People used to write or developers used to write on the [indiscernible] C++ developer. I'm a Java developer, no one does that anymore because today, developers call themselves, I'm a full stack developer. So multiple different technologies emerged to perform different development tasks. And for all of these technologies, it's different forms of binary files, different forms of executable files that build. So what historically has been done is that the company that would create this technology as the byproduct would also offer open hub or open source repository for this type of technology. Docker is a great example, right? Docker invented container, but Docker Hub was open source repository for this type of technology. So historically, what company have been doing, they build homegrown solutions to kind of try and automate and build those connections between open source repositories. JFrog came to this world and said, instead of managing multiple open source repositories, let's create 1 repository that will support all of the technologies and will be your system of record for all of the software that was created internally or brought into the organization externally. For example, one of the large companies that standardized on JFrog replaced more than 1,800 repositors with 1. They gave them significant control or [indiscernible] build. Just think about it as like in -- because if someone does not log into sales force, your interaction with the customer, you don't have visibility into what the pipeline and what's the engagement with the customer. Same kind of idea for us. If your developers don't build against Artifactory, you lose control of what is built. And so the Artifactory basically became the only system of record. And because binary files, they also include a lot of metadata about how it was created, what kind of license it includes, what kind of test it's gone through, what kind of dependence are there. It also became your database of DevOps, so you could automate a lot of processes based on this metadata. And that's why we see people kind of use this as a central tool for the automation of all of the DevOps processes.

Pinjalim Bora

analyst
#7

So the value proposition is you're removing the need to manage a lot of different repositories. You're removing a lot of people that would need to manage those different repositories.

Jacob Shulman

executive
#8

You also automate different tasks that developers, they want to be creative and write a code. But today, they need to do more technical stuff and a background and administrative stuff to manage the software release process. For example, developers use open source and open source is kind of hosted in open source hub. None of the organizations want their developers to go to open source hub and search for, for different open source components. Who knows what kind of vulnerabilities they're going to bring in. So Artifactory would serve as a proxy for them. Our organization would define a framework what open source hubs could be approached, what kind of security framework could be built. So instead of thousands of developers go into this, Artifactory does it automatically. And there are -- if you have multiple teams in different geographies, you want all of your developers to work against same set of assets. Artifactory will do automatically replication and all that. So there are a lot of things that today or maybe prior to Artifactory were done by -- manually by developers on administrative side, today is replaced by Artifactory automatically.

Pinjalim Bora

analyst
#9

So clearly, you have a kind of a critical position in the DevOps life cycle, right? We think you're saying system of records for binaries, there's a system of records for source code, which is the gate repository, let's say. But when we look at Artifactory, we don't really see much competition, right? You have Sonatype nexus, but other than that, that's also pretty small. There is not much competition. Why is that? What is so difficult in creating this repository?

Jacob Shulman

executive
#10

First of all, you're absolutely right that Artifactory became de facto standard. And today, we really penetrated in the largest organizations, 89% of Fortune 100 majority of Fortune 500. Significant portion of Global 2000 are customers. It's a combination of our first kind of mindset. We're strictly focusing on binary management and software supply chain, which is primarily flow of binaries. And we were able to build a very strong and scalable technology. But competition, as we think of competition, it's comprised of several tiers. First one, we talked about homegrown solutions. Second, there are companies in DevOps space. Sonatype is one of them, but we also know that some of their source code kind of companies put on their road map. They want to build some sort of binary management capabilities. And finally, we look at large clouds. First of all, large clouds, they're very good partners of ours, and we have mutual go-to-market programs, et cetera. But all of them have container -- container is a form of binary. We believe that clouds have slightly different KPIs than ours. Their KPI is how much traffic or compute we generate on their system. Our KPI is how we enable our customers to release software quickly and securely. We generate a lot of traffic, they partner with us, but they also want to be close to developers. So they tend to focus on solutions that optimize for data transfer. And our technology stack is much wider. We support not just containers, but various -- variety of different technologies, about 30 different technologies. Even to build container, you need several technologies, so we support in that regard. We also offer security, and there are 2 major differentiators on the business side that will be -- we believe in always in our favor. One is hybrid. None of the clouds can offer hybrid capabilities, and we believe that all enterprises, especially large enterprises, that have significant on-prem capabilities. It will take them years to get [indiscernible] Many of them will remain hybrid for any foreseeable future. And second, differentiator is multi-cloud. None of enterprises want to be just, let's say, AWS shop or Azure shop. All of them talking about multi-cloud capabilities and us serving as a kind of [indiscernible] in this space, we believe it's a competitive advantage.

Pinjalim Bora

analyst
#11

So let's talk about this critical position and how that helps you on the security side, right? Is there an inherent advantage to control that system of record for binaries that gives you an advantage to secure those binaries?

Jacob Shulman

executive
#12

Yes. So our platform is focused on main asset of software supply chain, which is binary. And if you think of all this flow from developer key strokes all the way to the device is primarily a flow of binaries. Therefore, hosting those binaries and control those binaries actually put us an advantage to be able to secure those. Now DevSecOps area is kind of new area that's evolving a lot of different point solutions. Many of them coming from different angles, more -- some of them focus on static analysis, dynamic analysis, container security, round-time security, software composition analysis. But what's common in all of them is that all of them integrate with Artifactory because they need this metadata. This data about the binary is about the software that organization creates and uses to build application. So we believe that native integration with our security solution with Artifactory and the fact that we have visibility across the entire supply chain, not just one kind of area, but the entire flow of binaries. Also those that even running in production, that gives us much better visibility and superior capabilities in that regard.

Pinjalim Bora

analyst
#13

Yes, interesting. So you entered the security space with Xray initially. And now you have launched the advanced security, which is further leaning you into the security space. Maybe talk about that difference, right? What does Xray provides and what does advanced security provide?

Jacob Shulman

executive
#14

Absolutely. So you're absolutely right, our Xray was the kind of first step in security space. If we own the repository and all kind of binaries control them, then it would be natural for us to secure them. So Xray was our tool in software composition analysis. What basically it does if your organization uses open source and Artifactory, we talked about it, and serves as a proxy of this open source repositories, then when you bring your open source component in the organization, Xray would scan it and we'll be able to identify whether the component is vulnerable or not. It also has capabilities of breaking even containers and the different components and say not just this container vulnerable, but containers many times comprised of different layers of different packages. It will be able to tell you what package in the container is vulnerable and you could apply different policies, whether you can alert that or you could block Artifactory from bringing this component to the organization, et cetera. So -- and that was a first step in this security for the security core. Now over time, I think the practice became that all of the steps throughout the software creation process needs to be secure. It's -- if you release 100 times a day, and one of our customers, Broadcom presented at our Analyst Day in February of last year. They said publicly that they released more than 6,800 times a day. So no one -- no CISO in the world can support this cadence of releases manually. So security practitioners understand that all of these steps need to be -- all of the security steps need to shift left and be introduced at earlier stages. There is no way a CISO could be with the switch off and push down on developers at the end of the process. So that's what brings the entire industry to the software supply chain, where every step in the process needs to be released. And our JFrog advanced security was our attempt to move kind of and create capabilities across this entire software supply chain. So we created capabilities more toward source code, static analysis and security detection, et cetera, and more towards the round-time with contextual analysis, et cetera. So it's our first a product that was released. It was released on SaaS back in Q4 of last year, made available for on-prem customers in Q1 of this year. And we have bridge road map and a few additional products will be released this year, and we'll continue to evolve this because, again, I think everyone understands that all of these steps need to be secured from -- for the entire software supply chain, and no one today has this full end-to-end capabilities. And that's why we believe Jfrog is well positioned to capture this market.

Pinjalim Bora

analyst
#15

Yes. Before we go further, is there a way to understand kind of the mix of the business between your binary repository and security?

Jacob Shulman

executive
#16

Yes. So Xray today sold as part of our kind of DevOps subscriptions because it's essential DevOps capabilities. And therefore, vast majority of our business comes from DevOps component. So again, our platform comprised of 3, of course DevOps, security and IoT. Have spoke about IoT , but it's like a smaller component, maybe I will touch about it later. So almost all our revenues come in today from DevOps and including Xray. And Jfrog advanced security just because it was launched just recently. It's very minor. We have over 15 customers in production. But we believe that contribution from Jfrog advanced security from security core will be meaningful in 2024. So 2023 is year of first adoption kind of [ setting the plant in the seeds ] in the ground. And then in 2024, when time comes for renewals and kind of decision-making standardization. That's where I believe JFrog advanced security will become material to you.

Pinjalim Bora

analyst
#17

Within that DevOps, what's the extra mix? It's like 25% is like a good guess?

Jacob Shulman

executive
#18

So about -- again, just because it's not sold separately, it's hard for me to put the dollar number, but I could tell you that about half of our customers have access or have access to subscriptions that include Xray. And about 2/3 of those customers actually using Xray in some form, where they're using some policies or some brands, some scans, et cetera. So not everyone uses that, but the majority of customers who have access to extra users of Xray and adoption of Xray continues to increase.

Pinjalim Bora

analyst
#19

No, that's great. So now on advanced security, that seems like an interesting product that's coming out. It's a product cycle. You launched it in cloud initially late last year. You said you launched in on-premise or self-managed recently. First of all, what is the applicability of advanced security across your customer base? Would you say it's applicable to 100%, 50%? How should we think about that? And so -- and the other part is you're basically saying that it will be a tailwind in 2024. Is that correct?

Jacob Shulman

executive
#20

Yes. So first of all, advanced security requires Xray capabilities. So therefore, it's only applicable today to customers who have Xray in their subscription. And obviously, because Jfrog advanced security has significant capability. We also see customers adopting more Xray because they want to have Jfrog advanced security capabilities. Second, no CISO in the world will replace the tech stack in 1 year, right? So therefore, what we're seeing right now is that those customers who went in production, went with the base starting package of Jfrog advance security because they want to try it in live production on a small subset of the team to compare to existing results to make sure that the flow is comfortable and all that and then they will be making decision on standardization. And therefore, we believe it's more '24 story.

Pinjalim Bora

analyst
#21

Yes. Okay. Got it. I want to switch gears a little bit and maybe talk about macro. That has been a consistent theme across software nowadays. You kind of saw a little bit of a better cloud consumption trend. It seems like in Q1.

Jacob Shulman

executive
#22

Yes.

Pinjalim Bora

analyst
#23

Q1 results were really good. How would you kind of characterize macro or the cloud consumption trends going into May at this point when you're talking to customers?

Jacob Shulman

executive
#24

Yes. So our expansion of our SaaS customers kind of comprised of 2 components. One is actual usage, transactional, and that's cloud optimization and all that, that we -- the kind of headwinds that we faced initially in the kind of second half of last year. And those subside. We talked about that the quarter started kind of very similar to December. But then in March, we did see that the actual usage of our customers across broad-based increased. Second component of expansion for our SaaS customers is migration of on-prem to SaaS. And that's where the judgment involved and the budget constraints and we continue to see some headwinds in that. Some deals pushed out even when customer got through POC, and then they need a CFO approval or someone from kind of higher level, and that's that got pushed out. On the other hand, we had deals that were pushed out maybe 2 quarters ago, didn't go in production. We gave this example of one of the large wins in Q1 weeks, which transitioned from on-prem to SaaS just because they realize that they cannot -- the business should be supported by a much more robust infrastructure, and they decided to actually move in production despite the project being delayed for a quarter or so.

Pinjalim Bora

analyst
#25

Yes. Yes. Understood. Okay. One common topic again is, obviously, this 2-letter word called AI. It is kind of taking software development by storm, starting with CoPilot. We're hearing more and more quotes for ServiceNow has its own LLM nowadays. We're hearing more and more of this, right, and there's no doubt. For everybody, I think, are thinking that, okay, this will increase productivity for software developers, which likely means they will develop more software as well. The pace of software development will increase. How do you see kind of GenAI? Is that -- is it right to think it could be a big tailwind for JFrog as that pace of software development increases, pace of binary increases, you need more usage of JFrog?

Jacob Shulman

executive
#26

Yes. So GenAI is more a language models, right? And again, we started this discussion that developers create or write code in people's language and what we manage is machine language, right? So definitely, it's the fact that developers will be more productive in creating code, which eventually translate it to more software being built and it means more binaries, right? So it's -- we believe it's a tailwind for us. Someone who will be using GenAI and will not have robust infrastructure for binaries management. So that will be the next bottleneck, and that we'll have to adopt products like ours. On our own product set, again, we're managing machine language and GenAI is less applicable. What it is applicable to is to provide more in general AIs is applicable to provide more insight in terms of security, analyzing different trends and data sets, maybe insights into what open source components better to use. So those kind of ideas that potential will be implemented in our products.

Pinjalim Bora

analyst
#27

Yes. Understood. Again, switching gears. You recently talked about a long-term model, which was very interesting to see in Q1. And it's an ambitious model. I think you're talking about a 23% CAGR over a 5-year period. I'm curious why now? Like why now the timing the macro environment is still uncertain. We don't really know. What are you kind of embedding some of the assumptions as you build that multiyear model?

Jacob Shulman

executive
#28

Yes. So the model itself is not new. What -- there are 2 new pieces of information that we added. One is what revenue levels required to achieve this model and what's the timing? Anyway, we'll ask these questions, and we actually never provided our own stance on that. And what we realized that led to a variety of different views, how JFrog would look like 5 years from now. And then we understood that we need to provide our own view how we see this business development and what we target. In someway agrees, and someway may disagree, but at least we thought that we need to provide our view how we think about it. Macro is cyclical, right? I don't think if I provided it in 2021, I would have been in a better position today, right? So it's -- that's why when we think about it, we think about long-term trends. And what kind of circular trends that we see will continue for 5 years and will be a catalyst for growth. And the trends that we thought about was, one, is the platform adoption. We'll continue to execute well in moving customers and customers adopting our platform. About 10% of our customers transition to the platform and the platform generates 44% of our revenues. It's growing over 50% year-over-year. So we believe there's going to be a long-term trend of customers adopting our platform, and therefore, it should support our growth in this 5-year period. Second long-term trend that we consider was SaaS adoption. SaaS adoption is beneficial for us. Our SaaS customers expand faster. Typically, when a customer migrates to majority of our customers on-prem customers. When on-prem customers migrate to SaaS, we see significant upsells on average 50%, 80% upsell. There are some exceptions where I gave a few examples where entry level into the platform customers, $120,000 of on-prem transition to even over $1 million customers for SaaS because they typically use this opportunity to adopt new capabilities across multiple regions. So -- and SaaS adoption trend will be long-term trend. If 2 years ago, none of the big banks thought about cloud. They are now making their first steps to transition to cloud. So it's going to be a long-term secular trend that will last for this period. And lastly is security. So we established ourselves as leader in binary management and DevOps side. Now we launched security capabilities. And we see that the adoption and platform play and security resonates with our customers. They cannot manage [ Sproll ] of these point solutions that provide multiple false positives, unmanageable, in actionable alerts, et cetera. So that security piece should also be a material component for us to achieve this long-term target.

Pinjalim Bora

analyst
#29

Is that -- does that also include any kind of new products as you're thinking through that 5 years?

Jacob Shulman

executive
#30

Yes. Over this 5-year period, we will add more capabilities on the security core. Absolutely. And some of these capabilities will be introduced this year and some of them over the course of this 5-year period. And finally, maybe this is the appropriate time to talk about our IoT, which is a small component today, but if you think about those billions of devices that needs to be updated and just think of driving cars and manufacturing robots and medical devices, right? Today is completely siloed process. Will this industry evolve to more automated updates and over the air base of the cars over the next 5 years? Absolutely, yes. So that's another component, which we planted seeds 2 years ago with the acquisition of UpSwift and we believe that this trend will expand in the next 5 years.

Pinjalim Bora

analyst
#31

Understood. That was a great plug on IoT. Yes. Any questions out there?

Unknown Analyst

analyst
#32

Within security, who do you see as the competitors you're looking to either displace or...

Jacob Shulman

executive
#33

Yes. So security comprised of several kind of areas of focus, static code analysis, dynamic code analysis, software composition analysis, container security, round-time security. And there are a lot of different point solutions that address those capabilities. So typically, we would see customers deploy multiple point solutions next to each other, up to 10 different solutions. And the customers that vendors that we'll typically see would be Snyk and Black Duck and Veracode and Mend and Aqua and Twistlock and Sonatype, those kind of vendors that we typically see in this environment.

Unknown Analyst

analyst
#34

How would you describe your gross margins for the DevOps piece and then how would -- versus security and then IoT? And then can you talk about the growth rates with all 3 of those different groups, if you would, please?

Jacob Shulman

executive
#35

Yes. So our gross margin, again, today, primarily a vast majority of our revenues comes from DevOps core, right? Security was just launched, so it's too soon to talk about security gross margins. On DevOps core, our gross margin is really dependent on type of deployment, whether it's SaaS or on-prem. For on-prem deployment, we have very high gross margins, like in 98% range. For SaaS, we have kind of margins comparable with SaaS companies, let's say, mid-70s, something like that. So the mix of SaaS versus on-prem, that what impacts our corporate gross margins. So far, we've been like in like low 80s, around 83%. But in the long term, we believe that cloud revenue will continue to grow as a percent of total revenue, and therefore, will be converging towards 80% gross margin overall.

Pinjalim Bora

analyst
#36

Can you remind the group what percentage of your -- like how many salespeople do you currently have? And how do you think about sales in the next 12 months?

Jacob Shulman

executive
#37

Yes. So historically, we've been growing through insight and inbound. And that's how we actually -- our products -- our factory got adopted into even largest organizations by just developers adopting the tool. Over the course of our life, we evolved our product and added security capabilities and build a platform. So to date, it touches multiple persona within enterprise. And that's why in addition to inbound, we started building kind of inbound and bottom up, we started to build top-down capabilities. About -- I want to say just before the COVID, we started building strategic team and then COVID happened, we paused it, but we now have a strategic team that touches C-level because selling platform is a more holistic approach to the digital transformation of the enterprise and it's more C-level decision rather than just developer decision. So this team already several tens of people, but it's not just quota carriers, but also high touch support is also product marketing and kind of field marketing. We also started investing into partner programs and partnerships. Again, economics different for partners when you sell full platform versus just $3,000 Artifactory. So -- and finally, we invest into our partnership with cloud. And we've seen great success in that. We work with all 3 of them. And today, our marketplace business is roughly 1/4 of overall SaaS business.

Unknown Analyst

analyst
#38

Great gross margins on the security and IoT pieces, are they materially different at all? Or would you expect them down the road to be materially different?

Jacob Shulman

executive
#39

So this is -- again, the IoT is just a very small piece in security. It will be more driven by the type of deployment rather than what core is used.

Pinjalim Bora

analyst
#40

Okay. I guess we're out of time here.

Jacob Shulman

executive
#41

Thank you very much.

Pinjalim Bora

analyst
#42

Thank you so much for your time.

Jacob Shulman

executive
#43

Thank you. Thank you.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete JFrog Ltd. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to JFrog Ltd. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.