Zscaler, Inc. (ZS) Earnings Call Transcript & Summary
June 4, 2021
Earnings Call Speaker Segments
Keith Murray
analystSo good morning, everybody. Thank you for joining Bernstein's Strategic Decisions Conference again. My name is Keith Murray, Bernstein's tech and payment sector specialist. I'm very happy to be joined today by Jay Chaudhry, Founder, Chairman and CEO of Zscaler; along with Remo Canessa, who's the Chief Financial Officer of Zscaler. In a nutshell, Zscaler is a cloud-based security software provider, but I'm sure Jay and Remo will do a much better job of explaining exactly what it is they do. Just one quick housekeeping item before we get to the discussion. [Operator Instructions] So with that out of the way, we can get to the discussion. So Jay and Remo, thank you very much for joining us today.
Remo Canessa
executiveThank you.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveThank you.
Keith Murray
analystSo Jay, I thought it might be a little bit helpful, if you could spend some time maybe upfront for some people who may not be exactly so familiar with Zscaler. Maybe if you take 10 minutes or so, you can kind of walk us through Zscaler's Zero Trust Exchange platform, how it differs from the traditional castle-and-moat security model and sort of the key business risks your firm helps to reduce and so on. So thank you.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveThat's wonderful. Keith, I'll use a few slides. I'll go through them fairly quickly, but visuals can help make some of the concepts a lot clearer. So if you see my diagram, every CIO is embracing SaaS and also embracing public cloud. And the users are becoming mobile. They're working from anywhere and everywhere. The data is everywhere because data sits with either applications or with users. Data doesn't sit on the network. Network is simply the transport. And what you see below the whole security and network infrastructure gets bypassed. Business is happening outside the corporate network. And we are still trying to do network security. That is kind of crazy. Our typical hub-and-spoke network, our typical data center made lots of sense when data center was the center of gravity, and all roads took to the data center with the shortest path. So ideal model for the pre-cloud and pre-mobile world. What is the problem with it? Well, in the -- for the last 30 years, to access applications, you built them and put them in a data center and users had to be on the same network that application were on. So we extended our corporate network to every branch office. If you got 3,000 branch offices, your network got extended to 3,000 locations. And now, if you embrace cloud, your network gets extended to every cloud location, every availability zone. And if you got 20,000 users working from home, using legacy VPN, your network is sitting in 20,000 homes. Your network is all over. It's a trusted network. Why do you do that? Because any user, once they get on the network, they're going to access any application. That's beautiful. The danger is that any user getting infected -- a single user, in a single place, everything can be infected. Those of you who have interest in security, you should read an article by Wired Magazine about Maersk, this is the mega shipping company that got infected with NotPetya ransomware and entire enterprise across 180 countries was down -- hard down. That's the danger of doing network security. That's the danger of having a wide area network. What will a firewall company say in this world? They said, don't worry about it. This network security is great. You don't like appliances? I'm going to spend my firewalls in a virtual cloud, VMs. You don't see them, you don't worry about them. It's a cloud service. But they're extending your network to wherever the firewall's on. Firewall is a network device. If you've got users at home, they won't call it VPN. But they'll say, trust me. I've got a great cloud service. It is VPN. Spending VPNs in a cloud -- it's still a cloud. And they can happily extend your network with site-to-site VPNs to every cloud provider. Your network gets all over, your attack surface goes up. And the risk of lateral movement, the kind of risk that Maersk had, becomes bigger and bigger. So what's the right architecture? It is Zero Trust. The throne is being hijacked by legacy vendors because they are worried that they're getting disruptive. Read 2 documents, if you want to read about Zero Trust. Gartner has a paper called Zero Trust Network Access, and NIST has a very good document. In fact, Biden talked about NIST paper in their EO about cybersecurity. Applications are viewed as destinations. Users or viewer on untrusted applications are users that are not on the same network. Network security doesn't matter. Network is simply the transport. It is plumbing. To connect 2 applications, a user comes over any network, they connect to our exchange. Think of Zscaler Zero Trust Exchange like a smart switchboard. Simple phone switcher who can talk to who. When they come to us, we redirect them to their identity system because identity is an important part of Zero Trust. Once user is authenticated, we looked at various contexts about user, device, application and content. If the criteria meets, we connect them to the right application or service. Period. There's no pass-through connection like firewalls and the like. This gives you great user experience, better security, makes business agile, and cost goes down big time. In the process, you end up eliminating the need of having any of these security appliances that are used to build a moat around the castle. In this castle-and-moat model, you have a drawbridge to go out and a drawbridge to come in. And with Zscaler, you simply forward the traffic to us, through ZIA, one of our products, to secured users when they go to internet or SaaS, and through ZPA when they need to access internal applications. Life becomes simple. You can actually enable your users anytime from anywhere to work on any device, and they can access any internal, external applications with Zero Trust being they're not on the corporate network. So that's the high-level view. You end up replacing lots of stuff. You don't need to do it overnight, but over a few quarters, a lot of this stuff goes away, business justification becomes easy, user experience goes up. And most importantly, security becomes much, much better. So I think that's probably a good high-level view. Maybe one more statement I'll make. Security should be looked at holistically. How do you do so? First of all, the bad guys want to compromise you. And to do so, every threat comes from the Internet. Since Zscaler sits in line with ZIA, like an international airport, for any communication in the Internet, we stop your users, your servers, your workloads, your OT devices from getting infected. Now, in today's world, when supply chain can get compromised like SolarWinds, you assume that you may be compromised. Then, our job is to stop lateral movement of threats, so they can't find high-value targets. Our ZPA product, while securely connecting users to applications, not in the network, provide the security. Treat every bad person wants to steal your data. And since we are sitting in line like an international airport, everything goes through us, we have data loss prevention, data protection services that make sure nothing goes up. So that's our overall holistic story. So with that, Keith, let's get into Q&A.
Keith Murray
analystThanks very much, Jay. Very helpful. So we have actually a couple of questions coming in from the audience already. So let's start with this one. Question is what's the total cost of ownership of the Zscaler's legacy -- I'm sorry, Zscaler versus legacy architecture and maybe compared to other cloud vendors? What's the differentiation there?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveYes. So first of all, when you compare a 1.5 to 1-point product, you can easily compare the cost. It's simple. We are an architectural chain. We eliminate the need for network. We eliminate the need for most of the security appliances. I mean, most of my large customers will say, "Wow, Jay. Your cost is so low. It's too good to be true," as compared to the cost they have. I, from time to time, kind of respond back and I smile and say, "My sales team screwed up. They didn't charge you enough." But it is true, by the time you eliminate the MPLS network, all the associated routers, switches, load balances that go with and all the network security devices, literally, the ROI is massive. Some of the customers have stated -- I had a customer from consumer goods company, he stated a couple of years ago at RSA, he said, "For every dollar spent on Zscaler, I save $6 to $7."
Keith Murray
analystThat's a big number. And your cost comments dovetail another question that came in from the audience. The question is, how long does it take for customers to transition to Zscaler from legacy competitors? And is it mainly motivated by cost? Or is it motivated by improved security? So what's the thought there?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveOften, #1 reason to do so is to securely do digital transformation. Security is actually the last thing in most of our decision-making process. CIOs are driving digital transformation. Our deals are often led by CIOs. When they move applications to the cloud, user experience becomes very bad, okay, because they're all backhauling through the stuff. And then they need to really transform the network and security needs to be transformed. And if they look at it holistically, what we are doing by simplifying the stuff, it becomes very impressive. So transformation is number one, to enable it because that's the highest priority for CIOs. Number two ends up being good user experience. Number three is reducing business risk. And number four, exactly cost savings.
Keith Murray
analystThank you. So you mentioned a recent cyber threat that was in the news. And this would be front and center, and they're in the news regularly. Can you discuss some of the major sort of secular tailwinds that you see benefiting the growth opportunity for Zscaler? And do you see those ebb and flow over time? Or has it been a pretty consistent expansion of a focus on the cybersecurity front, just given all the risks that are out there?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveYes. Security has been an issue with the last several years. But in the recent time, for example, when SolarWinds happened, this was a first, a large, large-scale supply chain attack. And it kind of shook off customers. It probably had a bigger impact than Target breach. And then, on top of that, Microsoft Exchange vulnerability is showing up. And then, this Colonial Pipe showing up. It seemed like it's a nonstop thing that's happening. In some ways, it doesn't surprise me. Our enterprise security for -- in large enterprise, still largely dependent on firewall-centric model. The model says castle-and-moat security. If you kind of come into my inside my castle, you are trusted. Outside, you're not. The problem is once you get in the castle, you wonder, wow, this visitor can get to any place. And that castle is connected to 9 other castles through very secure tunnels. So once you're in, you can get to any of those 9 castle. That is the problem. That is where a firewall architecture simply breaks. What is a firewall? It's a door in front of your castle. What's Zero Trust? Zero Trust says, there's no inside. There's no outside. Everything is outside, okay? An application is a destination. A data center is destination just like your application on Azure, just like your application like Office 365, and all users are untrusted. You go through our switchboard, can I talk to X, Y and Z application? We authenticate it. We check various lot of contacts. Where are you coming from? What kind of device are you coming from? And we connect. Otherwise, we don't. It doesn't really matter. What -- how will the firewall do this? They can't. So what do you do? You kind of try to say, I can do this. I think one of the damage done to our enterprises by legacy vendors who claim to do everything, they create a false sense of security, and enterprise are getting compromised. As long as we depend upon castle-and-moat perimeter-centric architecture, these threats will never go away. Zero Trust is the only way because this architectural change has to happen. It's like we used to defend our castles when only armies could invade us. With Air Force and everything around here, what do moats do? Nothing. Same thing is happening in our cybersecurity world.
Keith Murray
analystThank you. Maybe one for Remo. So I know you guys have highlighted a $72 billion serviceable addressable market. Maybe can you give us a breakdown of the components of that? And how do you see that addressable market growing or maybe the different pieces of it growing?
Remo Canessa
executiveYes. Yes. Thanks, Keith. So our addressable market is the market that we're targeting. And we're targeting companies of greater than 2,000 employees. There's about 20,000 companies like that in the world, and the total number of employees in those companies, they're about 337 million. So what we did, and this comes from third-party sources, we looked at what our average price per user is. And again, we sell basically user protection and workload protection. So if you look at the user protection, it includes ZIA, ZPA and ZDX. And the average price per user for companies of 5,000 employees, and we're seeing this type of pricing, net pricing to Zscaler is $145 per user. And you can break that down into ZIA, if they buy the Transformation, which is our highest bundle. We sell them 3 bundles, Professional, Business and Transformation. So if they buy the highest bundle, Transformation is about $45 per user. The ZIA add-ons are about $30, and that's DLP, CASB, [ Atavan ] and browser isolation, more security type offerings. ZPA is $45, and ZDX is $25. So if you take the $145 and multiply it by the 337 million employees, you get $49 billion. The workload protection, what we looked at is large public company workloads. The AWSs, the Azures and the Googles. And the amount of workloads in those public clouds is 150 million. So if you look at the pricing that we have on the workload side, this really can break it out to 3 groups, and this is for companies that are deploying thousands of workloads that we've seen. CSPM is about $40 per workload. Workload segmentation is $60 per workload, and workload communication is $55. So that's $155 per workload. So you can multiply that by the 150 million large public company workloads, I get to $23 billion. So the $23 billion plus the $49 billion gets you to $72 billion. The thing about it is that that's a $72 billion SAM. It doesn't really include other things that our platform is capable of. IoT, device to device, B2B, B2C, smaller type companies, companies below 2,000, which there's over 200 million basically employees in those companies. So really, the TAM is much, much bigger, but our focus is this -- that the larger companies as well as -- we looked at the large public workloads. Where's this going to go? It's going to continue to grow. And it's a huge market. Jay talked about the savings that you're getting with this digital transformation. It's not just replacing appliances. It's basically also replacing costs. And those costs are like MPLS costs, which we talked about, communication costs, because they go through broadband. Costs have been related to servicing these products, just significant cost, the support cost that you pay for companies. So a lot of other type of costs that basically we're collapsing into our platform, which is resonating with our customers.
Keith Murray
analystThank you. I appreciate that, Remo. Another question from the audience. This is about sort of a company transitioning to your platform. If you have a legacy architecture in the enterprise and want to transition to Zscaler, do you have to rip and replace the entire system at once? Or can Zscaler do this in pieces and support the legacy while the migration is happening?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveThe migration always happens in phases, okay? That's kind of interesting. COVID showed that you don't need most of the legacy that's sitting in your data center on your network. When you had to work from home, you could literally come from your home, from your laptop, with a small agent installed in it, traffic comes to us, internet and SaaS-borne traffic gets sent to internet and SaaS through ZIA, and internal traffic gets sent through ZPA. You don't have to touch anything inside your wall. That legacies that didn't even exist, okay, you work without it. That's the biggest mindset change that COVID did. The CIO said, I'm spending $50 million per year on my network infrastructure. Wow, I can work without it. I never felt that it could be done. When you guys told me about this before, I said it's too good to be true. There must be a catch somewhere. There isn't a catch. So more and more CIOs are talking about not doing network transformation but doing network elimination. It's like, I don't need my corporate network. If you don't need corporate network but you need network security, you don't need network security. Your security needs to connect users to applications through an exchange and a switchboard. So that's how the world is working now. Having said that, there's just -- removing legacy takes a few quarters. For example, there are some contracts with service provider on wide area networks in out there, right? They need to go. And when your users go back to office, they want to really have a local connection, local broadband connection from every office, and they need to phase out the MPLS connection that goes from a branch to the data center. So if they were paying $2,000 per month for each branch office for MPLS and you got 1,000 branches, do the math. The numbers add up. This is a monthly number. And then, they spent $150. They get a broadband connection in the branch. What's the price difference? Literally, less than a 1/10 profit. So it takes a few months to get X hundred branches with a local breakout connection. But as soon as they get the broadband connection, it -- the router locally can be configured to send traffic to Zscaler directly from the office. Or until that's done, the traffic from Zscaler in the branch will still flow through whatever the network is. We really -- we are not married to the network. The traffic for Zscaler can flow over any network. And the changes to replace some of the legacy takes a while. So it's a journey, and customers like a phased journey. For example, typically, based on ZIA and ZPA to enable employees to work from any area, that's number one. Number two, then they say, let me remove my secure web gateway and outbound firewall and DLP and sandboxing and antivirus, that's sitting generally in 2 or 3 data centers. But that doesn't matter. They want 1,000 branches to go direct. So is there replacement? Yes, we replace 3 data centers, but there are thousand other branches that are net new, so to speak, greenfield opportunities. That's how this thing expand. ZPA starts, we're replacing VPN. People get confused. They think ZPA is a VPN replacement thing. VPN is only a small piece of it. That's a remote access thing. ZPA make sure your users aren't getting on your network, but ZPA overall removes the whole inbound stack. For example, when you deploy applications in Azure, you will need to figure out what do you do with global load balancers, DDoS protection, external data firewalls, IPS internal layers and all. ZPA subsumes all of that. You simply come to us, we connect to the right application. You don't have to worry about any of that. So the overall cost savings, simplicity and security are a massive benefit. That's why all these customers are buying us. They're not buying us to say, are you better than this firewall device?
Keith Murray
analystThanks very much. Jay, this is a 2-parter from the audience. So maybe one part for you and one part for Remo. The first part is how do you make sure the transmission from homes to airports are secure, just as an example? And then, second part is, what is your market share now? What do you think you can achieve market share-wise in the long term?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveRight. So first of all, transformation. Secured communication from your laptop sitting at home to our exchange is using standard SSL technology. There's no problem with secure communication. The problem is knowing what is in that communication. So like the international airport, right? You're carrying a luggage in your bag, right? So being able to go through X-ray technology to make sure you're not carrying any guns and weapons and drugs to make sure things are safe. So we, at our exchange, are inspecting for all that stuff. So the issue is by having simple SSL inspection, you're communication is safe. No snooping can be done. The problem is bad guys hide in the same thing. And our job is to make sure we can inspect that SSL traffic to find any bad things to keep you safe. The issue of snooping is an easy problem that isn't solved by everyone.
Remo Canessa
executiveAnd from a market share basis, I'll just throw some stats to you. The bottom line is we're very early in this market. The companies of greater than 2,000 employees in the world, there's about 20,000. We have a little over 2,000 of those companies. So our penetration is in those 20,000 companies, about a little over 10%. Then when you take a look at what we presented at our Analyst Day is our upsell just for ZIA and ZPA. There's a 6x -- from our current ARR that we had in January, there's a 6x opportunity to sell more into our existing customer base. Global 2000, we're a little over 500 of those. And ZDX and ZCP are just starting. I mean, it's just the beginning stages so very early in the market. What Zscaler basically did 10 years ago, I mean, with Jay and the founding founders of basically Zscaler, they saw where the world was going. Applications are going to the cloud, users going mobile. Do today's or yesterday's networks work in that kind of world? They don't. They don't work well. Zscaler purpose-built a platform for today's world. So we're in the early stages. And the accelerant was COVID. Basically, brought to light the need because companies couldn't get their employees working because they're going to traditional VPN. So we got calls last March, not this March, but the March before, over a year ago, and basically, we brought on hundreds of thousands of employees very, very quickly where they can access internal applications and do work. That started and that got the CXOs and others thinking, digital transformation is here. The world's changed and I need to protect my company and put the proper platform in place to transact business and run our company. We're seeing that. So changes takes time. And it's kind of like, I don't want to say herd mentality, but the more and more companies that embrace our platform, the easier it gets, and the more accepted and more trust. And the advantage that Zscaler has done is we started off with ZIA, built ZPA. And then once you've got customers that understand our technology and platform, and as you introduce new products like ZDX and ZCP, workload communication, workload segmentation and other offerings, it becomes easier. So I think the opportunity is very big for Zscaler.
Keith Murray
analystThanks to both of you. Maybe we could spend a few minutes on the government opportunity. It seems like there's a growing opportunity to help government entities around the world with cybersecurity. It's becoming, obviously, a bigger focus. Can you discuss that opportunity? And then, what's the importance of Zscaler having the FedRAMP certification that you guys have? How much of a differentiator is that? How difficult is it to achieve that certification? So color on that would be very helpful. Thanks.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveRight. So first of all, it's good to see governments waking up and saying they need to do something, Biden administration's EO regarding Zero Trust as the key enabler was very good and clear. It's also good to see they referenced NIST architecture for Zero Trust because it defines it properly. So vendors just don't hijack the term and try to abuse it. That's a wonderful thing. Regarding certifications, government need to make sure that the solutions are secure and safe, and the certification is very important. So we have spent about over 2.5 years going through FedRAMP certifications. ZIA, ZPA both have achieved certification at different levels. With ZPA, we have FedRAMP High. With ZIA, we have FedRAMP Medium, about to get to High pretty soon. And it's taken a lot of time, and that's with the right architecture. So it's an advantage. You could have the right products but if you're not certified, you can't sell. And on top of FedRAMP, there are further certifications to sell to defense organizations, DoD and the like. So making those investments early on and having put a team in place for federal sales, we think we're pretty well positioned to do so. We have a strong pipeline. It's growing, and we're bullish about the opportunity in federal market. Remo, you want to add any more color to it?
Remo Canessa
executiveNo, I think that's -- it's hard to get those sort of FedRAMP certifications, as Jay mentioned. We're high with ZPA. We're in the process of going high for ZIA. Those are years. Those aren't months. Those are year-type investments. In addition, we've really significantly increased our federal and SLED teams for state and local and education. So we're well positioned for the federal as well as the SLED market.
Keith Murray
analystAnd maybe Remo, just to clarify, the $72 billion SAM that we discussed earlier, almost -- I'm pretty sure the way you described it, this is not really -- the government opportunity is not really part of that addressable market. Am I thinking about that correctly?
Remo Canessa
executiveYes, that's correct. Yes. These are employees. Yes.
Keith Murray
analystYes. Great. Thanks very much. I think, Remo, you touched on this a bit earlier on the pricing bundles. Just curious what kind of traction are you seeing on that? Is there a significant uptick, significant traction being gained by some of the pricing bundles that you're offering?
Remo Canessa
executiveYes. That's a great question. I'm sorry, Jay.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveGo ahead.
Remo Canessa
executiveYes. So we are seeing movement going to our highest bundles, which is the Transformation Bundle for both ZIA and ZPA. The pricing, basically, if you think about it is 1x for Pro -- Professional; 1.5x for Business; and 3x for Transformation. So the percentages of our ARR is increasing. So we're seeing that. We're also seeing customers buying more of our offerings initially. So they're buying the higher bundles initially as well as buying more of what we call pillars. And our pillars are ZIA, ZPA, ZDX and ZCP. So -- and again, that's the platform. What we're trying to do, we're selling a solution. We're selling a solution to handle user protection and workload protection. All your networking basically, security, is what we're selling. So yes, things are moving up, increasing, and have been increasing, broader platform, record 7-figure deals, larger deals. Those record 7-figure deals, about half and half, new versus upsell. So all positive signs that basically companies are embracing our platform. And Jay, I'm sorry.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveThis is good. Thank you.
Keith Murray
analystThanks, guys. Maybe we'll spend a few minutes on the go-to-market strategy. So I think you guys made some key changes in the go-to-market strategy over the past year plus. Can you kind of talk through the tenure and productivity of the sales force that you have now, the success that you're seeing in some of the value-added reseller channels? And then you have this CrowdStrike partnership. How important is that partnership on the go-to-market? And there was actually an audience question related to that one as well. So please, go ahead.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveAll right. Good. Let me start with broad comments. I could talk about it for an hour, but let me keep my answer pretty short. I think one of the things we did fairly soon after the IPO was to make sure that, if we need to go from a few hundred million revenue to a few billion revenue, we really need to build a strong foundation for go-to-market scalability. And that's when we brought in our new CRO, and we put in place some proper sales enablement, better hiring, better training, better leadership, weekly cadence, and tools. All that stuff took us 3, 4 quarters to put in place, and we're very transparent every quarter to show what the progress we have made in terms of leading indicators. So from a sales point of view, the sales organization is highly optimized. It's doing well. Now we're adding lots and lots of salespeople every quarter, so they're ramping number of sales. Reps are probably more than ramped. We have Remo who'll know exact numbers. But -- so that -- but that's great progress. The 2 other things we're doing to make sure we have more and more leverage, one is channel, making the channel works well. The multiple channels out there, they are VAR channels, SPs and SI. We've done a lot of work with SPs all alone. VARs used to kind of stay standoff-ish, thinking that Boxes will sell forever, but not, they have pivoted. They realized that Box business is going away. We're getting inbound calls. Our brand has become bigger. And we launched a Summit Partners Program to make sure it's tailored. If partners want to do more work, more engagement, the more points they get, it's working well. But that's relatively young, a couple of quarters ago, but we're seeing good traction. A related area, technology partners, for example, like CrowdStrike and Microsoft, they're doing some very good engagements. To elaborate a little more on CrowdStrike, I mean, they dominate EDR, security endpoints. We dominate the cloud. Think of them protecting every household in America. We are trying -- we are protecting every international airport, okay? The 2 are complementary, right? So most -- all of -- most of our customers want an EDR solution. Most EDR solution customers want Zscaler solution. So we did 2 things. One, we did integration between the 2 products, so we could share threat information to provide better security to our customers. And two, we say, let our field organizations work together. Let our marketing organization do some joint marketing things. For example, we have done some joint webinars. Then, our field organizations are working together on accounts to help each other, which is a wonderful thing, and we see more and more of that kind of stuff happening to help us. Remo, do you want to add some?
Remo Canessa
executiveNo, I think that's great, Jay. That's perfect.
Keith Murray
analystAnd maybe sort of a follow-up, but the question from the audience also asked, how would you see the relationship with CrowdStrike evolving over time? And are you coordinating go-to-market sales efforts with them?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveYes. So as a part of field-level engagement, it is all coordinated. I mean, it doesn't happen automatically. But when you align at the headquarters, George is a good friend. I mean, we are aligned at the headquarters and sales organizations come together and -- but real things happen in the field. So when we really have joint account planning discussions about accounts, so it's a proactive effort because it helps both of our companies. And we see it growing and helping both companies. It's a win-win partnership.
Keith Murray
analystAnd can you maybe touch on -- I think you have some other key partners like VMware and IBM, and what those partnerships enable you to accomplish?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveWe like to have few technology partners that work well with them, rather than saying I have 1,000 partners. VMware partnership is largely driven by their SD-WAN offering. As you know, we don't offer SD-WAN. We are like Switzerland, who really secures all SD-WAN solutions. We have integrated with most of them through API-based integration. VMware is complementary to us. They need an enterprise class security like Zscaler to secure their SD-WAN. And they have a big presence. So as they go in there, they help us to pull into their accounts. We help to pull them into our accounts. It's a great partnership. IBM comes from a different angle. They got security solutions of their own. They do transformation. They are an SI as well. So as a partnership, we have integrated with their products. They've -- our Zscaler solution becomes part of the overall portfolio. And then when they do transformation, they're also leveraging Zscaler. So good partnership on that front. And Microsoft partnership is driven on many fronts. Office 365 has the biggest catalyst because to deliver great user experience, Zscaler makes a big difference. Then you got a partnership on the Azure side of it, you've got a partnership on the identity side of it, multiformat. And similarly, now we have been growing our partnership with AWS as well. Customers need to access workload securely with great user experience. And we sit in the middle as a switchboard, as an exchange. You connect. Our technology is not dependent upon a cloud provider A or B or C. It works equally well when it comes to accessing applications in Google Cloud, AWS or Azure. From field point of view, since Microsoft has such a large field sales force, we have a lot more engagement at the field level with Microsoft than the other 2 cloud providers, but we work equally well with them.
Keith Murray
analystThank you. Very helpful. Maybe we'll touch on the M&A front. So organic growth has obviously been very strong for Zscaler, but you've also done some M&A, Trustdome in April; Smokescreen, you just announced last month. Can you kind of talk through your philosophy on M&A and maybe what you're looking to accomplish with deals like the 2 recent ones? How do they fit into the platform?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveYes. Maybe I can start with what we aren't looking for going through M&A. We're not buying companies to bulk up revenues, okay? And the driving principle for that is we don't want any legacy technologies. We are proud of the cloud-native technology we have and most of the large vendors out there. Our legacy technology, they may rename it, whatever, but it's still legacy. What we're looking for is expanding our platform functionality in a pretty elegant and simple and easy to deploy and manage way. And if we feel like there's some good technology vendor out there who can reduce my time to market by 9 or 12 or 15 months, we acquire that. Generally, smaller companies are easy to integrate from a technology point of view as well as from a culture and people point of view. And also, early on, it was important for us to kind of get to understand how M&A is done and how it works with some of these smaller acquisitions. And what we've done, we are seeing some very good results with the acquisition. We are seeing some very good results from, for example, the acquisitions we did a year ago or so, CSPM. Cloud Security Posture Management is helping us quite a bit. It gave us a 9- to 15-month lead in getting the market. The browser isolation, which is a feature, being able to acquire a tech company and integrate with ZIA, ZPA has been very good. Similarly, Trustdome acquisition further makes our cloud security partially better because it is allowing us to do permissions and entitlement. So it is complementary to the CSPM solution we offer. And Smokescreen is a very cool and elegant technology that helps us in reducing the lateral threat movement. Think of it. Remember, we said with Zscaler Private Access, we connect users to applications only, not the network. So once they're on -- we don't put people on the network. So we don't let threats move around. But in case you're already compromised like with SolarWinds, Smokescreen is like a security motion camera inside your house, okay? It kind of picks up things if bad guys tries to go, we set up honeypots like active directory. If somebody tries to go and say, "Aha, I got active directory." It's not real active directory. As soon as they do it, we catch the thief red-handed, okay? So it's one more piece, one more technology that gets integrated to strengthen our ability to stop any lateral threat movement. So you're seeing us selecting them, and they all become integrated in our platform. And we'll do more. I mean, we're not rushing into it. We're methodical, we think through, and we're open to larger acquisitions if they make sense, but we won't rush into anything.
Keith Murray
analystThank you. This is sort of a numbers question maybe for both you, Jay and Remo. But for investors who sit on the outside, what are the most important metrics to gauge success in Zscaler's business? I mean, you can look at current remaining performance obligation, the dollar retention rates, billings growth, et cetera. If you had to pick 2, let's say, that are kind of the keys to focus on, what would you say as -- this is what you should be looking at?
Remo Canessa
executiveI'll start. I think billings is really the #1 thing to look at for Zscaler. We primarily bill annually. Our contract duration is increasing. So we're doing much more your 3-year contracts, which is great. I would say billings is really #1 metric. When you got CRPO, RPO, CRPO bookings growth rate, RPO bookings growth rates, those are all outstanding, have done very well. The RPO bookings growth rate was like 131% or something like that this last quarter, which is huge, where our CRPO bookings growth rate was like in the low 80s. And the reason for that is customers are doing longer contracts with us. And because what CRPO and RPO represent, it's committed revenue, revenue that's been committed. But we feel billings is just the right way to look at it. There are other negative things that go against the RPO, CRPO. If there are some cancelable clauses we have in our contracts, we won't pick that up in RPO, CRPO. Government deals, even though they might be like a 4-year, 5-year deal, since they have to approve the budget each year, we won't take that up. So there's distortions that can get created with RPO, CRPO. So -- and since our -- and since we bill primarily annually, I think billings is really the #1 -- the one metric to look at. I mean, the trailing metric is revenue, and revenue has been increasing. It's more of a trailing metric. I think billings is the right way to look at things.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveAnd Remo, if I may add, net dollar retention rate, the other part you get asked. I mean, we look at it, but we don't really pay too much attention to it because the bigger the bundle we sell upfront, okay, the lower the net retention rate, okay? That's one challenge with it. Two, if I sell product suite A today and within 12 months, I sell a lot more, it doesn't get picked up. So it's because of those reasons. We kind of say net retention rate, directionally, it helps, but it's not the most important indicator.
Keith Murray
analystThanks very much. We've got one more in from the audience. What legal liabilities does Zscaler have if there is a security breach?
Remo Canessa
executiveWell, we're limited on our contracts, and related to what our legal liability is based on each contract varies. So there are -- the companies do put in liability clauses, but that varies contract by contract.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveAnd then we got insurance coverage.
Remo Canessa
executiveYes. And then we have a significant insurance coverage also.
Keith Murray
analystThank you. So you have noted on recent earnings calls that there's not a whole lot of change that's happened on the competitive landscape despite the significant growth rate in your space. I'm just curious, why do you think that is? And are there a couple of competitors out there that you could point to and say, okay, this couple seem to be making some progress?
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveI would say, what we have built, the way we've done technology is not an incremental change. You can incrementally change products easily. You can go from firewall to a next-gen firewall to a next-gen firewall because it's still a firewall. It's a pass-through connection. Underlying, it's the same architecture. You may say, I can do app detection, but fundamental traffic flow is the same. But what we've done is actually multi-tenant cloud security is very different. It is like you are very good at building DVD players. Now you need to build a Netflix streaming service. Your experience in building DVD player doesn't help you at all. It actually hurts you, okay? So it's because of that, generally, incumbent vendors will struggle. They generally don't make it across when the big shift happens. So I think I'm probably wondering, it will be more likely someone coming from really a startup phase and trying to figure out a new disruptive angle. The challenge that creates for them is you can easily do that in a one-point product area. When you're talking a large platform, it gets very hard for a startup. Think of this way, how many SaaS companies are out there? Thousands and thousands are happening. They are unidimensional. They are easy, self-contained. But think of ERP in the cloud, real ERP in the cloud. NetSuite started 20 years ago. And who else is out there? Workday started working on it 6, 7 years ago and brought to market 2, 3 years ago. Why aren't there lots and lots more ERP companies in the cloud? Well, because it's hard. Why hasn't SAP actually moved to a real cloud ERP? Because it's not simple. I think firewall will have the same kind of stuff, legacy company, the same kind of stuff. And you need to build something, a clean slate for new architecture. That's what we have done. We are sitting in the traffic path. Think of this, what has moved to the cloud easily? E-mail security. It's kind of -- it doesn't matter. It's sitting somewhere. It takes 2 seconds or 2 minutes for your e-mail to go through some filtering centrally. It's easy. Take identity. Identity is a phone book. It's a unidimensional stuff. That's why you saw 60, 70 companies start in the identity space, then you saw Okta and Microsoft AD becoming dominant in that 5, 7 other players. And after that, everything is weeded out. But when it comes to our space, being the exchange, you need to sit in the middle of every -- all traffic, okay? And you don't want 5 cooks sitting in the middle because now your finger pointing, your risk or your availability and reliability goes up significantly. But for an enterprise to depend upon a vendor for putting all its traffic through is a big obligation, it's a big responsibility, and it's not likely to happen easily. That's why that's a barrier to entry for young companies. When I started Zscaler, I was at a stage on my life where I had successfully built and sold 4 companies. I had no interest in doing and building one more point product start-up. So I actually put more money in Zscaler than the previous 4 companies combined and say, let's build a platform. Let's invest whatever it takes. So it's a unique stage of my life that helped me make these investments and start a big platform, which is giving us an advantage in the long run.
Keith Murray
analystWell, we've actually -- we've gone over time. I apologize for keeping you a little bit late. So thank you very much for participating, both Jay and Remo. Super helpful. And hopefully, we can do it in person.
Jay Chaudhry;Co-Founder, President, CEO & Chairman of the Board
executiveGreat. Keith, Thank you.
Remo Canessa
executiveWe look forward to it. Thank you, Keith.
Keith Murray
analystGoodbye. Take care. Thanks, everybody, for joining.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Zscaler, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Zscaler, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.