SentinelOne, Inc. (S) Earnings Call Transcript & Summary

October 16, 2024

New York Stock Exchange US Information Technology Software special 100 min

Earnings Call Speaker Segments

Douglas Clark

executive
#1

Go ahead and get started. Welcome, everyone, and thank you all so much for joining. Doug Clark, Investor Relations here at SentinelOne. It's already been, in my opinion, an incredibly exciting day with demos, keynotes, customers and partners. Thank you all for coming in person here today, and thank you all for coming on the webcast as well. Before we begin, I would like to remind you that during today's presentation, we will be making forward-looking statements. These statements reflect our views and expectations as of today only. While we believe these forward-looking statements are reasonable, the outcomes are subject to risks and uncertainties, so actual results could differ materially from our expectations. Please see the risk factors on our most recent 10-Q filed with the SEC for further information about these risks and uncertainties. Furthermore, we undertake no obligation to update these forward-looking statements as a result of new information or future events. Additionally, unless otherwise stated, excluding revenue, all financial measures discussed in this presentation are non-GAAP. Please refer to our disclosures on why we use non-GAAP financial measures and the reconciliation of these non-GAAP financial measures to their most directly comparable GAAP financial measures on our Investor Relations website and filings filed with the SEC. So with that out of the way, we have a terrific agenda for you all today and a lot of ground to cover. We're going to be talking about strategy, technology, go-to-market and financials. And then we'll end with a Q&A session where we'll be taking questions from everybody in the room. So let's jump right into this. It's my pleasure to welcome Tomer Weingarten, our CEO and Co-Founder, Tomer, thank you very much.

Tomer Weingarten

executive
#2

Thank you. Okay. I got my own mic. This is a slightly different stage than the one that we had this morning, but really great to see everybody in person. I appreciate you guys all joining us. It's -- hopefully you've been -- a good experience for you all thus far. Would love to kind of dive a bit more deeply into really some of the foundational technology decisions that we've made over the years and our road map going forward, as well as what opportunity do we really see in the markets that we play in and how we plan to capture it. So first of all, the emphasis that we have put on building a true autonomous system cannot be underscored. To us, the only way forward in cybersecurity is by leveraging AI, is by building a system that can understand, plainly put, in real time the signal that it captures and then gets to a decision, finds an insight, and automates action to prevent a bad thing from happening again, simply put. This is what SentinelOne has said to build from day 1. We've done it on the endpoint very successfully. We're the only product in the market that has a complete autonomous, no-update-required capability that spans pretty much every supported operating system for compute devices. We've done the same for cloud security around workloads. And that is what you're going to see us do across every surface, in every capability, whether the native ones where we build controls that are designed to be deployed, or our data lake opportunity, which brings together the ecosystem of security products that folks have in their enterprise. So just a few principles for us. AI powered, we just talked about that. We've been an AI leader for, I would say, the duration of the company. We've innovated with AI. We pushed the envelope of AI for security. And now with the AI SIEM and Purple AI, we're ushering a new era for how you can apply AI at scale across the entire enterprise. One of the biggest challenges with AI, and this is not only in security, but more generally, is how do you make the data accessible? How do you make sure that AI can actually traverse all of these different data points in the enterprise? That's one of the biggest challenges, and Ric is going to talk more about how the AI SIEM and our security data lake back end solves that. And obviously, going after the entire enterprise posture is one of the most key elements of our strategy. Endpoint is an amazing market for us. But at the same time, it's very clear that customers out there are looking for full end-to-end protection, quality protection for every surface that they have. And in terms of the reach that we have, the entire go-to-market for SentinelOne has been built to extract every single part and reach every single part in the TAM, the respective TAMs that we play in. This is not a product that is designed just for Fortune 500. This is not a platform that can work only for a small/medium business. This is the same product, the same code base, the same technology that serves half of the Fortune 10, and at the same time, a 50-seat small/medium business. That is obviously tremendous power. The intuitive nature of our interface, the level of automation allows the system to be as applicable and as effective across the entire spectrum of the TAMs that we play in. And obviously, one of the things that we are very excited about is that we're starting to reach that breakout scale, the $1 billion in revenue scale. Obviously, we've IPO-ed about 3 years ago. We've since about 7x-ed our ARR since IPO in 3 years. But we're nearing this very rarefied air territory for cybersecurity vendors who cross the $1 billion mark. And obviously, it's just the beginning for us. So a little bit about what is different in SentinelOne's technology stack. And this is a great illustration that takes us through the generations of technologies, specifically around the endpoint and how they've evolved. Obviously, you'll remember, I hope, McAfee and Symantec, they were the big endpoint companies about a decade ago. They're no longer with us, and that's generally, I believe, a good thing. We have since moved into what you all know as EDR products, which mainly have leaned on making the detection capability accessible for a professional team in the cloud, thus requiring detection on one end and response orchestrated from the cloud. This is what we call people driving tech. This is what most security providers do today. This is why most of these systems require these updates to remain relevant, to be up to speed with attacks. And this is where we believe cybersecurity needs to scale, which is to the actual advent of AI driving these detections, not only for endpoints but for everything. This is where tech starts assisting people and not people just driving tech. That's why we believe that AI on device, the embedded algorithms that we've developed for years, are key to unlock further opportunities in the endpoint space and outside. And talking about these different components, behavioral AI and static AI were the 2 components that we developed about 7 to 10 years ago that reside on the endpoint. We've ported some of those to actually work completely in a detached manner for the endpoint and on different data sources. So as we go about extracting these other opportunities across the different facets of the enterprise, we're leveraging the knowledge, the know-how, the data science teams and the data that we've used for years to build these models, but we're now adapting them to solve different challenges. We've done that with our cloud workload protection suite, where it's the only cloud workload protection platform on the market today that has embedded AI capabilities that can actually detect threats in real time and prevent them, which sounds very elementary but it's actually something that doesn't exist outside of SentinelOne. And obviously, with the newly found generative AI capabilities, the foundational models bring us a multitude of different approaches and algorithms that allow us to then compound these 2 approaches, behavioral and static, with a grand orchestrating algorithm that can then stitch together multilayered modalities that can tackle many different challenges in cybersecurity, not just detecting malware-based threats, but also detecting user-based threats, anomalies, different types of actions that otherwise we would not have been able to discover unless we would have this algorithm that can see and stitch together these typically uncorrelated data points. Obviously, as we go about building these models, it's really important to state the principles that we take. We have always been very transparent in how we deploy, how we code, and how we audit everything we build. And with AI systems, it's even more important to make sure you have complete auditability and transparency with every model that you build. So you see some of these principles like transparency, safety, they are front and center with every single model with every single algorithm that we develop, and that's incredibly important. Customers today care about the safety of models. Models themselves, if they go unchecked, can cause damage on their own. So the safety of these models, the auditability, the move away from black box magic is imperative for cybersecurity to scale. And that really results in a more resilient architecture. As I mentioned quite a few times, if you look at how SentinelOne operates today, across tens of millions of protected devices across the world, it doesn't require a single update on average daily. The AI embedded algorithms are so effective that, for any other, any other comparative product in the endpoint market, this is a very, very different picture, where most of these products, by their own admission, by the way, need 10 to 12 updates on a daily basis to keep current with threats. That's obviously a huge difference in how detection is being made. It's not just about the updates. It's why are these updates needed and why are they not needed with a solution like SentinelOne. That obviously translates into some real-world outcomes that we all would love to avoid. No delayed detections. The delayed detection moniker sounds very friendly. It's just the delay detection. A delayed detection means compromise. If you can't react in real time to an incident that happens, that's where these incidents escalate into breaches. And SentinelOne has been a leader 4 years in a row in the Gartner Magic Quadrant. We're incredibly proud of the result this year. We were one of the vendors that made the most gains in the quadrant, while our 2 biggest competitors, I would say, have lost ground. So to us, this is another testament on the incredible progress that we're making in ushering this autonomous future for cybersecurity. And it's not just Gartner. You've heard quite a bit about our leadership in MITRE for years, but also beyond the endpoint for cloud security, SentinelOne is a leader. Once again, we have the ability to build best-of-breed capabilities. Not just another check box, not something that we're expecting customers to just digest from us, but a capability that is so good that they will choose it on their own, that stands in itself, where they can adopt it regardless of the other components, regardless of endpoint protection, regardless of anything we have. If they want the best SIEM in the world, they can find it with SentinelOne. If they want the best workload protection in the world, they can find it with SentinelOne. And that has been our approach with every single capability that we've built since inception. And just to give you a little bit of, I would say, a sneak peek into how this platform has come together, you see that there is full coherence in the order of capabilities that we've built over the years. And the ability to also support every and any third-party provider has put us in a very unique place where we don't have to force customers to go all-in with a single platform, rip and replace all kinds of different things, prebuying licenses, forcing to move away from different products. That is not the way. It is absolutely not the way. The open architecture approach that we've devised allows for flexibility. It allows for choice. And it allows for customers to weigh in their security decisions and choose the best product for them. It might not be SentinelOne all the time. We recognize that. We want to be applicable no matter what you have in your enterprise, be it one of our competitors, be it a cloud security company, it doesn't really matter. The ability for a backbone data lake to ingest data almost as a first-party citizen in the platform then allows for these 2 other layers that you see, which is the security operations layer with the AI SIEM, and then hyper automation, which we just talked about today. These 2 layers are generic. They work across every single product that you have in the enterprise, not just SentinelOne native surfaces. And obviously, the pinnacle of all of this is the ability to then apply AI processing on top of any piece of data that gets into that data lake, once again, whether it's SentinelOne or a third party, that is the game changer. The ability to stitch together the separate data points, siloed product into one cohesive AI-driven enterprise defense is unique, and it's what we believe is going to be the future of cybersecurity. And it's a pretty comprehensive platform to say the least. We typically don't like to parse into every single module that we have, and we don't kind of go out and say, "Oh, we've got 10-plus attached modules." Honestly, we don't care that much about the single module. We care about product lines. We care about the key capabilities, which are very simple to understand: endpoint, cloud, data and AI. That is it. Each one of those is a host of different modules in them. Some customers choose to go with some of them, some with more. It doesn't really matter to us that much. We are laser-focused at looking at these surfaces and adjacencies that obviously map into massive market opportunities in as their own product lines. Talking about the market opportunity, obviously, this is an incredibly sizable market no matter how you slice and dice it, whether it's the endpoint security market, which is still 50% of in the hands of the incumbents, or the data analytics market, which is a complete new opportunity, brownfield, to move away from incumbents with inferior architecture. And we've been in that movie once in the endpoint market. I just talked about McAfee and Symantec and where they are today. That is solely due to antiquated architecture and the lack of ability for some of these companies to reinvent, rearchitect and redeploy technology. And technology for data analytics that was developed 15 years ago is not going to scale in the petabyte age. You may sprinkle some new stuff, but the actual engine is not going to be rewritten. It just doesn't make any economic sense for some of these companies. That represents a tremendous opportunity for SentinelOne. And obviously, the cloud security market, pretty pristine greenfield opportunity where every single workload that's deployed, either in the public cloud, private cloud, hybrid environments, on-premise, and everybody has an on-premise environment. There's very few companies that only do public cloud stuff. So when you look at all these newcomers for public cloud, it's really clear they're not covering the entire gamut of workloads that you have in the enterprise. And this is something that only SentinelOne, maybe a couple of other vendors, have the ability to cover today. So a great opportunity that lies in all of these data centers. There's actually an interesting move these days to take more and more workloads on premise, which actually bodes really well to the opportunity and how we see it. So I really believe there's going to be a new dawn for cybersecurity in the next 2 to 3 years. And we believe that we're incredibly well positioned to change the face of cybersecurity more than we have been in the past decade or so. It's definitely not a solved problem. You can just see that from the amount of breaches that still happen day in and day out. The amount of different products, the disjointed platforms, the claim to fame by some other platforms that typically lead customers to rebound back into a best-of-breed capability is something that we see more and more. And as I mentioned, more modules don't mean better security. It just doesn't. It does definitely add more complexity. So for us, taking that autonomous approach, a unified platform, simplicity, scalability, and moving security to be real time is the goal and is what we believe is going to lead the cybersecurity market in the next few years. So as I mentioned, the real-time security aspect is so incredibly important that we're also seeing customers starting to open up to the idea that something is wrong, that the way that things have been done to date are not contributing to better security. And first and foremost, it's that need to have a system that sees events in real time and not after the fact. It sounds very, very trivial, but it's not. And there's no system out there that does that today. If you're looking at to the SIEM market, as an example, is this data aggregator of today, these systems are not streaming systems. They're not real time, they can't even query a petabyte of data in under a second. Typically it takes them a few minutes. So obviously, that cannot be the answer. So the move away from leaning on all the models of the past that are failing us every single day I think require and necessitate that question in the customer mind of, what comes next? And how do I solve these challenges. And we believe we have some of the best ingredients in the market to solve those exact issues. We're executing well across our entire strategy, whether it's go-to-market or technology and customer acquisition. We've been one of the fastest-growing software companies in the public market bar none, in the entire software universe. We're acquiring customers across every part of the TAM, whether it's the largest enterprise customers, all the way to SMBs, to our MSSP ecosystems, OEM partnerships, on-the-box motion, and platform expansion with existing customers. We have always believed in a very friendly go-to-market approach which empowers our partners to be an augmentation of SentinelOne. That is actually have been one of the most important elements in the past few months as a lot of these partners, shared partners of ours and our competitors, have turned back to SentinelOne to ask how can we hope with expansion motion that might have been halted with other vendors. So being there, being a trusted vendor and partner to data ecosystem has been critical at this time. So obviously, we got a pretty significant amount of growth vectors that we're executing across and are growing towards. Not only our go-to-market is wide reaching, but our ability to now go into new markets -- these are very pristine. The opportunity is not even 50% -- or close to 50%, much like the endpoint market. These are new opportunities. The data market is a new opportunity for us and for every other vendor out there. The cloud security opportunity is just in its first inception. The reason these markets at this stage are important for us, it's because there has been a definite sentiment and a change in consideration for what SentinelOne can do in light of some of the shortcomings of some other vendors. So as we look to the next few years and growing our customer base across these different TAMs, that consideration at this point in time is key. It puts SentinelOne as a front contender for all these new surfaces in the enterprise that represent the vast amount of that $100 billion target addressable market opportunity. Let's dive into the endpoint market. It's been the core of what we do. And as I mentioned, still about 50% of it in the hands of some of these antivirus incumbents. We have been gradually taking share year after year, and we've been the vendor that takes the most share by percentages every single year, growing faster than anybody else. Both our competitors have stagnated in their market share acquisition. SentinelOne keeps on growing significantly within the endpoint market. These percentages, some of them, for some vendors, really mean 10 million, 20 million, sometimes 30 million devices. If you think about some of our new partnerships, like Lenovo, that's a 30 million device partnership over a few years. Imagine what it can do to transition away market share and change this pie chart. Speaking of that, not only we believe that the Lenovo partnership is transformational for the endpoint market, and again, this will be gradual over years, enabling a large company like Lenovo with all these distribution channels takes time. But once this is up and running and it's embedded within Lenovo's ThinkShield offering, which is a key component, key growth component for Lenovo, that will, of course, accelerate SentinelOne's market share in the endpoint market. I'm also really excited about this one. We are sharing for the first time that our cloud security business has crossed $100 million in ARR. That's obviously significant scale for any player in the cloud security market. There's almost no other established players, probably 5 players in the entire cloud security market, that are at a scale of $100 million plus. It's us and some of our competitors. Having the ability to do that mostly on a workload protection suite, we just onboarded complete CNAPP capabilities, a complete CNAPP suite, just lately, which means that most of this growth has actually come from run-time workload protection, which is still an underpenetrated market. So this is an incredible achievement. This business is growing faster than the overall business. And now with our CNAPP suite, we expect more expansion with our customer base. Speaking about a customer example. This is a small land 2 years ago with just a portion of the workload environment, side by side with another incumbent on the endpoint side. And within 3 years, what you're seeing is a 10x expansion including the endpoint environment that was once again owned by a competing product. So the ability to land inside of the cloud security domain, regardless of the endpoint provider, is a door for us to continue and expand into other footprints even if the endpoint footprint has already been deployed by a different vendor. We don't need to buy it out. We don't need to prepay the licenses. We don't need to screen platformization. We just need to deliver really great security and customers naturally expand. And another incredible achievement is our growth with our data business, which has now crossed $70 million of ARR. This is significant growth. Significant growth. And it comes on the back of data ingestion. It comes on the back of data lake sales, AI SIEM sales. All of those go into our data business, which is growing even faster than the cloud security business. So as you think about SentinelOne today, we already have 3 fairly established growth engines, definitely with endpoint, but also with cloud, and with data that will continue and sustain us for years to come. And our Singularity AI SIEM solution is actually very unique in how it can be deployed. And that's critical to unlock the data analytics opportunity. Our data analytics solution, our AI SIEM is not only a product to rip and replace an existing vendor. That sometimes take a lot of time. Some customers have a pretty difficult time even mapping out what that could look like. But all customers have net new data that they want to store and that they want to make accessible. Transitioning versus transforming has been a unique market motion to SentinelOne that allows us to deploy side-by-side and provide an off-ramp from your existing data solution and into Singularity AI SIEM. We can also transform entirely. We can take away all data storage from your existing SIEM. But we recognize that this market moves at different pace for each and every customer and use cases are quite unique. We believe the full unlock of this entire TAM, which means that we believe that our AI SIEM will be applicable to every opportunity, that's probably about 12 months away from where we are today. It's still a significant amount of the market that we can serve today. One of the things that's incredibly important to remember, customers don't, if they're already existing customers, for each and every one of our capabilities, they don't need to deploy anything new. The platform that they own, if they bought an endpoint license or a cloud license or Purple AI or identity security, is already the data backbone. They, in essence, can start ingesting data from third-party sources from the moment they wish to, if they already own the platform. They actually get some free tier of ingestion to start doing that without needing any interaction with SentinelOne. And that data growth is, much like the cloud story, is yielding expansion opportunities naturally. This is a significant deal we've signed for a federal customer where we started by onboarding an AI SIEM capability and through the motions, we also recognized or the customer, more accurately, recognized, that they can benefit significantly from our endpoint capabilities and then opted to buy endpoint and replace the incumbent that was there. So a market motion that's predicated on data, different sellers, different use case, different problem set is yielding naturally more expansion into other surfaces given the complete integrated approach for the platform. And there's so many, so many reasons for these customers to move away from these incumbent solutions. Speed and cost are definitely the most impactful ones. On average, we see 50% cost savings. I've seen 80% cost savings, I've seen even more than that. It really depends on the current set that the customer is using and what they're ingesting into their existing data solution. 80% faster, we're being very, very kind with these stats. I've seen cases we're 80x faster. All data you store with AI SIEM is hot data. For those of you that have covered maybe the data analytics space at some point in time, you always had that notion of hot data and archived data and cold storage and all that stuff. Why? Why? Why do we need that? We need all data accessible for his long period as we can. And we need it to be fast. And that's what AI SIEM can deliver through to today. And when you couple all of that with Purple AI, the advantage starts being significant in a way that's incomparable to almost any other vendor out there. Purple AI has the ability to bring together all these different data sources that are plugged into the data lake, and stitch them together and uncover the hidden patterns that otherwise, we as humans, and no matter the size of the team that we have, are just unable to find. And obviously, being able to do that in real time is a pretty significant game changer for the entire security market. Couple that with natural language interfaces, with auto-triage, with auto investigation, and you're starting to shorten the cycle of how we do cybersecurity in a very, very significant way. And obviously, customers are starting to see incredible productivity gains from even using the first-generation capabilities we've released to market in the last couple of quarters, We've talked about and we've seen really great traction. I mean double-digit attach within the first quarter of selling. Just phenomenal traction. Just to recap, significant opportunity, open TAMs, best-of-breed products, a great strategy to overhaul cybersecurity, that's why we believe SentinelOne is an enduring company. And you see some of the team here today. We don't pick them just by height. I had to make that joke. Just incredible people. Obviously, you're going to hear directly from them. Ric, who's been in charge of taking all these amazing concepts of products and actually making them something that runs and deliver, has been with us for a while, and it's driving everything from technology to product to now cross company operations. Barbara, that just joined us, is a significant force multiplier for us with everything above and beyond finance and the operation of the company. And obviously, Michael, which I think we've talked to most of you about, at least in the past 4, 5 quarters, on the level of impact that he's been bringing to the go-to-market organization, and they join a long list of folks that have been with us for quite a few years. And I would say, beyond everything else, the culture throughout the company is a culture of trust, a culture of transparency, and a culture of delivering on our promises. And you see that going through each one of these leaders. Speaking of that, it's also been reflected through so many different accolades. Sometimes we go through those, they seem very generic, but SentinelOne has actually been the highest-rated cybersecurity employer on Glassdoor for the past, I think, 4 or 5 years. This is not an easy feat. We can't game any of these things. This is people and what they believe and what they think and what they choose. So you're seeing one of the fastest-growing cybersecurity companies, we're the fastest-growing software companies with the highest rated culture, with best-of-breed products that lead the market with AI, I would say SentinelOne is a tremendous company. Thank you all. I think this is where we're going to switch and get you some actual technology talk, but I appreciate the time.

Richard Smith

executive
#3

All right. Good afternoon. Thank you for having me here. It's great to have your attention. Thank you for spending the time with us. So speaking of culture, it's no secret that we take great pride in protecting our customers. It's at the core of who we are. And over the past 12 months, we have witnessed and responded to a shifting landscape of threats. And our platform, which processes over 1 trillion events a year, even from -- everything from small businesses to Fortune 10 businesses worldwide, we get a very clear view of that threat landscape. It's enabled us to see things like 90 different ransomware groups, including new and emergent threat actors like RansomHub, Hunters International and Black Suit, are making their mark on the cyber crime ecosystem. And despite the challenges that we uncover, we've done a great job of protecting our customer base. We detected and blocked over 0.5 million ransomware attacks. We've stopped over 1,000 human-operated ransomware intrusions. We've identified over 300 malware variants, including notorious variants like Pikabot, Qakbot and [indiscernible], say that 3 times fast. But that proactive and relentless defense has been instrumental in stopping ransomware campaigns from infiltrating critical systems. We've stopped everything from state-sponsored actors from attacking critical infrastructure, to stopping malware that targets the health care and financial sector. And when we're not busy defending against these external threats we're defending against internal threats for our customers. So this would be employees making misconfiguration and cloud environments. But no matter how or where, we take great pride in being the first line of defense for our customers. So let's talk about where we're going. So as an industry, we've done a great job of being able to identify threats, whether that's through malware, intrusion or anomalous behaviors. But as threat actors grow more sophisticated and we see more threats, the challenge and need for innovation is actually shifting towards response. This includes the areas of things like triage, investigation, threat hunting, orchestrated response and orchestrated remediation. And that's why we are taking a multilayered approach and breaking new ground in the area of response based off of our leadership and detection. We take Purple AI as an example, that empowers teams to ultimately respond and remediate nearly autonomously, driving down response times from hours to minutes. And that's a huge win, not just in terms of cost cutting, but reduction of risk exposure. Our AI SIEM actually takes things a step further. It provides a seamless user interface that removes contact switching from the analyst. And it also provides AI affordances that automate key tasks, bringing greater efficiency and accuracy to those teams. Now we're not in the business of replacing human analysts, but we are in the business of making them better. And it is very rare that you find a technology that simultaneously makes your teams faster, better and more cost-effective all at once. But that's exactly what we're trying to do by autonomizing security operations and pushing the frontier of response. Now since July 19, you can't talk about security without talking about architecture and secure-by-design. Let me start with we are a technology company, first and foremost. We are not a consultancy using technology to scale our services. That distinction is critical. Now based off of a recent congressional hearing, we are fully aware that our nearest competitor delivers 10 to 12 content updates per day. In comparison, we do the same volume of updates over the span of a quarter. The difference comes down to approach. We leverage AI to interpret events and make real-time judgments on the endpoint. In comparison, others stream that telemetry to a data lake where analysts sift through that, sometimes assisted by machine learning, but ultimately, when they make judgments, you're getting a delayed judgment. This is often overlooked when we talk about these 2 distinct companies. Furthermore, when we deliver a content update, it's meant to inform our models about new techniques that we've discovered in the threat landscape. It's not signatures, it's not regular expressions. When we deliver those content updates, they are delivered in 2 processes that are operating in user mode, not kernel mode. This is exceptionally important because it means our risk is narrowed down to stalling or crashing an application, not taking out an operating system or potentially stalling business operations. When these content updates or software updates, or if we update our cloud environments happens, this is done through a progressive rollout that is controlled. We do not do updates across our entire customer base at once. We also put customers in control of these updates. So within their own environments, they're allowed to opt in and out of content updates as well as versions of our agent. This gives them ample time to test within their own environments before they roll out to their global enterprise, giving them more control of those environments so that they do not interfere with business operations. Now the proof is in the numbers, but on our stats when we look back over the past 24 months, less than 0.5%, 0.5% of our customer base have reported a significant issue. When we're not talking about architecture or security by design, usually in this industry, we're talking about security as a data problem. And ultimately, how that compounds an overwhelming talent shortage within the industry. Now these teams are ultimately stunned by the volume of data that they have to contend with. Because security platforms and data platforms are taking trillions of events and trying to distill that down to something meaningful. And as I stated earlier, we've gotten a whole lot better at identifying threats, Heck, we've even gotten better at defending despite the growing volume and sophistication of attacks. But overwhelmingly, there are 2 things that remain a significant challenge. First is, how do you deal with all of the threats you've identified? Most organizations are too constrained in terms of resources and budget to be able to get to the bottom of those backlogs, which means that they remain exposed. Secondarily, even if you have the data, often the insights are poor quality due to lack of correlation or lack of enrichment. And that disconnect prevents you from being able to take meaningful action. Now to get true context and to do informed decision-making, you need to centralize that data into either unified data lake, federated solutions and create a complete real-time view. Today's technology is too difficult to operate, too costly to operate, too complex and too slow. And addressing these challenges is really key for us to be able to keep up with an ever-changing security landscape. With our AI SIEM, we address both the data collection problem and the overwhelming deluge of data. This empowers our customers to take trillions of data points and distill that down to meaningful insights that actually deserve their attention, in priority order. In addition, it allows us to take on the ability to recommend a response or actually, if they prefer, we could do those responses on their behalf. Putting this into context, it means taking trillions of data points, distilling that down to 5 alerts, 3 of them are already on their way to being triaged by an intelligent assistant in the background who's been working diligently on their behalf. Now they say in marketing that if you provide too many options, it actually causes a lot of problems with the consumer experience, or in our case, the user experience. The reason that we saw in retail, a shift from big box stores down to curated brand-focused stores, which ultimately makes the buying decisions a lot smoother or the decisions of the user a lot smoother and ultimately translated to one of the largest market capitalizations in retail. We're seeing that same trend right now within Web search, which is akin to that big box operator and a shift over to AI-driven searches, which provide that very curated view that's summarized and easier to understand, or that niche play like the Apple Store. We are taking those same principles and applying that to the security context by providing analysts with a curated view that gives them the insights they need in priority order to protect their businesses. We see this as the greatest unlock within the cyber industry. Because as I stated earlier, it's very rare that you find technology that ultimately makes your teams faster, better and more cost effective all at once. Now, how do we actually do this? How are we capable of doing this? Well, we were the pioneers on endpoint automation, which really means that we are experts in building models that can take an understanding of deep context of processes, network traffic and identities and stitch that together in a very resource-constrained environment. When you look at AI SIEM, we're taking those same principles, that same expertise and we're applying that broadly across the security ecosystem. And what that translates to is that when you look at the CISO's portfolio of products, we can take all of those automations around triage, investigation, response, threat hunting and remediation and apply them broadly to the CISO's portfolio of products. That ultimately means that they gain the efficiencies that we can provide of our platform broadly it saves them money and it drives down the response time. If you give a customer, swift access to triaging alerts and you drive down their costs, you get 2 great outcomes. Those outcomes are simple: Better security, happier customer. AI data-driven approach extends well beyond AI SIEM and Purple AI, it translates to every surface that we touch. So when it comes to our endpoint security product, our cloud security product, our exposure management product or our identity-related products, all of them benefit from these same capabilities. And that's all delivered to you on 1 platform, with 1 agent and 1 unified view. And ultimately, we see taking the tedium out of this and automating these things, not just in terms of cost saving reduction, but we also see that as the future of security because, in our belief, applying AI to human operations is really about generating super human successes. So with that, I would love to give you guys a demonstration of Purple AI to show you how it's helping our customers succeed. [Presentation]

Michael Cremen

executive
#4

Okay, great. Now you can certainly see why our customers are loving Purple AI. I, just a few hours ago, in the main stage of the OneCon event, I moderated a -- thank you. Thank you. I moderated a customer panel. And I got to tell you, the whole room was buzzing when we had customers talking about the applicability of Purple AI, not just solving problems but creating opportunities. And I got to tell you, probably the highest in demand and shortest sales cycle in terms of our product I've seen that's great for customers and wonderful for a CRO. So thank you very much. My name is Michael Cremen. I'm the CRO, as Tomer mentioned. I am really glad to be with all of you and be able to talk to you a bit about our go-to-market. A couple of things. It has been an interesting few months in the industry for sure. The threat landscape continues to explode. AI-led attacks are on the rise. One of the #1 concerns that customers talk to me about is that attack surface and trying to manage those very dynamic and expanding environments that need to be protected, one of the reasons why AI and autonomous protection is just resonating more than ever before. With the global outage the conversation with executives at customers and with our partners into customers is not so much about brand market share, it's about what Ric talked about. It's about quality, risk mitigation, architecture, process, resiliency in a cybersecurity strategy, really, really important and something that's happening all over the world across all segments and in every industry we're seeing that. So I got a -- I received an e-mail from HR on Monday, now it wasn't a bad one, congratulating me for being at SentinelOne for a year. And I knew it was coming up. I didn't know which day, but it went very, very fast. I know. And I will tell you, it reminded me of why I decided to join SentinelOne. First of all, in almost every company I worked for, it's been hyper-growth, disrupting a market, which is always exciting, exhilarating and the place to be, certainly bringing a whole new level of value to markets and customers with partners. The partner aspect, by the way, was really important. The commitment we have to our partner ecosystem was tremendous. But when I started really digging in and understanding how special the technology was and the fact that SentinelOne was so far ahead in terms of, from the beginning, placing AI into that agent, and the autonomous approach and more of a technology driving and helping people versus the reverse was just big. And then, of course, again, in my job, the TAM is really important. And every time I looked, it got bigger, really exciting. And then the other aspect, talking with Tomer and other executives, was understanding not only the level of ambition for the company, for our customers, but also where we are at in terms of size, scale, scope, from a size of organization, go-to-market piece, overall business ARR, and it really fit well into what I've done and my track record in terms of coming in from a go-to-market leadership perspective and being able to scale into the billions with the company. So that all came together very nicely. And we haven't looked back. I haven't looked back for sure. It's been tremendous and a lot of fun. Now there was a great foundation upon which I was able to come in and build on. So let me be very clear, I'm standing on the shoulders of people before me. But what I'd say to you is we really work to accelerate the good and transform into new areas. And if you take a look, over the last 3 years and this past year, we built on this, and that was really significantly accelerating growth. And the 3 areas we put immediate focus on were really around us expanding our customer base. And we measure that, when we look at customers that are $100,000 plus in terms of ARR. And you can see they're 3x over the last 3 years. And then looking at the enterprise and really moving deep into the enterprise segment. It's actually where I've come from with all my previous companies across all the big industries that represent enterprise. And we certainly look and measure at $1 million-ARR customers, and you can see unbelievable growth there in the last 3 years. And we're really proud and excited about that, and that trend just continues and there's big, big tailwinds there. And then finally, it's overall, not selling products, but selling a platform and expanding and extending well beyond endpoint as Tomer and Ric both talked about. And we're able to then look at an average ARR customer and seeing that increase significantly to measure our success there and really a platform selling. And you can see they're 2x after the last 3 years. So we're proud of this. We're not stopping here by any means. This continues to go. But it's important measurements of our business and the progress that we've made in the market. The #1 lever through all my experience in really scaling into the billions is the partner ecosystem. And what I'd share here is, coming into SentinelOne a year ago and taking a look at the commitment we have made to partners, and then looking at the different categories of partners, it can be complex. And if there isn't an integrated holistic approach, there can be confusion and friction in the marketplace. And so one of the first things that I did was take a look at everything we had set up in terms of partnership and do just what I said, holistic approach, really understanding all the categories of partners and understanding their business and where they were going, and meeting with them there, but then also bringing in a level of talent who are proven with these entities, they're well-known entities, but also proven in terms of understanding whether it's MSSPs, cloud service providers, OEM, all the way through all the different components here, but then developing an integrated strategy that's relevant to everybody. So all of our partners around the world have a good understanding of where they sit in our go-to-market strategy, what we can bring them, designing programs that are very beneficial to their business, and really starting to see a true force multiplier. And this is the foundation in this partner ecosystem that's going to lift us over the next 3, 4, 5 years, which is vitally important for us. This one may not seem as sexy, I'm sorry, but the reality is, it's vitally important. And as I said, there is a good foundation, but really hardening, I'll call it, the fundamentals from a sales and field and go-to-market standpoint are key, and really looking at all aspects that you see here, of course, pipeline's crucial, really understanding different ways and levers around creating more and more pipeline and managing the business a few quarters ahead from a pipeline management standpoint as well. Really took a look at all the important functions and bringing an enterprise-class level to them, things such as revenue operations, sales enablement, our renewal organization. I just talked about our partner ecosystem. But really having seasoned leaders that have operated at scale and significant growth trajectories able to come in and bring a new level of maturity to these type organizations and functions and really build for that future, again, is vitally important. The work we've done collectively with my good partner here, Eran, from a customer success standpoint, really looking at all the ways that we touch a customer, from our partners all the way through to customer success, our renewals team, our account team, and making sure that we have the right approach there and that it's seamless with customers is vitally important. And then I talked about platform selling. The only thing I'd say is building a high-performance culture, really, really key, and all the aspects that go along with that. And then finally, and really what you start with is a operating model, the way that we run the business in the field day in and day out, and you cast this net across all aspects of that and you start building significant consistency, predictability and sustainability. And that's exactly the path that we're on there. Look, I wanted to be brief. I want to let everybody know that we're just getting started. But it's a pleasure to be here with all of you. It's been great at SentinelOne. And I'm very bullish about the future. So thank you so much, folks. I do appreciate it. And I'm going to turn things over to our CFO, Barbara.

Barbara Larson

executive
#5

I'm going to take the stairs, guys, instead of the big leap of faith there. Much better. Good afternoon, everyone. It's great to be here. It's nice to see some familiar friendly faces in the crowd as well. So as you've already heard, there is a lot to be excited about here at SentinelOne. But let me share a little bit about why I'm particularly thrilled to be here. And first and foremost, it's technology. SentinelOne is a clear leader in innovation. We're not just keeping pace, we're setting the bar and that is really powerful. Then you've heard, there's the culture. The leadership team here has built a culture where innovation and collaboration seamlessly come together. It's rare to see that blend, and it's a key driver of our long-term success. And of course, as a CFO, I was drawn to the large market opportunity, the mission-critical nature of the technology, as well as the growth and financial profile of the company. After 1 month in the seat, I can see the opportunity here is substantial, not just for scale, but for operating leverage as well and I'm really excited to be here and help drive that forward. So SentinelOne has been on an incredible growth journey. You can see that here. Again, the fastest-growing company in cyber for years. That's no small feat at all. Driving that growth is a powerful combination of new customer acquisition as well as deeper partnerships with our existing customers. Our ARR grew 32% year-over-year in the most recent quarter. And we're well on our way to surpassing that significant milestone of $1 billion in ARR. As you all know, being a subscription business, our revenue closely tracks our ARR growth over time, resulting in 33% year-over-year growth in our most recent quarter for revenue. And looking ahead, we see significant disruption in our core endpoint market. With that disruption comes opportunity to capture market share. And we're laser-focused on that opportunity and making the most of it. Beyond that, we're also addressing and succeeding in multiple large markets. You heard Tomer reference earlier our cloud security solution has now surpassed $100 million in ARR. And we're already more than $70 million in ARR with our data offerings. Both are growing at a really rapid pace and are key growth drivers for our business going forward. Now as impressive as this revenue growth has been, our margin expansion really sets us apart and it highlights our focus not only on scaling up but operating more efficiently as well. So we take a lot of pride in our best-in-class gross margin. Last quarter, we delivered 80% gross margin, and we're forecasting 79% for the current fiscal year. That gross margin performance reflects the power of our platforms, strong unit economics, our disciplined pricing, and our unified data architecture. We're also seeing significant improvement in our operating margins over time. Over the last 3 years, we've really seen that operating leverage start to kick in and drive profitability, again, underscoring our growing scale as long as -- as well as our strong unit economics. And then in line with our operating margin, we've made solid progress expanding our free cash flow, which will fuel our ability to continue investing in innovation. But this is just the beginning, and we're well positioned to continue building on this momentum. So now let's take a step back and look at our margin journey through a broader perspective since our first quarter as a public company. So the long-term targets you see here on the slide, these are the same long-term targets we outlined during our IPO just 3 years ago. Look at where we are today, they're in the middle and the progress we've made since our IPO. We're already operating at the high end of our long-term gross margin target, 80% in Q2. And beyond gross margin, we've delivered meaningful leverage across every line item. Overall, we're delivering on our commitment to build a scaled and profitable business. So where do we go from here? We're operating in an incredibly dynamic market environment right now. But one thing is clear. Our focus on our customers and security has been and will continue to be the backbone of our success. Agility is our advantage right now. We're staying flexible. We're adapting, evolving and building an organization that can seize on the opportunities to succeed in today's environment and well into the future. In the short 30 days I've been on board I clearly see an opportunity to drive continued leverage and strong growth. So to that end, we're balancing growth and profitability. That continues to be at the core of our strategy. That won't change. We're sharpening our focus on delivering results with discipline and capturing the large opportunity in front of us. So thank you, everyone, for joining us today. Hopefully, today's session gave you a clear picture of the opportunity that's in front of us, where we're headed as well, as what's next for the company. So with that, I will invite my colleagues to join me back on stage, and we'd be happy to answer any and all questions you might have.

Douglas Clark

executive
#6

Okay. Perfect. While they're getting set, we'll take questions. Please limit yourself to 1 question. We'll go back and forth between the room and appreciate the time. We'll start over here.

Brad Zelnick

analyst
#7

Brad Zelnick with Deutsche Bank. And thanks for the time and the presentation, and the keynote this morning was fantastic. I wanted to drill into the OEM opportunity and what you've spoken about now multiple times, specifically with Lenovo, and maybe more to come. For those of us in the room that remember the prior generation, and I'm looking to some folks that have been doing this for a while, the endpoint companies of last generation actually were paying the OEMs for placement fees. Now this time around, the deal that you have, we understand that they're paying you. So tremendous opportunity, I think, across multiple different facets. But I think there are a number of questions as well just in terms of how the opportunity flows through to the financials, and just any comment about the value and perhaps the ability to then successively penetrate other OEMs and use this as a leverage, as you said, to go out and go after the 50% plus of the market that are still using legacy products out there.

Tomer Weingarten

executive
#8

Right. So definitely a very different world between what the incumbents have done in the past decade and what we're seeing today. And by the way, this is not just for SentinelOne. One of our competitors have I believe a similar economic deal. I think what you're seeing more generally is a lot of these hardware companies are looking for more software-based ways to maximize and continue and capitalize on the reach that they have. So when they look at something like our AI capabilities, they're getting basically a 2 for 1. One, they're getting better security, which I think everybody wants. It creates a great differentiator for them. AI-based security for the AI PC sounds like a pretty compelling offering. And the second part is it allows them to build a host of services, managed security services that provide for another revenue channel for them. Taking it back to us, you asked about the economics of the deal, it's fairly simple. This is a subscription-based business, we get payment per license. And then we have the opportunity to activate the customer for the out years as well. So it's a very simple reseller-like approach, only it's something that is pre-bundled and attached to the already preexisting engine for the PC sales, which is, for us, the benefit here. And for Lenovo, obviously, just another avenue for growth. They charge a price point for that offering, for the entire ThinkShield offering. Part of it we get, part of it, they keep. So it's a growth engine for them on the software side. It's a great growth engine for us. And also, as I mentioned, the out-years opportunity is also reserved for SentinelOne. So it's something that will take a number of years to fully unlock if we do it right. Enablement is a big part of it. As I mentioned, Lenovo is a very, very big company. Training their entire sales force to speak security, to speak AI security, will take a bit of time but they are, I think, fully committed. I've been pleasantly surprised by the level of commitment by Lenovo. They just had their own event a couple of days ago, ThinkShield, AI security and SentinelOne has been front and center. So it's just great to see. It seems to be a great partnership. And I also believe there's more OEM partners across different swaths of the endpoint market that are looking to do the same things. The ability for our platform to work in an automatic, autonomous way, which we've talked so much about today, is critical for some of these providers. Not all of them want to stand up a full service. So you really have to have a product that's almost consumer grade. Now I would not suggest that we will take SentinelOne to consumer anytime soon, or maybe never. But that level of automation makes it a great candidate for OEM partners to put on their machines knowing that it's kind of a fire-and-forget type of an offering versus almost any other endpoint vendor in this space.

Brian Essex

analyst
#9

Brian Essex from JPMorgan. Tomer, I think you said in the past that you were growth-constrained because you're focused on margins, and clearly hitting that, approaching breakeven for profitability and cash flow is a substantial achievement. As you kind of look forward, now that you've kind of hit that level, investing for growth, where would you say like top 3 areas of growth investment are? And how do you manage growth versus profitability now that you've kind of achieved that milestone.

Tomer Weingarten

executive
#10

Yes. It's -- obviously, that's the eternal question with us, and I always have a slightly more refined view on that as time progresses. I think, first and foremost, we see the market opportunity, and that's what I think Barbara sees and Michael sees as well, we want to capture it. We definitely don't want to taper away with sales and marketing. So that would definitely be one area of growth. A lot of our philosophy around how we grow in the next few years is a reinvestment philosophy. It's basically trying to keep and expand our operating margin to the maximum that we believe will not constrain that growth in a superbly negative way. But at the same time, we don't want to veer away too much from our profitability profile. We believe that getting to that breakeven is a great milestone, but it's something that we want to continue and expand, as Barbara kind of alluded to. We all believe there is more leverage in the business. So as we extract that leverage, we expect more efficiencies, we expect more room with operating margin, and we take that, and we reinvest that back into growth. So we are trying to balance all of these 3 different components into something that should, hopefully, and this is my belief, will be one of the leading growth companies in the market even in the next couple of years. Can we do that? We're going to all have to wait and see. And obviously, as we go to next quarter's earnings, we'll share more, and obviously, in Q4.

Brian Essex

analyst
#11

Has that balance tilted in the past like 2 months?

Tomer Weingarten

executive
#12

Not in a significant way. I think we're constantly refining our view. We definitely see a more accentuated opportunity in the endpoint market. There's no question. But look, a lot of what we've done, and I've said that numerous times, has really been just doubling down on our own organic momentum. What's happening in this space, Barbara said it too, such a dynamic space. Every single day there is something. Yesterday we saw probably the advent of the largest global espionage campaign the world has ever seen. That's new. So every day, there is a catalyst for us, and we're just trying to stay nimble and make sure that we balance things in the most appropriate way.

John DiFucci

analyst
#13

It's John DiFucci from Guggenheim. I have just a small follow-up to Brian's question, and thank you, Tomer, for the detail. But I just want to make sure I understand this. So Lenovo, as you put up on that slide, with 59 million units shipped, and that's the largest PC OEM out there, and they're not all business PCs. But are you going to get paid -- so Lenovo ships a business PC, let's say it's, I don't know, half that, whatever it is. Do you pay it on every PC they ship to a business because you're on there? Or does the business that they're shipping to have to say, "Yes, I do want that." And you get paid on just those ones that say, "Yes, I do want it." And then I really have a question for Barbara, but I'm going to be respectful to Doug, and maybe I'll follow up with her later.

Tomer Weingarten

executive
#14

Simply put, everything that's within the ThinkShield envelope, which, I don't know, you got a Dell laptop, so you probably don't know. You need a Lenovo right now. But everything that comes with ThinkShield comes with SentinelOne. And I think that's the easy kind of lens to look at it. The joke was that if you had a Lenovo PC, you most likely have the ThinkShield offering. So put these 2 data points together and I think you arrive at the conclusion.

Robbie Owens

analyst
#15

Rob Owens from Piper Sandler. And Zelnick, thanks for looking at me when you talked about 20 years ago and what OEM was doing. I really appreciate that. So obviously, from a competitive perspective, 2 of your competitors have really moved towards bundling, call it what you want, platformization, flex programs. Talk about where go-to-market is, how willing you are to be flexible there and just what pricing looks like in this dynamic and why SentinelOne wins in the end?

Tomer Weingarten

executive
#16

Do you want to take some of that, Michael?

Michael Cremen

executive
#17

Yes, I'm happy to. What I really have liked about this past year being at SentinelOne is we -- it's one of the most flexible companies I've been in, in terms of really understanding what our customers are looking for, meeting them at that place, working with our partners as well to really understand the opportunity and the requirements and really what the customer is looking to accomplish. So I feel that we have been very flexible, and I like the way that we've approached the market from that perspective, and we haven't made any dramatic changes because we really haven't needed to.

Tomer Weingarten

executive
#18

Yes. I mean just to add to that, we support consumption-based pricing. We support ELAs. We support subscription, obviously. So we are just trying to give the best financial solution to customers. We give financing through our partner ecosystem. We don't feel like that's something that we need to take upon ourselves. And that works for customers. I mean, oddly enough, when you go into some of these customer commitment or credits type constructs, that's -- the word commitment is not necessarily something that customers like to hear, especially if it's a big out-years commitment. Sometimes actually doing something that mirrors the actual consumption is a more favorable financial construct. So I think the key word, as Michael said, is we're being flexible. The one thing we're not doing is crazy discounting or giving stuff away for free. It's just -- it's not us. And when customers talk to us, we're not putting it out there, we're not buying out contracts en masse. With that, there has been and will continue to be ad hoc situations where we're going to come in and we're going to offer favorable terms. If it's something that we want to win, if we believe it's strategic, we look at the lifetime value for these customers, and those are easy decisions. You're right to point that Microsoft has been offering bundling for years. And Palo has been offering free licenses for quite a few good years. I haven't seen that be an insurmountable headwind for us to continue and stick to we sell this best-of-breed software, we charge a decent price for it. I remember 5 years ago, we started with this. We had a price point, then we IPO-ed. Everybody said, our price point is rock bottom, we're dragging down the market. And now you come back to us and you say, "You guys are pretty expensive. Everybody else is giving the stuff away for free." Our price point has been the same across that time frame, give or take a few cents. So all in all, we believe there's value in what we do. We believe we priced fairly and have priced fairly. And I think that's kind of the prevalent motion that we see with our partners. That said, we are iterating, we are adding more site license type deals, deal structures. We are going to allow folks to buy the platform and use any capability that they want, call it flex, call it platformization, call it whatever. Buy the platform, use what you want. It's all the same to us at the end of the day, and we'll support all these pricing models.

Saket Kalia

analyst
#19

Saket Kalia of Barclays. I want to switch gears a little bit. And first of all, just thank you for the disclosure on cloud and data ARR. I think those are really important. Maybe the follow-up question is, and Tomer or Barbara, feel free to chime in, but I think it's roughly $170 million in ARR from those 2 businesses. What type of growth is that sort of -- first, year-over-year? And then secondly, maybe more for you, Tomer, the cloud piece, and I always love asking this question, like how do you kind of think about that cloud market over the next few years? You have cloud security specialists, right? You've got endpoint players like yourself. And then you've got, I don't know, the network security vendors. Who has sort of the right to win in that $12 billion market?

Tomer Weingarten

executive
#20

Yes. Look, as far as growth, this is obviously growing each and -- one of them separately and both of them together faster than the overall business, in a pretty significant way. I think what we're seeing is, obviously, AI is driving also data sales. So everything is starting to get this compounded effect for growth, and we really like what we see there in terms of growth. If I look at the overall cloud security market, I mean, look, to me, this market has converged into maybe 4 formidable players, which we're one of. And that makes a pretty simple picture, where one of these players is a network player that has done fairly well, probably leading the cloud security market in terms of revenue. One of them is our endpoint peer, which is probably kind of second level in revenue in that market. Then you get 1 stand-alone upstart that have done a great job in selling a CSPM oriented offering. And that's the only stand-alone that I see in the market that I believe is relevant. And then there's SentinelOne. I mean that's kind of the short list of what you can do in cloud security today if you're looking at options. I have always said, ever since we started talking about workload protection, that to me, that is the true center of gravity for cloud security. Oddly enough, I think you're seeing some of the stand-alone player gravitate towards that direction as well, now that they've kind of disseminated the market with their CSPM offering. The amount of workloads that require protection is basically boundless and they keep on growing. So the majority of growth that I believe will be driven in the cloud security market is going to come, A, from reaching these workloads. It's totally underpenetrated. Nobody is covering all these workloads right now. Most of these vendors that we talked about is a very nascent workload coverage. Even Palo Alto Networks, which has been an established player in cloud security, I don't think they're known for their runtime security capabilities. So the workload vector, just the amount of workloads is one big driver. And then it's the capability set. And I think you're seeing a couple of interesting approaches in the cloud security market where you see folks try to paint that picture, they call it code to cloud, which I somewhat believe that's a growth driver, it's the expansion of the platform, it's more stuff that loosely is connected. But I also see significant disruption to how we code in the next 2 to 3 years. So if you're putting all your eggs in the ASPM basket or integrating into the IDE and kind of going all in on code, while the IDE, the development interface for code is going to change, it's going to be most likely very AI driven, I'm sure you've all seen what AI can do today in coding applications. Imagine where that was going to be in 2 years. I don't know exactly how the models I see today for code-based security, the shift left movement, kind of come to terms with that. So I would be very cautious if people are kind of selling that notion of code to cloud. What I'm hearing from customers is that it's more of a wait and see. I want to see how the coding landscape will evolve in the next couple of years, investing now in something, integrating it just to find out it's relatively relevant. I mean, just another example, I don't want to digress, but all these coding -- code security platforms, they're there to try and tell you when you onboard the vulnerable library into your code. If you're coding with AI, you just ask AI, make sure that these libraries aren't vulnerable or don't have vulnerability, and done. You don't need a whole product just for that and all kinds of wizards and all that stuff. So I do think that the next phase of growth in cloud security market doesn't come from code necessarily, maybe I'm right, maybe I'm wrong. I think that DSPM or data security is an important component. I think that AI SPM is also an important component, how we secure the usage of AI in the enterprise through all the different facets that right now, I believe, hinder adoption in many senses because we just lack the control. If we give unfettered access to an AI model to all employees in a given enterprise, we have completely lost track of what's being shared, what's being returned. It's a data leakage nightmare. And I think that represents a big opportunity. So I think the cloud security market is going to evolve in these directions that's kind of definitely what we've been investing in and believe customers will absolutely need, almost under any type of scenario in AI progression.

Patrick Edwin Colville

analyst
#21

It's Patrick Colville from Scotiabank. Congrats on the first Analyst Day you guys have done, I believe, right? So congrats, it's great. So in your presentation, you touched on one of your competitors' July 19 incident. I think it was helpful. You talked about why SentinelOne wouldn't suffer from such an incident. But I think the question on many investors' lips is that incident driving new customer conversations in SentinelOne? You kindly gave us the message during 2Q earnings 6 weeks ago, but what is the message as of today at OneCon on the fallout from the July 19 incident?

Tomer Weingarten

executive
#22

Yes. I will return to the Q2 earnings and reiterate what I said on Q2 earnings. There has been a significant shift in consideration more than anything else. My belief is that this is a long-term impact -- positive impact for SentinelOne. The customer conversations that we've been having have been significant, I would say. Those will unlock themselves over time. There are some folks that want to move, some folks that have already moved, some folks that will move. I think, again, the timeline is hard to predict. I'm not going to attempt in predicting it. I don't feel like we need to predict it. We got our own organic momentum, which is incredibly strong. So is this a net positive for SentinelOne? Absolutely. Did the other vendor take a reputation hit? Absolutely. That would be the lens that I would encourage all you to think about this. Net new endpoint projects, you can imagine what was our position pre-outage, what is our position post-outage. In terms of customer churn, again, renewal cycles are going to educate us more on that. If there's one thing, I think, we can clearly share is that in terms of the partner ecosystem, which if you think about it, they've also, given what we here, have lost pretty significant amount of their inertia in terms of expansion movement with that competitor. And we share a lot of these partners, right? I mean these partners work with a lot of vendors. I think they're absolutely coming back to us and looking to us as to how we can help with those expansion footprints. So to me, again, it's a structural change that impacts SentinelOne probably the most. I think it impacts us in an incredibly positive way when you think about the adjacent surfaces. Obviously, the growth with cloud is going to be important to watch as well. But again, all of it is positive. I don't really want to get into numbers, mostly because I don't know. These things move at a certain pace that I can't predict. But again, I sincerely believe our position is better than it was before.

Douglas Clark

executive
#23

Thank you. We have time for one final question.

Unknown Analyst

analyst
#24

So I wanted to maybe ask Ric and Michael on SIEM. So you highlighted kind of the efficacy of it, why it's so strong, why it can compete stand-alone basis. But I think where SIEM is going in this new direction is it's kind of going from being a third-party neutral vendor to kind of first party and native to somebody that already has strong proprietary data to offer from the platform itself. So just given that SentinelOne might not have the incumbency on endpoint in a lot of enterprises, how do you, both of you, kind of approach that opportunity to displace some of the legacy SIEM vendors out there if you don't have that endpoint incumbency?

Richard Smith

executive
#25

I'll start. I think we're equally promiscuous even if it's not our endpoint. So if you want to give me CrowdStrike's endpoint and have me do all the automation around triage investigation, threat hunting, orchestrated remediation and response, we'll do it all day long. On top of that, you can build out the same rule sets that you would otherwise have on the other SIEMs on top of that telemetry. So we look at that as a nice transition point to get one vendor in the portfolio, and augment that, and not have to lead on a let's rip out CrowdStrike on the endpoint, even though that's possible.

Tomer Weingarten

executive
#26

No. I mean, I'll just add to that. I think the consideration point for SIEM is so different than endpoint that thinking that just because of endpoint incumbency, you have the right of passage to data, I don't even think that for our customer set. I think that you need to have the best capabilities possible. And that's what's going to determine the consideration. Look, we have done deals where we ingest data from Palo Alto firewalls and CrowdStrike endpoints. We've actually been the data bridge between Microsoft and CrowdStrike all being put into a SentinelOne data lake. I think that at the end of the day, you don't want to replace 1 SIEM for the other. You want to pick a foundational technology for the next 3 to 5 years. These things, there's not going to be a rip out motion every couple of years. This is going to stick. It's going to be significant. It's a significant integration effort I think it's probably the hardest surface to replace, I would say, much beyond the endpoint, definitely beyond the cloud. Cloud is probably one of the easier ones. That's why I think that customers are taking their time, they're not jumping to all these glitzy offerings that come with the platform, I think it's all about capabilities. And you're seeing some players in this market, which are a bit different. I mean we immediately think SIEM, we think Splunk, great, that's the incumbent. You probably are thinking Palo because they bought QRadar and you kind of believe that's going to be a huge deal. Not entirely sure how that plays out, given that most of QRadar is on-prem and cloud -- and Palo is only cloud. So there's some transition that's unnatural that's going to have to happen there. You obviously see Microsoft with a kind of a highly integrated offering. But then you see Google with Google Chronicle as an example, and they're a stand-alone SIEM player. And they actually have probably more scale today than what Palo Alto has in the same world. So I fully subscribe to the first part of your question, SIEM needs to be agnostic, it needs to be the UN of security. It needs to take in data from any surface, whether it's native or not. And that's why when we think about our market approach, we really think about it in a way that's detached from our endpoint motion. It's a great benefit. If you're running both our endpoint and you're going for data, that's a huge benefit to you. You're getting all of that data for free into that data lake. But beyond that, I think there's so many different constructs and so many different other factors that are as important that the consideration is, first and foremost, the functionality. And then, yes, it could be an added benefit to also have endpoint or cloud or any native surface, but that's not the prevailing motion.

Douglas Clark

executive
#27

Okay. Thank you, everyone, for the questions. Thank you for joining us today. We'll speak to you again upon our earnings call. Appreciate it.

Tomer Weingarten

executive
#28

Thank you so much.

Barbara Larson

executive
#29

Thank you.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete SentinelOne, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to SentinelOne, Inc. earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.