Zscaler, Inc. (ZS) Earnings Call Transcript & Summary
October 6, 2026
Earnings Call Speaker Segments
Operator
operatorWelcome to Zscaler Investor Day. Please welcome to the stage Zscaler SVP of Investor Relations and Strategic Finance, Kim Watkins.
Kimberly Watkins
executiveThank you. Hello, everyone. It's my pleasure to welcome you to Zscaler's 2026 Investor Day. And whether you're here with us in New York or you're watching on the webcast, we really appreciate you taking the time to be with us today. So it has been 5 years since we hosted an Investor Day. During that time, we've grown into a broad and integrated platform built on our Zero Trust Exchange. We have a great lineup today. to tell you more about our evolution and to help you come away with a better understanding of our strategy, our product differentiation and our growth drivers. So Jay will kick us off and take us through Zscaler's vision and strategy, including how our solutions fit into the changing cybersecurity landscape. Next, Adam will take us back to basics and introduce the Zscaler platform followed by Dhawal, who will talk us through AI security and data security. And that's an area I know many of you would like to know more about. So listen up. Then Dhawal will hold a panel with 3 customers that we're very grateful to have with us today. They'll be sharing their security challenges and their journey with Zscaler. They'll also be available to take your questions. So start thinking about what you might want to ask them. And then after a short break, our new CRO, Ross Tackett, will introduce himself to all of you and share our go-to-market strategy, and then Kevin will finish this up with some financial perspectives. And then we'll welcome all the speakers back on stage and take all of your questions. And for those of you here with us in New York City, after that, we'll invite you to join us for lunch and a reception. And we also have some demos of the products that we'll be sharing today. So make sure you hang around for that. So now the part that everyone loves, the forward-looking statements. Before we begin, I'd like to remind everyone that today's presentation contains forward-looking statements within the meaning of the safe harbor provisions of the federal securities laws, including statements regarding our future financial performance, business strategy and market opportunities. These statements are subject to risks and uncertainties that could cause actual results to differ materially from those projected, and we undertake no obligation to update them. For a more complete discussion of the factors that could affect our results, please refer to the risk factors described in our most recent filings with the SEC, including our annual report on Form 10-K and quarterly reports on Form 10-Q. And with that, it's my pleasure to introduce Zscaler's CEO, Chairman and Founder, Jay Chaudhry. Jay?
Jagtar Chaudhry
executiveGood morning, everyone. Great. Thank you all for joining us this Zscaler's 2026 Investor Day. As you heard from Kim, we have a great lineup planned for you this morning, and I'm excited to hear from leaders across our business. Overall, we expect you leave today with 3 key takeaways. Number one, Zscaler is the cybersecurity platform for the AI era, and AI is the most powerful tailwind of driving our business. Number two, we are capitalizing on this opportunity by expanding our platform and strengthening our go-to-market muscle. And finally, we have multiple growth engines that we expect to drive a reacceleration in the years ahead, right? So let's get started. Zscaler takes me back to 2008, when I started the company, when we pioneered Zero Trust security. The term Zero Trust wasn't well known, but what we came with the idea was trust no one. And making the Internet and advanced technology safer to do business was our primary focus. We aren't focused on building the next and next-gen firewall. And with this, our vision was ushering in a world where people, devices and AI agents can communicate and innovate securely. So security shouldn't be holding them back. And we achieved a lot in the past some 18 years or so. Look at the numbers, over 50% of Fortune 500 companies, 750 billion daily in-line transactions we inspect and enforce policy. Over 200,000 locations, these are public globally distributor, and there are many more private ones. And over 1,000 patents issued and granted, lots of cool technology, we are essentially about innovation. So the new approach to security we took was driven by the fact that in my background where I spent over a dozen years before starting Zscaler doing security. And I've seen more and more security products coming and more and more breaches happening. I was convinced that the traditional way of doing security by building these moats with firewalls wasn't going to work. So the new approach was Entity A should be able to talk to Entity B through our exchange, our switchboard, literally like a phone switch ward in the old days. In the old days, when you called, you said, "I want to talk to John," you got to connect to the John and John only. Then you said I want to talk the President of the U.S., they store go away, you are not allowed to. Simple concept. Party A can only talk to Party B as opposed to the old concept, everyone is in. Now let me try to put the guards and own firewall here firewall. That was these simple concept, the simple idea. And the goal was fundamentally twofold. One was stopping threats, no matter where they come from to us protecting data. Two basic things. While we started with users, that architecture designed to handle any entity. Today, we handle devices, setting in plants and factories. We handle all kind of AI agents, the most exciting part. We've taken into cloud workloads and third parties and the like. And they should be able to access the right data sources. There could be AI models, could be applications, SaaS applications, agents and whatever tools. It's a very exciting platform, and it is probably far more needed today than it was ever before. Now I'm going to talk about why Zscaler is winning the business and why we have a durable growth opportunity at Zscaler? Four simple areas. Architecture matters, and you can't fix it overnight. A unified integrated platform takes time to build. You can buy a bunch of companies and call it a platform. And removing cost and complexity, and lastly, our go-to-market entire. Let me walk you through each of the 4 areas. The first is our architecture, okay? Many times, people get confused between architecture and features. Architecture is the foundation, features are you can add on. You don't build foundation every day, okay? Now our story starts with building disruptive solution, disruptive technology, have always like not to build me too, but a different, better way of doing it. Mobility played an important role in Zscaler's success. That is a big mega wave. Cloud was the second mega wave that helped us because in the world, the mobility and cloud, the old security based on firewalls and VPNs made no sense. We leverage those 2 big mega waves. And now we see the AI era, I call it a giga waves because it's going to change things. It's already changing things. And AI is the largest tailwind we have ever witnessed. We are already seeing early signs of it. And we think there's a lot more to be coming. Now AI. There's hardly a meeting that goes by where AI is not part of the discussion. I do lots and lots of customer meetings. Last week, I was in Dallas, meeting 80 CISOs of large enterprises. Every discussion starts, with, my CEO, my Board is asking me to really roll out AI solutions that are faster and faster pace because CEOs are convinced and rightfully so that it can accelerate the top line growth, and it can also drive efficiencies. But they're all worried about some of the challenges, especially the cyber issues they have to deal with. I'm going to talk about how we deal with, how we help our customers with cyber risks to manage them so they can effectively start rolling our solutions. And this cost and complexity of the current infrastructure they need to deal with on top of which rolling out AI becomes very, very hard. So the tailwinds for Zscaler platform can be put in 2 buckets. One is Frontier AI attacks. These models are powerful. These models are dangerous. And we'll talk about how we empower our customers while mitigating the risk. And the second part is AI agents, agents we deploy our agents other deploy agents going rogue. How do you use agents effectively, okay? Let's start with the risks posed by Frontier AI. For that, one needs to understand how most of the world has worked in the past? The way technology is done is, I'm going to build my application portal, my mobile portal and put a VPN, firewall, load balancers in front of it, and it's all open to the Internet. So people can come over the Internet and connect with it. That was good. But the more things exposed to the Internet, the bigger our tax surface. We had some amount of attack surface before AI. Now AI is further increasing the attack surface. You're adding AI chat boards. You've got MCB servers, you've got AI agents. The attack surface is getting bigger. We call it attack surface because any one from the Internet can scan you and find you. That was there before. But now once they can find you, with AI models, they can find all kind of security vulnerabilities. It's unbelievable how many vulnerabilities can be found. Once they find them, they compromise it and then the game gets over. That's a lot of these breaches are happening. So the risk of Frontier model is exploiting these vulnerabilities and the gap between discovery to exploitation, which used 3 months is now becoming minutes or seconds. That needs to be handled and you can fix it by putting on more DDoS protection, more firewalls, more VPNs. Here is a real-life example of a customer. It's an energy company. Rather than reading all the stats, I'm going to highlight 3 things, internet-facing assets. These are exposed infrastructure. your application, your firewalls, your VPN, your load balancers and all those things, about 6,614. It's not an unusual number. That's what we see in large enterprise. And for that enterprise, 1,049 software vulnerabilities. And 1 thing worth highlighting, VPN appliances, 40 of them. It's easy to find every other week, you see some VPN cut compromise. This is the landscape you're dealing with and models, these frontier models can exploit them very easily. Now how do you fix them? Not buying more of those things, but simply using a different architecture. In the Zscaler world, all applications that acquired authentication are head and behind the Zscaler and attackers can't breach if they can't reach. Very simple elegant architecture. That's what our customers get very proud of because simpler but great solutions. The second area is the lateral movement of threats. Once they compromise a firewall or a VPN application portal, the malware moves lately. How does that work? I tried to explain that concept. Generally get confusing between networks and all. So I came with a new idea. Let's use the highway matter for, just like highway connects different cities, that corporate network, the private network connects your data centers, your SaaS application, you public cloud, your neo clouds and all the branches and everything. The goal is, once you get on the corporate network, you move left, you move right, that's a part job with a network. That's wonderful. But now we got first of more applications on top of what we had. We got AI applications, we got agents and all of that stuff happening. And what can bad guys do? They can get on your corporate network, they can move laterally, they can reach targets and cause breaches. It used to be hackers before. Now you're going to see more and more AI agents acting autonomously being able to do this job. That's a big risk that needs to be dealt with. Let me give you an example of real life. We have been reading about Hugging Face and OpenAI agent. How did it happen? Well open, had this agent in a sandbox. It got out of sandbox. It got on the network. It moved laterally then it got to found a way to the Internet, and then scanned. It found Hugging Face website, then it discovered vulnerabilities on the website and then a breached it. Simple concept, but this is a great example of all breaches happen. I wonder why people are surprised about it. This has to change, architecture has to change. And that architecture is going to help us. Now one other point. Today, we worry about users being the weakest link. Tomorrow, agents will be the weakest link and far more dangers than people because they can move at machine speed. They know they need no coffee break, no weekend, no evenings, no vacation and the numbers keep on growing. That's the big risk. How do you fix it? By taking -- adopting a different approach. That's where Zero Trust comes in. Remember I said in Zero Trust architecture, Entity A talks to Entity B through a switchboard to an exchange. That's a simple policy engine. The difference, the old approach was, you put everyone on the network, now you try to kind of control who goes where. This is the difference. That's why you can't build it on top of traditional security. You can add -- you can't bolt on Zero Trust on firewalls and VPNs. Let's move to the second area, and this is our comprehensive and unified platform. We started Zscaler with securing users, first of all, Internet, second for private application that you knew ZI, ZPA. In '18, when we went public, we had just 1 product, ZI and investors used to ask, would you really be able to go beyond ZPI? Look at the journey, we have come along. We build full 0 trust for users with interacts, private access and user experience. Then we added a branch because branch and devices must be Zero Trust. The big risk out there is these networks that are like a mesh network, everything connects to everything, whether you have MPLS or SD-WAN, you have risk of lateral movement. We brought the solution but each branch is simply like an Internet cafe, it's an island of its own. Each device in a factory or a plant is isolated. It can, in fact, each of the very powerful technology. I told you years ago that MPLS had to go away because with Zscaler architecture, everything will go direct over the Internet. People kind of said that was a crazy idea. I can tell you it's a matter of time, you'll find that SD-WAN used to be something. Today, when people talk about Zscaler's competition, they compare us to SD-WANs of the world out there. I really will show you our customers are embracing Zero Trust branch and you hear from one of our customers about this story, but they're on a large-scale transformation from the old world. Zero Trust Cloud, more and more workloads and applications are being built in the cloud. And how security done in the cloud still the old way, just like people used to do application lift and shift and they realize that lift and shift wasn't a good thing. Now they build cloud-native applications. But they're still lifting and shifting security. You know how? Firewall boxes for East, West in the data center. Now it's virtual fire on the cloud. Firewall is an IP device. It's a network device. It deals with IP addresses. This source IP can only talk to this destination IP. That is hard enough to deal in the data center. Think about dealing with lots of moving IPs when the workloads [indiscernible]. How do you deal with that? Impossible. The best solution would be Zero Trust. You can say, workload in VPC A can only talk to work on VPC B, powerful concept, workloads with [indiscernible] talk to what [indiscernible] B. Those are the innovations we bring to the table. That's why our customers are so excited about working with us. And then the most exciting area of expansion of Zero Trust journey is AI agents. Dhawal is going to talk about how we really built. We have the underlying core most of the technologies in place. We had to build a number of things. We have to build MCP gateways, A2A gateways, how do you extract and analyze prong. How do you figure intent? Those are the type of things we build. But we're already sitting in the traffic path. We already distributed infrastructure. So we believe that we are in the best position to really provide the solution for controlled managed use of AI engines. So this brings together to the overall platform that's integrated and comprehensive. Zero Trust as everywhere, users to branches to cloud to agents. Then on top of that, data security is fundamental extremely important. Our customers want data security that's integrated on policy rather than 5 different data security products. In this area, we have very strong advantage. We have over [ $410 million ] ARR. If this was an independent company, it will probably be the largest data security company. And we are the natural party to do data security because almost all data leaks on the Internet. We're sitting in the traffic path for that. Security for AI is the next big opportunity. If you're deploying AI, how do you secure it? And Dhawal will get you deeper into that. And the other new area we recently added is Agentic SecOps. SecOps is ready for disruption. Aaron will take you deeper into it. But 1 comment I'll make is we have better, more meaningful data for SecOps than anyone else out there. And two, anyone who started building SecOps before a couple of years ago, built it the old way. They may be using AI, but they were using AI to supplement something built for humans. We actually build SecOps for AI agents for the native use. That's -- so what is our unique advantage for architecture and platform? Our scale, scale matters, scale that become bigger and bigger with AI. Cyber better protection because of architecture that gives us minimal attack surface and prevents lateral movement. A platform that covers everything for Zero Trust Everywhere is #3. Number 4, are securing AI and data every year. It's hard to find someone who really can provide this security every year. And lastly, unmatched proprietary data. AI models are getting commoditized. They will be special models and open weight, all this stuff, but private data will matter, and that's the unique and lasting advantage we have. Let's move on to the next topic, cost and complexity. If you look at a typical enterprise, this is what their infrastructure looks like. Everything connect to do everything because they want to reach everything. And trying to secure a firewall here, router, switch here, all that stuff is very complex. It's hard to find a CIO and Head of Infra that says my infrastructure is simple. And then they keep on adding more and more products on top of that. It's really a mess. And what does it result in? Well, you got high cost, CapEx and OpEx wise, scaling challenges as a problem, complexity. Complexity is enemy of resilience and complexities is the enemy of security. And those things need to be fixed. That's why you couldn't fix it by bolting on more and more features on an architecture that's 30 years old, you do it the new way. And this is where the Zero Trust architecture comes in. One other clarification. The world platform has lost meaning out. Every company claims to do a platform. Platform actually uses a common set of services for policies, some of the other stuff. That's a real platform. I see many customers talk about and said they got sold the platform. When they looked underneath, they found it as 8 policy engines, 8 product. That's a real core from large retail in the U.S. who I met with about 2 years ago. We are very mindful of building a right platform. That's why even when we do an acquisition, it's generally a smaller tuck-in company so we could integrate the solution and make it part of our platform. And if we do it right, we bring a lot of cost down. In this simple example, the various areas, even if you exclude legacy Sun cost because that's already paid for and the customer wanted to say, let's deal with that in Phase 2, we're able to bring the cost down significantly. Typically, 30%, 40% range is not unusual to take out. And that's because we don't worry bought the cannibalization of firewalls and VPNs and load balancers and those express routes and the media like that, all those things go away with scale. Firewall companies have to protect the installed base because if that goes out, the business hurts. That's why we can take a lot of this stuff out that others won't do. Let's move on to the fourth topic of why we win. It's our go-to-market engine, okay? Our TAM, you've seen the numbers. It started with Zero Trust users at about $62 billion has moved up at $220 billion because all these platform offerings were added. We are dealing -- and these are very logical and systematic plans. We don't just go and randomly buy a product or buy a product. These are very synergistic areas, very well thought through. We're not trying to be everything for everyone. And I'll highlight that in the previous chart, I showed our AI security TAM of $24 billion. That's about 1% of the total TAM of AI spend that Gartner is predicting. Most of the conversations I have with CIOs, they tell me that they're factoring mid-single digits of the total AI spend for AI security. If I look at that 4% or 7% range, that'll be in the $100 billion to $200 billion range. So we kind of left it outside. But just to give you a data point where the numbers come from. How is AI helping you? Let me give you be more specific. First of all, these tailwinds are coming from first 2 areas: large attack surface and increased lateral threats. Those 2 things are bound to bring more breaches. We're already beginning early signs of that, which really means customers are appreciating more and more need for Zero Trust architecture. And this will give us opportunity to sell new logos as well as upsell. And second area, [indiscernible] more traffic. They are more entities. There are billions of agents. Communication, when we secure communication, we're dealing with more traffic. That means exponential traffic growth, which will drive security consumption, which will drive upsell opportunities for us. Let me give you some real data points. Since Mythos' preview program, we've done over 400 assessment with a large global customers. And what are we finding? Well, as I talked earlier, large installed base that needs to be minimized. Internet exposure needs to be minimized. And that drives need for Zero Trust private access. Lateral tech movement, which typical networking brings. We need to eliminate trusted network. Network should merely be the transport and plumbing. It should never be trusted. Zero Trust SASE everywhere is a solution for that. Attackers are scanning the targets once they get on the Internet once they get on your data center. Maybe in the data center, they get on the network, maybe in the data center, maybe in the cloud. We have [indiscernible] technology deception to handle that. We are seeing meaningful increase in that demand for it. And if breaches happen, then they take your data loss. So there's a bigger demand for data security. And lastly, AI is showing up, shadow IT agents showing you there's a lot of demand we're seeing at a pretty rapid pace with short cell cycles in this area. So these are tangible examples of AI risks that are leading into growth opportunities. The 4 levers of GTM that Ross is going to expand upon, platform, you heard the expansion story, new logo engines with the platform expanded. There are many, many areas to land on. There's no -- we don't need to go through just one traditional way of Zero Trust by users. You can start from AI side, you can offer data security side and others. Partner leverage, you spent a lot of time building a partnership. Global system integrators are especially useful because they actually help drive the transformation. And customer obsession. Our customers are very proud of what we do, or what they do using Zscaler. You'll hear from a few of them today. But here is the stat I'm very proud of. This is based on some data we analyzed. This is about 9- or 12-month old data, 285 CX so this large company. They bought Zscaler in 2 companies, went from company A to company B, called us, 84 of them in 3 companies and 45 of them in 4 companies, very, very wonderful to see them. So our financials, strong financials. You know the numbers. $3.8 billion ARR. That's about 25% year-over-year growth. Revenue growth in the same range. Net new ARR, which is an indicator of near-term how things are happening, you're seeing some very good results. Look, we started at 7% in fiscal '25, took it to 14%. On first half of fiscal '26 was 10%, Q4 was 17%. It's moving in the right direction. We are going to keep it moving in the right direction, and there's enough opportunities to do that. And we also manage our bottom line very well. Kevin will give you more about that. Here's what I'm excited about, the big opportunity for us, with all that stuff. We think we can take -- get to $8 billion to $10 billion by fiscal '31, okay? And there's a lot of opportunities, the reasons I already stated to be able to drive 17% CAGR on the base level and 22% CAGR is very much achievable, that's a potential upside for us. Very excited to build the business to take to those levels. Why invest in Zscaler? If I boil it down to 4 simple reasons, I stated enough about the architectural advantages. Others can't just copy architecture. It's the foundation, you have to do it right and you to worry about cannibalization that's why you aren't seeing firewall companies building on Zero Trust. They may claim Zero Trust once in a while, but it's not there. The demand tailwind I talked about, untapped go-to-market, there's a lot of opportunities in the customer base as well as new logos for us to do and very strong financials. So what are we going to hear today? So for the rest of the presentations, right, my team will give you a deeper view of it, okay? Platform expansion, Adam and Dhawal will share more detail about the platform and the recent innovation we have done. You'll have a chance to directly hear from some of our customers about this area. Okay. And then Ross will take you through our go-to-market engine and the steps you're taking to drive growth moving forward. And finally, Kevin will share some financials and should give you more confidence in a path to $10 billion ARR and provide a fresh look at a long-term financial model. So let's get started. I'm thrilled to welcome Adam Galler to stage. Adam?
Adam Geller
executiveAll right. Thank you, Jay. Welcome, everyone here in New York, everyone on the webcast with us. I'm excited to spend my time talking to you about all the new innovations we have in our platform, and I want to connect those to how we're enabling new growth opportunities for the Zscaler business. So we've been relentlessly innovating on our platform for the past 17 years to solve some of our customers' biggest cybersecurity challenges. This is leading to our key Zero Trust solutions, and we're delivering them for some of the world's largest organizations. We started with Zero Trust for users well before SASE existed as a market category. And from there, we extended the principles of Zero Trust to branches, to OT, to IoT. And now we deliver Zero Trust SASE everywhere. And it's this foundational platform that's also enabled us to deliver new adjacent solutions over time. So for example, we launched data security, and we started with our in-line data loss protection, or DLP. And we've since expanded that over the years to cover all of the important channels for DLP. So that's endpoint, that's data at rest, data in motion, data in the cloud, data and SaaS applications, even data on-premises as well. And next, we delivered security for AI, and this is a space where we've innovated very rapidly over the past several years. And Dhawal is going to dive deeper into this right after my presentation. And most recently for us is Agentic SecOps. We just launched the latest update to our Agentic SecOps offering last month, and we're bringing together -- to do that, we brought together our strong Agentic SecOps product capabilities with our expert-led services around managed detection and response and managed threat hunting. Now Jay mentioned this, the rise of AI-driven threats and the massive increase in vulnerabilities discovered by Frontier AM models like Mythos, it's created a huge uptick in demand for Zero Trust solutions. What that means is Zero Trust is no longer just a strategic security transformation for an enterprise. It's kind of changed. It's now become an urgent Board level mandate to help organizations protect themselves against AI-powered attacks, but also to help them safely enable the adoption of AI for the organization itself. The fundamental truth that existed, and this existed, by the way, pre-AI, it's now more true than ever. If you are reachable, you're breachable. And this continues to be true for users and applications. And now it's also true for AI and for agents. The reality is Zscaler as a company and as a product it was built for this moment. So it turns out the unique architecture, Zero Trust architecture from Zscaler that our customers have used so effectively to secure their users, it's also the best way to secure AI agents, and to protect against AI-driven threats. We continue to expand our platform on the foundation of Zero Trust Exchange to solve the broadest set of cybersecurity challenges for our customers. Now we're going to share more details about our expanded set of capabilities beyond Zero Trust for users and how this has enabled us to address even larger total addressable markets. But first, I want to come back to this point that Jay mentioned again, which is why does the architecture really, really matter? So you may think of Zscaler as a network security company. We have a fundamentally different point of view on that. So networks, whether it's LAN, WAN, SD-WAN, VPN, whatever technology you're talking about, their whole goal is to connect things together. Zero Trust is not about connecting things together, right? So earlier, Jay touched on our approach to securing the agentic enterprise. And it's based around this premise and this principle here that secures any to any communication using business policies and not networks. So let's dive a little bit deeper into that. Our fundamental approach to security lies on abstracting away the network completely, right? That's the primary job of our Zero Trust Everywhere. So to us, that network, it's simply plumbing and we never trust them. So that means you never put the user, the device or the agents directly onto the network. Instead, that's where we use the Zero Trust framework to connect entities only to the resources that they should be allowed to have access to. So let's take that one step further, how do we do this? When an entity tries to connect our resource, our Zero Trust Exchange is going to quickly run through a process in real time to do the following things. First, we're going to verify the user, next or the entity. Second, we're going to establish what should they be allowed to do? Then we're going to bring together first and third-party signals, contact signals because we want to understand the user, the entity, the device as well as the potential risk in whatever interaction is about to happen. And then finally, because we're in line, we're able to enforce a policy decision on what actions to allow and what actions to block or to deny. Now the net result of this is a dramatically more secure environment that can protect against the 4 stages of an attack. So the first step is, number one, we'll minimize that attack surface. This is by hiding applications behind our Zero Trust Exchange. This way a tankers can't even discover them. Second, if an attacker does somehow manage to get in, we prevent breaches systems from being breached with our in-line cyber protection capabilities. And then third, we're going to prevent attackers from moving laterally across the environment where they're looking for those high-value assets. With the Zero Trust model in place, everyone's untrusted every device is isolated. That how Zscaler customers operate their branches, their factories and their cloud environments. And then fourth, we're going to use our in-line protection capabilities, data protection capabilities across all channels to make sure that we can stop sensitive data from either being accidentally or intentionally exfiltrated out of the organization. So why does this architecture matter? Not only do we connect users and agents only to what they need, unlike competitive solutions where the users and agents land on the network, but we also sit inside every traffic flow where most other solutions observe that traffic from the outside. We are a single unified platform where others stitch together different point products. And in an AI world, where exposed applications can easily be exploited, this difference absolutely matters. As I said earlier, if it's reachable, it's breachable. And we stop attackers from even being able to reach the applications in the first place which does wonders for preventing the possibility of a breach. So while we continue to drive innovation across -- and growth across our platform, a big focus in our product development over the last 12 to 18 months, has been building new product beachheads. This is an opportunity to land new customers and to expand to our existing customers as well. And we see this in 3 main areas: users, branch and cloud. So let me walk you through what we're doing in each of these areas, and I'm going to start with Zero Trust for users. So Zscaler Internet Access, Zscaler Private Access, so ZIA and ZPA, they have been the foundation of our platform for the longest time. This is how we secure users accessing the Internet, SaaS applications, private applications, whether they're hosted in customers' data centers or they're hosted in the cloud. We've been very successful helping customers understand how to implement Zero Trust for users to transform their overall security architecture. So this is a strong part of our business, and it's growing in the double digits. And these transformation projects, they are -- when they complete, they take Zscaler and they put us in place as mission-critical service for our customers. And the scale of this is unmatched. So Zscaler now protects nearly 7 million business applications for our customers and safely enables more than 55 million users every single day. Zero Trust transformation for users with ZIA and ZPA that's typically how customers have started their journey with Zscaler, and we've continued to drive industry innovation, specifically in this space. Now in particular, let's look at ZPA for a minute. It's seen a sharp increase in attention from customers in 2026 from the tailwinds created by AI. Mythos-like frontier AI models and AI-powered attacks are finding vulnerabilities, they're chaining them together to evade legacy perimeter security solutions. With ZPA, we're known for hiding that attack surface area and preventing lateral movement. We also now protect applications at run time with our new autonomous AppShield, virtual patching. And so this solution uses frontier AI models to continuously scan these applications that we're protecting. It's going to find vulnerabilities, create virtual patches for them, and we'll be able to protect these applications before a customer even has a chance to patch them. Just yesterday, we announced our partnership with IBM and RedHat to deliver virtual patches for vulnerabilities even more quickly, often before they're publicly disclosed. So ZPA represents a meaningful expansion to our installed base alone as approximately 30% of ZIA user licenses today don't also have ZPA. So it also drives new logo opportunities as prospective customers are urgently looking for new solutions to protect themselves against AI threats. Earlier, jay showed a slide and he talked about the Frontier AI model assessments that we did with over 400 organizations. The #1 ask that comes out of those assessments is what do I do next? This is exactly what we tell them to do. And a Global 2000 financial services customer was looking to reduce their exposure to vulnerabilities found by Mythos-like AI models. And they expanded their ZPA footprint to cover all 120,000 of their users. This increased that customer's ARR to Zscaler by nearly 50%. Okay. Now we're going to move over and we're going to talk about browser security. The browser is where modern work gets done, but web content can be risky. It can also provide -- also providing third-party contractors access with BYOD, so bring your own device. It's historically been hard and complicated. You think about it, a dangerous website, it can serve malware down and compromise an end user's machine. Also, limited controls can allow sensitive intellectual property that's in that application you're trying to protect to be extracted out. In Zscaler, we pioneered one of the most effective solutions for this problem, it's called Cloud Browser Isolation. And so with this approach, user accessing an application or a potentially risky website, they only see a streaming image of what they're browsing. And this means that they are protected against malicious content because no content is coming down, and the organization that's controlling this can easily decide what sensitive data even gets delivered to the user, what can they see and what can they do with it. Now while full cloud browser isolation is arguably the most secure approach out there, there are some cases like with third-party contractors where a simplified user experience through a local browser might be preferred. And so over the past 18 months, we've expanded our browser capabilities to include a browser extension that lets a customer work securely in any browser that they want as well as building and releasing a dedicated enterprise browser. And so with this, Zscaler now has the most comprehensive browser security offering in the market. And we think it can satisfy customers across any use case and beat any of the point product competitors. The result of this for Zscaler is a net new land opportunity where browser security starts as a potential first step in a customer Zero Trust journey, and we saw this play out with a Fortune 500 retailer, where we won a competitive deal against other browser-only security vendors. The customer who bought Zero Trust browser for 350,000 of their users, they had no previous Zscaler deployment, no ZIA, no ZPA, and this was the land for it. And then they plan to expand to more parts of our portfolio in the coming quarters. So that's just some of the incredible innovation we're driving in Zero Trust for users. Now let's talk about branch. Legacy branch solutions like SD-WAN, VPN, MPLS, they're typically quite expensive. They can be complex to manage, and they drastically expand the overall attack surface for a customer. Remember, all these are networking technologies. So they were built for a purpose, and that was to connect things together, not to provide security. We introduced our branch connector several years ago, and that was our initial solution to this problem. Over the past 12 months, we thoughtfully unified our branch connector and our micro segmentation capabilities into a line of purpose-built appliances that provide a true secure Zero Trust alternative to SD-WAN. The unified appliance that we built, it seamlessly connects the branch location to our Zero Trust Exchange and then leverages local micro segmentation to eliminate lateral movement within that branch location or factory. And so just by way of definition, micro segmentation, it's that ability to place every single device even small footprint IoT, OT devices into isolated segments. So this is where they can't communicate with any other device unless we explicitly or the customer's policy explicitly allows it. Remember that these devices, for a lot of customers, especially in factories, they're in places where they can't install additional software or software agents onto it. So it's critical that they're able to easily segment out their infrastructure to prevent lateral movement in these environments. The result again with branch security is a new land-and-expand opportunity for Zscaler. Highlighting this, it's a recent deal we won with the Global 2000 manufacturer who's deploying Zero Trust branch to secure their OT environment. Again, this customer had no previous Zscaler deployment. Their incumbent network provider had a shot at winning the deal to secure this environment, but the customer chose Zscaler to secure all of their critical production sites because of the way we approach this in a Zero Trust fashion. Now 40% of Zero Trust branch customers are new logos to Zscaler. So this is a great opportunity for us to accelerate our new logo growth. And again, it also provides an expansion opportunity to the rest of our customers once they are on the platform and are going down the Zero Trust journey with us. So now on to cloud. In the cloud area, enterprises have been struggling to secure cloud applications running in hyperscalers like AWS, Google, Azure, OCI. And the traditional approach is to bring that, what you know, so bring legacy firewall appliances and move them into the cloud, and they can be costly, complex to manage and not often able to really stop the lateral movement that we would want them to protect against. So when we started in cloud security space, we started with a Cloud Connector. This made it easy to secure cloud workloads running in public cloud. And customers liked that simplicity. They liked that flexibility. And they really decided they wanted this to be extended more and to be able to replace all the different use cases that they would want, where they would typically need to deploy a virtual firewall. This is why we introduced our Zero Trust Cloud Gateway in late 2025. And this is a managed solution designed to deliver Zero Trust for cloud workloads. And it includes micro segmentation. And overall, we'll run this service on behalf of our customers so there's no need to deploy and manage virtual firewall infrastructure. If you remember just before, I talked about this idea of micro segmentation in the branch and the goal of that is to stop lateral movement. We apply that same principle natively for cloud workloads. This time, it's an agent-based approach. And that's what allows us to do full -- all directions, north, south, east, west traffic flows in cloud environment in a true Zero Trust fashion. This too, creates new land and expand opportunities for Zscaler. We saw this at a global manufacturer. They deployed Zero Trust Cloud in a 7-figure deal to implement micro segmentation. The goal was to eliminate virtual firewalls, and they did this following a major cybersecurity incident, which brought their physical production environments down for over 6 weeks. This customer was able to get our Zero Trust cloud solution up and running in less than 10 minutes during their proof-of-value process, and that demonstrated the simplicity of our powerful cloud solution. So Zero Trust, as we described, this is a journey, right? And as I've described today, customers are starting that journey wherever it makes sense -- the most sense for them, could be users, could be branch, could be cloud, and increasingly, it's going to be AI agents, which Dhawal is going to talk about in just a moment. Any of these are starting points for customers to adopt Zero Trust SASE everywhere. And with our relentless innovation, our proven success in the market, we are really proud that Zscaler has been recognized as a leader in the 2026 Gartner MQ, Magic Quadrant, for SASE platforms. And if you dig a little deeper into that, Gartner says, 50% of new SaaS deployments are going to be based on single vendor SASE platforms by 2028, and that's up from 30% last year in 2025. So with what I described to you with Zscaler's Zero Trust SASE everywhere, we think we are super well positioned in this space to win with a comprehensive single-vendor platform in the SASE space. So we continue to expand our Zero Trust SASE Everywhere cloud presence too, to support more and more customers across more and more locations. And now what's increasingly important in many parts of the world now is cloud sovereignty, right? Our leadership in sovereign cloud, this is a structural advantage for Zscaler. The nature of our architecture, it provides us with the ability to maintain separate traffic processing, management and log storage, and we can do this in isolated regions around the world. And as digital nationalism rises globally, Zscaler is the only cloud-native platform that delivers global performance while we're meeting strict local data residency and unique regional requirements. So for example, our partnerships with providers like [indiscernible] Digits, who combine our Zscaler Zero Trust Exchange with their European sovereign cloud StackIt, they continue to support customers with sovereign cloud requirements, or together, we do, in ways that our competitors cannot easily serve. You're going to see us make further sovereign cloud announcements in additional regions over the coming year. So in my last few minutes, I want to talk to you a little bit about agentic security operations or Agentic SecOps. Now along with availability, reliability, performance, our customers benefit from our unrivaled telemetry across identity, network, endpoint, cloud, and they get this when they leverage our in-line Zero Trust Exchange. Now it's important to note, without accurate and relevant data, the value of applying AI models, especially in the cyber world, it's greatly diminished. But with this unique foothold we have on the endpoint as well as with this global cloud presence, we can see and stop threats that others are going to miss. We believe one of the most important ways to leverage these powerful vantage points and this telemetry is to apply it towards detecting and responding to cyber attacks. This is why we launched our agentic security operations solution a few weeks ago. So let me introduce you to our Agentic SecOps offering. Legacy SOCs, security operation centers, they were typically built to chase endpoint alerts and to search SIM logs and do this after the fact and most typically with humans in that process to try to figure out what happened after a threat was detected. Now that model itself has struggled in the past and now it's completely broken with AI-driven threats that are operating at machine speed. So with Zscaler's Agentic SecOps, we started with an agent-first approach. We have over 50 agents that are trained on our global telemetry and they're tuned by 10-plus years of human security experience that comes from our Zscaler Threat Labs team as well as our Red Canary Managed Detection and Response team. In our Agentic SecOps platform, we also brought together exposure management and threat management into one place. So what does this mean? This means that a customer can proactively work to reduce their vulnerabilities, their exposures and their risks and then they can use that information to quickly contextualize and automatically respond when a security incident is happening. That information is super valuable to go through an investigation. And so time and time again, our telemetry has proven to be very valuable to our customers and helping them investigate security incidents. And now we're operationalizing that value for customers with our Agentic SecOps solution. SecOps too does provide yet another land-and-expand opportunity for Zscaler. We had a Global 2000 manufacturing company engaged us to help quantify and manage exposure and risk across 700,000 assets. That was before Mythos. When Mythos came through, this customer realized that sampling their estate is just it was not going to be enough. They adopted our Agentic SecOps solution and expanded their coverage to more than 20 million assets to make sure that they could cover their entire organizational footprint. Now we're in the early innings of reimagining security operations, but we are really excited about our unique opportunity in this space. So to summarize, the Zscaler Zero Trust Exchange, it is the platform for the AI era. We think it's the best way to secure AI agents and to protect against AI-powered attacks. We've continued to drive innovation across our platform to expand our TAM. So not only does Zero Trust for users remain a powerful growth engine for us, but we've also unlocked new and upsell opportunities across users, branches and cloud. In addition, we're excited to disrupt the SecOps market and transform how organizations detect and respond to threats, which we believe will open up a large adjacent growth opportunity for Zscaler. And with that, I'd like to thank you for your time today. And now I'd like to welcome Dhawal Sharma to the stage, and he's going to dive deeper into what we're doing in AI and data security. Thank you.
Dhawal Sharma
executiveWelcome, and thank you, everyone, for joining us here. In this section, we're going to talk about 2 broad areas of our platform, security of AI and data security, which unlocks a significant TAM for us, as Jay showed, which is about $48 billion. And we have a sizable book of business already where we are securing data for our customers over the last many years. And earlier this year, we also introduced our AI security portfolio. As we have been selling this in the market, what we are seeing is there is a strong synergy between the 2. Persona of Chief Data Officers is overlapping and merging with the Chief AI Strategy Officers, and CISOs are getting deeply engaged in securing AI everywhere. Also, when you think about the traffic patterns, 80% of unauthorized AI traffic caused a data security violation. And as I creates more data, organizations are leading to build safeguards against AI with Zero Trust. And these are strong statements that have come from Gartner recently and we do strongly validate that in our customer conversation as well. As we think about AI security, we are seeing AI actually creating strong tailwinds for data security as well. We are seeing that AI adoption is growing in organizations. We have a strong book of business of more than $400 million in data security today, growing with a CAGR of 31% as well as, in the last 3 years, we have seen strong growth of 126% in this area. What is even more exciting, however, is that AI security creates a new entry point of Zscaler for customer acquisition? What I'm very excited about is the fact that 70% of security for AI deals in our fiscal Q4 actually had data security with it. And as we think about these 2 problem statements. They are actually converging and are becoming very symbiotic in nature. To understand how these 2 areas are coming together, let's look at the underlying problem statement. So in today's world, every app we have built over the years, every SaaS application is becoming agentic and is creating more data. Fundamentally, it is becoming harder to understand who has access to data what they are doing with it and what is the risk of their access to the data? Moreover, AI models are not just consuming your enterprise PII data and transforming that data. They are also creating more data. This creates more data attack surface for the organizations and also AI agents can work autonomously with no human in the loop, exfiltrating enterprise data to risky destination. In my observation, this is a new frontier that enterprises have not tackled before. Zscaler has been working in the area of AI security for many years. So let's talk about our security for AI solution for a second. We have been building this for more than 4 years, and you think about the moment when ChatGPT came out, right? Since then, there has been explosion of generative AI and agentic AI application. There are thousands of them that have popped up since then. We introduced our gen AI security product that provides visibility into shadow AI and also secures thousands of gen AI applications. Then we introduced AI Guard, one of the industry's first intent-based policy framework to secure what happens inside the prompt of these applications. In last 1 year, we are seeing that AI adoption, especially within the hyperscalers and neo clouds has accelerated significantly, which means people are building more AI infrastructure in the cloud. We introduced our AI asset management solution there to bring visibility into AI everywhere and then secure the posture and configuration of these AI applications as well. Then we also introduced the ability to do offensive red teaming through our acquisition of SPLX on AI applications that organizations are building to determine the risk of AI apps. 2029 the year when agents are going mainstream, whether embedded inside SaaS applications, whether they are built independently for the organizations. To understand the relationship of AI agents, data that they have been using and identities that they're using, whether they are human identities or nonhuman identities, we introduced the AI access graph through our acquisition of Symmetry Systems. We also introduced endpoint AI security that is built using our acquisition of Squarex. And finally, we introduced our AI Gateway that sits between every AI interaction within an enterprise and secures them with, and we'll talk more about it soon. When we think about security for AI and data security, the 3 big pillars in this area as we bring these together. And the thing that really stands out to our customer is that when we talk about AI, it also includes how data is coming with it. So the 3 pillars are discovering data everywhere and making sure the AI that is using that data is also discovered, securing every AI interaction and securing it with, again, cyber incidents like prompt injections, and the data that is getting transferred in those interactions and protecting those AI apps and infrastructure that you are building. So let's go deeper into the discovery to understand the shadow AI usage, but the problem is more layered than just shadow AI. It's not just AI visibility, but understanding how AI is connecting to data and identities. Let me explain it further. First question to answer in discovery is what AI and data exists in my enterprise? And where is it being used? We discover all kind of AI assets, agents, MCPs, agentic applications deployed everywhere, including public cloud, customers' data centers and SaaS applications. One important example of that discovery is our Zscaler Endpoint, AI Asset Inventory, where we discover agentic apps, locale models, AI development environments that your developers are using, local models and AI that your employees are using within the browser through extensions and what skills they are using? This adds the foundation and brings full visibility of not AI, but the lineage of data and identity within AI, which is really differentiated compared to siloed visibility that customers are getting through their EDRs, identity tools and cloud security solutions. Once we have discovered the AI and data in organization, it is important to understand who has access to that data and what are they doing with it? This is where our acquisition of Symmetry comes into the picture. It allows us to connect with various AI data identity tools that organizations are using and build a full relationship or the lineage and that is a very hard problem to solve for a lot of large complex organization. One of the key differentiator here is that we can connect to hundreds of tools in the organization in the connectors that we have built and also the data that we discover in line through our Zero Trust Exchange and what we discover on the endpoint, we bring it together. With this, we can provide the granular insights into the usage of these applications and how they connect to the enterprise data and understand the overall rate. Now risk is broadly defined in 2 broad categories here, risk tied to data and the risk that is tied to your AI. For data, we provide full visibility into risky behavior associated with the enterprise data, including sprawl of data, which is you could have a lot of duplicate in your environment, that could be very expensive. Sensitive data exposed to third parties or with the elevated privileges. And most importantly, we classify data everywhere, whether it's on the endpoint, whether it's in line, sitting in your SaaS services or public cloud, and figure out the risk associated in these very complex environments. This is what we do with Zscaler DSPM, or Data Security Posture Management. Now let's look at the risk that is tied to AI, and that includes how risky is AI deployments in the public cloud, understand the risk tied to AI models and risk tied to the configuration and posture of these models. And finally, help organizations build a full AI build-off material. To understand the supply chain, your AI applications are not living on their own. They connect to software packages, they connect to data stores. And building that full bill of material is something that we give organization with the full risk and that is what Zscaler AISPM, or AI Security Posture Management does. And most importantly, we remediate the risk with agents and integrate with enterprise workflows. Enterprises are really struggling in this area as we interact more and more with them. They end up buying multiple tools and need to manually connect the dots. And connecting the dots is where our acquisition of [indiscernible] has done a really good job. We not just connect the dots in these complex environments, but we also offer agentic remediation. Now let's move to the second area of our security for AI and data, which is connecting -- which is securing all the AI interaction. As you saw during Adam and Jay's presentation, our Zero Trust Exchange secures every enterprise interaction, including for the AI traffic that might be associated to agents that you are currently deploying or building. So think about a lot of our customers are deploying Claude code. Many of you use Claud CoWorkCare or codecs as well as autonomous agents and Assistant that are running on your computer or agents that run in the public cloud. For agentic traffic coming from employee laptops, enforcement happens on the endpoint from Zscaler with Zscaler Endpoint Security. And for the AI agents that are deployed everywhere else, we secured with our Zscaler AI gateway. Before we proceed further, now everyone in the industry is talking about intent and context. And your LinkedIn feeds, you must have seen what is the context-based engine, what is the intent engine? So let's talk a bit about that. When we secure users today, context is typically who is the user, what is their identity? Where do they come from? A corporate network, what devices do they use? What applications they are trying to go to? What is the user's risk profile or risk posture? Is it a risky user because they've done a lot of bad links. And based once we determine the all these actions, our Zero Trust Exchange grants the access to the user. And this context layer is gold and rescale has one of the richest contact layer that we have built for user over the years. When you think about the agents, the same context player is now extended to AI agents. Agents also have their own unique context, such as agent risk. Everyone is worried about your agents might burn too many tokens. So cost management, token usage is important, but agents also need to be governed based on the intent. And intent is essentially the task which was -- with which that agent was set up. For example, a customer support agent for a bank should not be giving stock advice. And that task behavior is very important to understand the intent. It is also important to understand how these agents are executing these tasks. They should not use very risky skills. They are now marketplace from where you can get these skills and use them to complete your task. The skill files, for example, can tell agents to steer traffic to an attacker server. And this is where Zscaler differentiation comes in the picture because we are the only gateway in the industry today that supports context and intent-based policy to secure the agents. Now AI agents could be deployed everywhere, most commonly on user devices, but also in public cloud, such as AWS Bedrock or Azure agent 365 or new cloud platforms, which have etch compute. Our customers can send traffic from agents deployed anywhere to over AI Gateway in Zero Trust Exchange. And this is where we integrate with agent identity platforms because identity is foundational for Zero Trust and start building the context layer. We just don't secure agents based on what they are, but also understand cost-based routing or more advanced policies that come with it. Our AI access graph gives us a unique and differentiated bottom-up context layer, which means that we know what data agents are using, what identities they have, and that context layer is unmatched in the industry today. So when we think about this architecture, what we are doing here, we are bringing the identity, we're bringing the context and intent as part of the policy evaluation. And if I have to summarize the 3 key points on why this approach really stands out for our customers. We're not just secure agents going to Internet, but also understand more advanced protocols like MCP deployments. MCPs are de facto in many enterprises to standardize agentic communication. And we have an MCP gateway built here as well. We are also the only gateway to support both deep context and intent, as I explained. And most importantly, built with our DNA of building large-scale gateways is ZIA and ZPA in last decade to deploy these gateways to handle billions of entities that are going to come at a very large scale compared to many agentic gateways that we see that are deployed only within a specific project or do not scale at that level. Now let's talk about one immediate security problem that I'm running into while talking into security teams every single day, how to securely deploy genetic apps such as Claude, Codex or one of many AI assistants securely within the enterprise? Traditionally, attacks have focused on user devices such as laptops, purely on the operating system, file systems and software that employees are using. And this is where we partner with every EDR vendor because they are really good at securing that attack vector. But AI is introducing new attacks targeting users that are primarily focused on the apps that your employees are using, AI assistant they are using and the AI they use within their browser. For example, implies are downloading seemingly benign files that look clean when they are downloaded initially. But these files can reassemble later and become malicious using what is called a last-mile reassembly attacks that EDSs can't easily find. What EDRs also do not secure is data exfiltration on the endpoint, whether that is transmitted locally using a USB stick or using a local MCP server that a developer has installed on their computer. This is where our endpoint AI security product comes into the picture as AI apps usually get full access to data on the user device and can transform that data via prompt and transfer it to unauthorized destination. We provide 3 fundamental set of capabilities here. We are usage control to provide controls on usage of sanctioned AI and detecting [indiscernible] or shadow AI on copra devices and do granular controls with these apps. For example, we do not allow data transfer between a corporate version of ChatGPT and a personal ChatGPT in the same browser. Cyber protection to understand malicious skill usage, use of risky AI models on the endpoint, you know that you can actually run a small local model embedded inside your browser or on the device now. And these could be used to create sophisticated phishing attacks through prompt injection in multiple turns. And these are the kind of things that EDSs can't find. And finally, data protection. Zscaler has the endpoint DLP product that discovers, classifies, monitors data everywhere and allows you to build consistent DLP policies around your data, including what goes inside the prompt and or data that is going out through browser plug-ins. This is a very refreshing approach for enterprises that we work with, the security teams we work with because they do not need to deploy multiple agents and get fully integrated AI and data security solution, which is very complementary to their EDRs. Data also needs to be secured in line or when data is in motion. And there is -- that is where we had a significant advantage as we secure data with Zscaler DLP across all channels where data can exfiltrate Data, as Jay explained in ransomware as either is going to Internet to attacker servers or to unsanctioned applications. Data can exfiltrate over e-mail or prompts within these applications. Our embedded chatbot that you're using, for example, if you use a food ordering up, it has a GPT powered chatbot underlying it. Intent of ransomware attacks is always a steel data. And if you have deployed Zscaler DLP to protect those channels, we prevent this from happening. So what I do want to highlight here is the fact that because of our Zero Trust Exchange architecture, we have a unique advantage. We have a proven proxy-based architecture to intercept and secure any data leaking to the Internet. We provide a uniform policy layer for data security across all channels. And all of this is delivered through a single Zscaler client that is running on more than 55 million devices today and customers don't need to deploy a new agent, which is really a very important point for organizations as they want to simplify what goes on their corporate endpoints. Let's look at example of a large global financial asset management firm that leaned in with our data security and how that created an upsell for AI security solution. The challenge this organization was facing is lack of visibility into data in their public cloud environments and limited classification of data sitting there. Using different data security products to secure data in public cloud and different for on-prem as something different from endpoint, they lack the full picture of where is data and what's happening to that data. With Zscaler DSPM solution, they uplevel their data classification and got a much broader coverage of data asset stores that they have deployed. As they connected more data stores, they understood the AI's probe and how AI is connecting to their data. And that led to the evaluation of AI security offerings. And within 1 quarter, we upsold them Zscaler AI security. The benefit from customer perspective, 1 of the main benefit was discovering better bytes of redundant data, which they removed and had lot of cost savings around it. We also understood the data access across their organization with upgraded data classification, and most importantly, single solution to secure data everywhere the pre-supported connector for every data store that they use within their organization. This also led to a $5 million worth of ARR expansion for Zscaler in this account, and our DSPM outperformed the stand-alone DSPM they were using which they replaced with this. Now let's move to the third pillar, which is helping organizations protect first-party apps, MCPs models and data stores they're using within their organization. To protect AI systems, we focus on securing full life cycle of AI within the organization. So starting from when you are building these applications to when you start deploying these production using our Zscaler [indiscernible] product, as I explained that came through acquisition of SPLX. And then once you deploy them in production, we secure these apps with our Zscaler AI [indiscernible] solution. Today, we are the only vendor in the market that is a fully integrated AI red teaming and a guardrail solution that takes input from the red teaming and enforces automated guardrail policies to secure on-time behavior of these applications. Now let's take a look at red teaming for a moment. We provide -- in this solution, we provide a catalog of dozens of supported agent platforms or model providers, hundreds of other providers are supported and thousands of MCP servers on Internet are already prebuilt and supported with it. Next, we have a library of preconfigured test profiles around safety, security, hallucinations of these models. And once you configure those tests, we can simulate 5,000 attacks like how attackers would attack our applications and test it with multimodality of like throwing tech image files to see how your applications break. This help enterprises find vulnerabilities and risk in their apps before they go live in production. But with our model benchmarking and baselining for frontier labs, open rate models, we help organization compare and pick the best models. One important thing to remember is that the entropy or the change in AI applications is usually very high. Every time a new model version comes or a new software liability is released, the overall risk posture of these applications increases. This is why we support automated on-demand red teaming. And finally, we are the only red teaming solution that provides an integrated and stand-alone prompt hardening service, making sure your apps are -- that you're building like chatbots when they interact with AI models, they have a very consistent hard and prompts they are creating. If prompts are not harder, we often the remediation as well. Next, when these apps move into production, such as everyone is building an employee-facing chatbot today, which almost every enterprise has built with a small or a large language model they have deployed or a frontier model that they've deployed within their organization. And this is where we basically analyze the risk request going into these chatbots and the response that come from the applications through their models. And a true intent-based inference or a run-time as security policy engine that secures every prompt and reviews every front as it is getting to these applications. This strategy of securing prompts across heterogeneous environments, such as multi-cloud system. So a lot of our customers basically are running their -- or consuming their model from 1 hyperscaler, their application is running on different hyperscaler. And one good moat that we have built here is that our customers, like how they -- Adam talked about Zero Trust cloud to provide same security for across all hyperscalers. We provide consistent guardrails across any model provider, any hyperscaler. And since we anticipated the need for such intent-based policy a few years ago, we had a head start in this area when we introduced AI [indiscernible] 2 years ago and have started creating a catalog of predefined detectors across different industry verticals and different use cases that are trained with use case specific data sets and small language models that we run on GPU-based infrastructure in our cloud so customers can easily deploy it with few clicks. We have also extended the guardrails for this AI [indiscernible] to prompts that are going through our escalaInternet access for a 3,000-plus application. And finally, here, we are able to enforce policies based on the token usage by these applications. We can tell you which users are using how many tokens and we can do cost controls on that as well. As we bring this together, right, to summarize, what we have covered so far across 3 pillars and how it comes together is a single integrated solution for our customer is that it starts with the discovery layer of every AI asset, including on the end point, models, applications, MCP tools and understanding its deep relationship with data and identities to create an AI access graph that allows us to build very comprehensive DSPM and AI security posture management solutions. This also builds a highly differentiated context layer. That enforces policies to secure every interaction with our AI gateway and of our agents deployed everywhere while we extend AI security to user devices with discovery with the AI endpoint security. And by the way, with AI endpoint security, we have also embedded Mythos 5 model in early access to find more sophisticated attack parts on the endpoint as well. And then protecting apps through build, deploy and run-time life cycle with direct teaming and AI [indiscernible]. Let's look at another example or a case study of a large global system integrator with more than 400,000 employees who lean in with our entire AI security portfolio that I just talked about. This organization had a very open access to gen AI applications for a couple of years, then got audited for very high risk due to data exfiltration risks. And as a result, access to all AI application was revoked within this organization. Business started losing competitive edge, as you would know, in today's world. A customer who was already a Zscaler Zero Trust [indiscernible] customer started enabling sanctioned AI applications for our employees with Jennie visibility and AI [indiscernible] for users to secure traffic. They also started mandating AI red teaming for first-party apps they are building and also started deploying agentic co-work application for the employees using our endpoint AI Security. This customer saw the value of consolidated AI platform, which already integrates with investments in data security, DLP, and in a full flex deal for entire AI security portfolio. That gives them access to the entire portfolio that I talked about and everything else we are building in this area. Broader access to -- from a benefits perspective, broader access to a catalog of AI apps and being able to do on-demand red teaming first-party apps while keeping the compliance with some European AI Act or risk management was a big differentiator. And this customer did a $5 million plus security for AI deal with us in fiscal Q4, raising the overall ARR for this account to $80 million. Now as we wrap up the session, I want to summarize what really excites me about this massive opportunity and why we are bringing AI and data security together, not just for -- by the way, for us, but also for our customer in terms of outcomes that they're driving with us. So our leadership in data security creates a strong demand for security as AI security outcomes are closely tied to data security and data problems. Pace of innovation is moving at lightning speed. Customers are looking to buy consolidated platforms versus individual point products to secure AI usage. And we believe the Zero Trust architecture is fundamentally built to handle the scale of AI agents, and this is where we have an undue advantage. And finally, both security for AI and data security solutions allow customers to deploy these products with no dependence on rest of the Zero Trust SASE portfolio. It can be onboarded and sold on its own. And with that, I would like to wrap this presentation. Thank you for paying attention. And Next, we will move to the customer panel. You have heard this morning us talking about our architectural advantages, forward of Zero Trust Exchange and how our solutions are helping our customers navigate a rapidly evolving threat landscape. But ultimately, the most important perspective is coming from our customers. And this is why I'm glad to be joined by 3 of our estemed customers here. [indiscernible]. They are a leader in global paints and coatings with a presence in 150 countries and ideally know this customer because -- they became a customer that ARI joined Zscaler in 2012. So they're long-term Zscaler customer. Marsh McLennan, the world's largest insurance broker and a Zscaler customer since 2019. And and Merck, a leading global pharmaceutical company, our customer since 2022. We were intentional about bringing together customers from different industries to illustrate both the breadth of all the challenges that enterprises are facing and increasingly universal need for modern security architecture across different verticals. Our panelists will share more about the challenges they are facing, how they prioritize their security challenges, how their projects are changing in the AI era and what they're looking from AI security solution. So let me introduce our panelists. Please welcome [indiscernible], who is the CIO of AkzoNoble, Curt, please join us here. John Easton, who is Global Head of Networks and Security at Marsh McLennan. And finally, joining us virtually is [indiscernible], who is the Deputy CISO at Merck. Thank you, everyone, for being here.
Dhawal Sharma
executiveI will kick it off with a quick question and then we will open up the floor for the audience in the last 10 minutes as well. [indiscernible] these challenges that your company faced when you first deployed Zscaler and what your Zscaler journey has looked since then?
Unknown Attendee
attendeeYes. I think first of all, there was the protecting of the Internet was at the time that we still had MPLS networks. I think if you look at the journey, all the products that were at the bottom that Adam showed, I think we have deployed them. So visibility with the ZPX, we ZPA. We have RISK360 and I think if you look at it more recently, like 2 years ago, we wanted to go to open Internet everywhere. So that's 995 locations. So we do that, on the one hand, with ZPA, on the other hand, with the branch connector. So it's really, I think Zscaler is fully underpinning or giving us the technology to do what we would like to do.
Dhawal Sharma
executiveAnd coming to you, John, you've been a customer for a while as well. and our relationship has been evolving. I remember, especially interesting time during COVID ZPA deployment. Can you share some of your initial thoughts on how you deployed Zscaler initially and how that has been evolving?
Unknown Attendee
attendeeSure. Yes. So when we started with the Zscaler, we were -- I think like many other companies, we had a centralized Internet, everything went through data centers in a couple of different regions, legacy proxies. We wanted to digitize our workforce and Zscaler was really what we thought was the best way for us to secure that internet traffic, in particular, enable that business to use those more modern tools. ZPA, we began testing initially. We had a specific business use case for it, and then COVID accelerated that plan pretty quickly. But really to the credit, and we deploy it over a matter of days to our workforce of, I think, 75,000 to 80,000 at the time, we're 100,000 now. Everybody using that as our primary tool for remote access and even in the branch office Zero Trust model, I'll talk about a little more later. But yes, our relationship has continued to grow as your product portfolio has grown very successfully.
Dhawal Sharma
executiveSo key point is that you started with focus on protecting users and the use cases have been evolving since then. Bob, I'm going to come to you. You have been a full platform adopter. What advantages you believe you've got from leveraging the full breadth of our platform? And how that has been evolving for you in the last 4 to 5 years?
Unknown Attendee
attendeeYes, sure. Thanks for having me. Yes, I mean. [Technical Difficulty]
Dhawal Sharma
executiveYou are looking the whole spectrum of Zscaler offerings. You're also a Z-Flex customer, right? So can you talk a bit about as you looked at the entire landscape what Zscaler is doing, and we talk regularly on what is on the truck coming soon, how did you move from product-based licensing to Z-Flex? And what are the thought process behind it?
Unknown Attendee
attendee[Technical Difficulty] Pull in another capability to test out without having to go back and do specific product-based licensing. So we've been able to check out things like the branch connector and even some of the more, I guess, newer offerings, advanced offerings like the Zscaler cellular in some of our manufacturing areas. So that's been very helpful for us as we've deployed these capabilities across the enterprise.
Dhawal Sharma
executiveThat's amazing to hear that we have customers who have started adopting, deploying cellular technology that we have, the release same on actually production environment. We are seeing a significant uptick in that now. Coming to -- go ahead. You've been at-scale customer for our Zero Trust branch offering. You started pretty early when we had the branch connector. You also have some very complex OT environments and securing civil comes with lot of legacy infrastructure as well. Can you talk a bit about when you thought about bringing Zero Trust to the branches, and I'm pretty sure you had SD-WAN, what made you think about adopting Zero Trust branch? And how do you see that as fundamentally different from SD-WAN?
Unknown Attendee
attendeeSo basically, we had the ID Internet everywhere with the aim of taking out all firewalls everywhere and also getting rid of SD-WAN. Now if you look at the offices, if you look at warehouses, that's fairly simple, if I can say. If you take that into the factories, it's more difficult because you have the PLCs, you have SCADA you have devices on which you cannot implement agents. So that's where we looked at the branch connector. And it's actually -- the 4th of October was our first deployment last year, not 2 days ago. So we're currently at 69 sites, factory sites that have been deployed out of 110. And it's -- so the thing is that we have a mix of everything, any equipment you could buy in the last 30 years we have, we have fairly old, we have fairly new. But basically, the intention is to implement the branch connector and the micro segmentation. So if you look at it I think in addition to that, also what said is that with the aim of going to Internet, open Internet, it was also aiming at a significant cost reduction and also the Zscaler SIM, so rather than replacing all the network equipment, for instance, in a warehouse. We put the SIMs into the scanner so we don't have to do the big investments. And maybe one anecdote, when we did [indiscernible], that was the first site, we organized a prize setting for our security team. So I said the first person that can break in, and they were allowed to use any tool, would get a nice prize. And I think 2 days later, they came back is, well, we can't find it. So I think that's -- there was also one of the statements if you can't see it, you can't hack it. But for me, that was really an important proof point that this is the right way to go over.
Dhawal Sharma
executiveThat's amazing. We actually have a lot of customers do that. as part of testing, they bring the Rogue, access points in their shop floors, plug it in and say, what can I find the technology the way we have built, you don't find anything else for that. Now John, you have unique advantage of running network and security both, right, in the firm. So one thing that everyone wants to know is like, how do you realize the advantage of using a Zero Trust architecture? Sometimes security and network look other way. So how did you bring that convergence of Zero Trust for architecture to protect your users everywhere?
Unknown Attendee
attendeeWell, and I think, over the past 5 years, the network and security has really converged and that's why we've made the organizational decision to combine them. But in today's business world, we need to really support our business to be able to execute at almost machine speed. AI has only accelerated that. So our ability to -- or using Zero Trust, we reduced the element of friction for our users, giving them better access, faster access, while simultaneously improving the security model. So it's a nice convergence that you don't often see. They -- we find our users are preferring the new model leveraging Zero Trust. They're able to do more and we have more visibility and it will secure it more and Zscaler tools have really enabled that ZPA has become the foundation of our Zero Trust model, providing that access broker for all applications, making sure that all of our users can access the applications they need to and not of the access -- don't have access to the applications they don't.
Dhawal Sharma
executiveYes. And I think experience is very important with security. And I think what ZDX does in this space is giving you visibility of user experience with a Zero Trust architecture also unlocks a lot of bottlenecks that we traditionally have seen with network, right?
Unknown Attendee
attendeeAbsolutely.
Dhawal Sharma
executiveYes. So let's switch gear towards AI, right? I talked a lot about AI and how awesome or AI security is. But I want to start with the speakers, Bob, coming to you. You guys have a big directive to deploy -- use AI for innovations. And can you talk us first of all, key use cases where Merck as a company is leaning in with AI. And what security challenges it create for you as a security leader as AI gets adopted widely?
Unknown Attendee
attendeeI am muted. I didn't want you to hear my team's alert. So I say we're going on, sorry. So yes, we made a public announcement earlier this year about $1 billion investment into Google Gemini as kind of our main orchestration platform across our enterprise. And we have several, we call lighthouses, or kind of lines of effort across the enterprise to help our organization. I mean at a high level, what we're trying to do is typically a drug takes about 10 years of development and of all the drugs you look at of all the molecules you start to investigate, maybe 1% of them will go to market. We're trying to get that down to 5 years and 10%, right? So it's a really interesting multiplication there of effort. And AI is going to really help us drive that forward. So there's various efforts to help the research element of Merck, even the manufacturing, even some of our global support functions to include IT and finance fee more efficient with what we have in rollout pardon me. and roll out more drugs in our pipeline over the next 5 to 10 years. So AI is a big part of that. And obviously, this business is focused on it. So we have to be focused on coming behind and making sure it's secure. So what I'd like to talk about is the AI governance, safety and security governance life cycle. So we're focused on how we're intaking various AI applications, agents and models. We're categorizing them by risk. We're applying appropriate controls, remains controls, and then we have compliance and auditing against them. So we're using some of the scale AI products to help in that journey, and we've started rolling them out actually last quarter.
Dhawal Sharma
executiveYes. That's great. John, I'm pretty sure you are looking at AI very closely in the form as well. some of the challenges that you are seeing, not just from security but from also how you connect your network traditionally to these AI ecosystems?
Unknown Attendee
attendeeYes. I mean so from a business perspective, we have 3 pillars of strategy for AI. One is -- the first is individual productivity using internal chatbots, similar to ChatGPT, working at business process optimization, how can we take our existing processes and use AI to improve efficiency and optimize there. And then more business process transformation, how do we transform our business to operate more effectively and win in the AI-enabled world. So we've had to -- so with all those challenges, you need to secure the environment using AI and you need to protect the environment from AI. And that's become really the critical challenge that we're working on working closely with partners like Zscaler to do that with the portfolio.
Dhawal Sharma
executiveAnd you have been given great feedback on our guardrails and detectors as the use cases requirements in each organization keep evolving. So really appreciate the feedback that we got from you. Your world is very different, Kurt, when it comes to agents and security, and we were at dinner last night, you actually, we were surprised to see how vast is your footprint of AI from not just employees but also in your plants and manufacturing and other places as you're thinking about AI usage. Some -- how are you thinking about AI security evolution in order to protect in these complex environments?
Unknown Attendee
attendeeSo I think currently, we have 8 AI towers, where a lot of the things we offer internally, like all users have access to more than 12 models, including some of the Chinese models, which may sound strange, but we allow within a framework to use it. And on the 26th basically, we will offer a tool kit to all our users to create their own agents. So it's really the challenge to make sure that the guardrails we have that they're good enough and then basically to see basically what everybody is doing and to be able to intervene where things get -- might get out of control.
Dhawal Sharma
executiveOkay. And we know that you have recently started looking at [indiscernible] portfolio, and we are going to take a deeper look at it as we.
Unknown Attendee
attendeeWe are piloting solutions so, yes.
Dhawal Sharma
executiveAll right. In interest of time, last question for you, Bob. We recently launched our SecOps offering, and you have been a Red Canary customer prior to acquisition as well, and you have been a strong voice in how we should be evolving the acquisition of veterinary into the agent secops that we have built. Can you share some insights what you're looking in terms of how this should come together?
Unknown Attendee
attendeeYes, I'm actually a 3-tiered Red Canary customer. So original view of the Managed Defense or MDR solution and Red Canary is to really push all of your, what I call, high fidelity alerts into the platform and it can really triage that scale. So those types of alerts would be coming from your EDR or maybe things like Wiz or guard duty. Low fidelity alerts would be things coming from Palo Alto or even in some cases, like the [indiscernible] Zscaler alerts like ZIA alerts coming through because it's just such high volume, most of them are either false positives or just indications of blocking. So I initially tried to focus the Red Canary solution on the high fidelity alerts, which we had about 20 agents in the platform that are running over all the data and really automating everything we did, and it really helped us out lower our mean time to remediate significantly and lower the number of incidents we're seeing per day or investigating per day and allowed us to kind of move up the maturity curve. And that was kind of Stage 1 or Phase 1, which worked really well. And now what I'm really excited about for Phase 2 is that kind of lower fidelity data how can we use agents to go across that data and do more of kind of a hunting. So the first one -- first case was more of like triage and maybe automating the initial stages investigation. In the second phase, it's more like true hunting, looking for anomalies, pulling threads. And I think AI is very good for that kind of recognizing patterns and we're kind of experimenting with that now as a design partner with Zscaler to roll that out. I think that's going to make a huge difference and really kind of complete a full AI-driven stock.
Dhawal Sharma
executiveOkay. Thanks for sharing insights as well. Now we will open the podium for the questions from the audience. If you could please raise your hand, we have mic runners in the room who will come to you. Please state your name, your firm's name and ask your question to the panelist. Let's start over there in the front.
Michael Cikos
analystMike Cikos with Needham. We're all hearing the presentations you guys you're listening to this on AI security. And I'm just trying to get a sense, if you're thinking about your cyber budget today, let's say, it's $100, right? And you're spending make up a number $10 on Zscaler 2 years ago, what is that percentage of spend today? How does that change in the next 2 or 3 years just given incremental AI security budget that you guys will be spending on these solutions?
Dhawal Sharma
executiveSo I think this question was not addressed to anyone, so I'll take the liberty for maybe starting with you, Kurt.
Unknown Attendee
attendeeOur thing to give percentages is difficult. The only thing I can say is that almost every new team that comes out, we look at and we adopt.
Michael Cikos
analyst[indiscernible]
Unknown Attendee
attendeeDo you see more of that value accruing to sellers than for identity I think it's mainly additional because the good thing about this career is I think about the problems you will have that you don't know yet that you will have them. So by the time you encounter the issues, there's a ready solution there. So in several cases, we did not even do an RFP like on ZDX. We just basically -- we tested it. We liked it, we agreed on the price and we deployed it. The whole -- I think what is very important with Zscaler is the concept on if you have the clients, I think it's also what you said, deployments happen within days of new capabilities.
Dhawal Sharma
executiveBob, anything you want to add to this?
Unknown Attendee
attendeeWell, I guess we're in a slightly different boat because we have sort of like an ELA with scale. So we kind of have nearly all of the portfolio or access to it. Obviously, there's some separate items that we buy at cost. But I'll say, I don't want to give percentages, but I'll say it's one of our top security vendors that we have on spend. Spending in security is obviously a little difficult to calculate because we spend a lot on Microsoft in security, but that's part of our larger Microsoft budget. But for our own budget within like our security group, it's one of our top items.
Dhawal Sharma
executiveLet's go to the next question in the front here.
Saket Kalia
analystSaket Kalia, Barclays. Thanks so much for hosting this panel. Super helpful. Maybe this is a question for everybody if possible. So as your usage of agents across the business -- across your respective businesses grows, how do you think about your usage of current Zscaler products like a ZIA or ZPA? And which other Zscaler products maybe become more relevant as that adoption grows? Does it make sense?
Dhawal Sharma
executiveJohn?
Unknown Attendee
attendeeYes. So what I would say is in the AI world, Obviously, things change, but we don't see a -- strong well-architected layered security model is still the best defense against these -- against the security environment. So nothing changes for us from that core set of tools we purchased from Zscaler or anyone. There are absolutely AI-specific use cases that we need to address and Zscaler is building a really interesting portfolio that we're evaluating. But really, our focus is on AI speeds everything up, especially in the attack space. But that core is still really important and something we -- I would say we're still very focused on and even doubling down.
Unknown Attendee
attendeeMaybe 1 example is, we want to go to fully ticketless which basically, we need to have all the inputs and the signals. So what you see is that Zscaler is also AI enabling, if I can call them the older products like ZDX. So we have an intelligent hub. And then the ZDX feeds in basically what is going on. So that also basically allows us to do more in a fully automated way. And I think as security becomes ever more important, it just is the whole suite that adds the value on.
Dhawal Sharma
executiveThat's a very good point because what I've talked about was security for AI, but we are also doing AI for security in every core product. And that also is leading to a lot of exception. Like a good example is deception product where we actually have LLM [indiscernible] for LM. So that becomes a natural expansion use there. So let's move on to this side right in the front here.
Keith Bachman
analystIt's Keith Bachman from Bank of Montreal. Wanted to ask a 2-parter. Where do you think you are today in your AI journey in terms of AI adoption versus where you might be 12 to 18 months from now? And the corollary part of the question is, how do you think about, not necessarily the companies per se, but just the incremental security that you need to adopt to enable further AI penetration, for instance, a lot of vendors talk about governance solution, cloud security agent identities. How do you think about just where you need to adopt technologies buckets of spend, if you will, in security? And how does that compare and contrast to your aspirations for AI adoption over the next 12 to 18 months?
Dhawal Sharma
executiveBob, do you want to take?
Unknown Attendee
attendeeYes. And your question is you're asking where are we with AI adoption like at the enterprise or within the security organization?
Keith Bachman
analystWithin the enterprise broadly.
Unknown Attendee
attendeeOkay. Yes, and we hear we have a pretty accelerating model on adopt. So the core folks in our -- we call them lighthouses, too, when there are lighthouses like in the research labs at MMD are fully adopted in those use cases. But across the enterprise with like business process assistance, the Copilots, things like that, we're moving towards a higher percentages there. It's accelerating every month. So we're keeping an eye on that. But those agents are pretty controlled in orchestration platforms. So like, for example, like the Gemini that we use is kind of this orchestration layer that automatically has controls and harnesses across all the agents developed in there. So we feel that they're pretty safe rolling out there. We're trying to drive users to adopt there instead of bringing in the new type of agent in our model. So that's good. And then your question about like where do you see the spending going and especially around like security governance. So I think every organization is struggling with this. Every vendor I talk to has a different approach on security governance, I don't think it's figured out yet. And what we're doing -- kind of the first thing we want to do or what we're doing is this kind of like a blocking and tackling mindset. So just because the AI is rolling out very quickly, it's a use we need to be monitoring it, controlling it and blocking and tackling issues that pop up. So we've established a couple of different vendors to help us with that and a bit of kind of a Tiger team to stand up and do that. But that's kind of a temporary solution. It's a process that we had to develop because it was needed. And we're having a study going on right now in our organization to identify how we're going to do the governance process over time, build a larger orchestration platform that's going to work across legal, governance, ethics, compliance and IT and engineering, which is pretty complicated. So that's kind of where I think the money is going to -- the funding will go in the next couple of years is towards a more robust solution that can take these atomic level feeds from all these areas to monitor what's going on, categorize it and satisfied stakeholders that I just mentioned, which is pretty challenging. And we've not really seen anybody come across and do that yet. Zscaler is certainly a part of the solution, right? But it's not the whole solution because there's a lot more that has to be involved in it.
Dhawal Sharma
executiveYes. I think the key point I was making is an evolving landscape. And one of the things that we are able to do is provide flexibility for customers to see what is relevant and needed for them, and they can switch to what is needed.
Unknown Attendee
attendeeCan maybe just spending money on security for AI is not a choice. You have to do it. spending money on agents, there, you have the choice depending on the consumption.
Dhawal Sharma
executiveAll right. Let's go in the middle somewhere over here.
Brian Essex
analystBrian Essex from JPMorgan. I had a question for Kurt. Within your manufacturing facilities or shop floor, I'd love to know how you're addressing the risk to your operational technology within those facilities? I think you mentioned you might have some stuff running on SCADA. So how are you addressing the architecture and risk posture within your manufacturing facilities? And how does Zscaler help you do that?
Unknown Attendee
attendeeYes. So previously, the way we run our factories is like islands connected from the main network. But once a hacker is in, they can go everywhere. So I think, first of all, with the branch connector, we try to make the site invisible. And then in case there's still a breach, with the micro segmentation, we limit it to just a number of systems. With regards to the PLCs, well, Zscaler has solutions for that, for the horizontal flow. And I think it has been a challenge, to be honest, because a lot of the technologies that we have are different. So it was not you have done one, you can now do 100 other ones. So every site we need to learn about. But basically, it's -- the impact that Zscaler brings is totally reducing the attack surface. And when something happens, we have the visibility.
Brian Essex
analystAre you adopting AI within those facilities? And how are you addressing the potential risk if you are, in fact, doing that?
Unknown Attendee
attendeeSo I think AI is the next step. It's initially in putting in place the protection and then you have the triggers and then those triggers basically are being followed up. I think more and more AI will be used there to then, yes, just take those triggers are really relevant.
Dhawal Sharma
executiveI think this is a great point to like wrap the session. And we have a great point where we actually have had a wide variety of topics that we discovered. So I want to thank all of our panelists and -- for joining us here today and for the insightful discussion with me and all of you. Before we break, I want to take a minute to reflect on a few key themes that have emerged since -- in this conversation and what we have been discussing since the morning and based on discussions that I've been having with customers. First, these conversations continue to reinforce our position as a strategic partner to our customers. What often begins as a single use case, for example, to protect users, then evolves because of the architectural advantages into expansion of Zero Trust Exchange beyond users to workloads and branches and expanding our platform deployed with the customers. Second, our customers are increasingly relying on Zscaler to solve complex problems. The Flex programs give them that flexibility. They can innovate with us. They can be design partners and solve security challenges and go hand-in-hand with us on some of these emerging priorities. And third, AI is a big opportunity and it is also a challenge from an architecture perspective, and we are looking to help our customers navigate both. The need to securely enable AI while also making sure that threats are -- you're protected from that is critical requirement. So against this backdrop, the opportunity is significant, and we believe Zscaler is uniquely positioned to capture it, helping our customers succeed in this very complex world. With that, thank you again, Kurt, John, Bob for joining us here. And I will now welcome back Kim to the stage. Thank you.
Kimberly Watkins
executiveThank you very much. And now we're heading into a short break, which you're probably very relieved about. We'll take about a 10-minute break. But before we do, I just want to put the demo slide up once again. So right outside the door, we have 4 demos. So a lot of the solutions that we've talked about today, from our Zero Trust SASE offering to Agentic SecOps, which Adam talked about both of those, the Zero Trust Exchange for agents, there's a familiar face there that's also what Dhawal talked about and data security solutions, which Dhawal talked about as well. The person who is hosting that is actually the CEO of Symmetry. So -- the former CEO Symmetry, now on a Zscaler employee. So enjoy those, and we'll see u in 10 minutes. Thank you. [Break]
Kimberly Watkins
executiveWe are ready to get started again. So come on in. Take your seat. Before I introduce our next speaker, I wanted to mention that we'll be sending out a post-event survey after today's program. We would really love your feedback. So please please fill it out. And our goal is to make sure these types of days are most valuable for you. I also wanted to give you a brief reminder. Today's presentations contain forward-looking statements within the meaning of the safe harbor provisions of the federal securities laws. -- including statements regarding our future financial performance, business strategy and market opportunities. And with that, it's my pleasure to introduce Ross [indiscernible], Zscaler's Chief Revenue Officer. Ross?
Unknown Executive
executiveThank you. All right. Thank you, Kim. Welcome back from break. I'm going to go over our go-to-market strategy for the next 4 hours. So I hope you buckle in, I am going to go over our go-to-market strategy for about the next 20 minutes. But before I do, I wanted to provide some background on myself and introduce myself to you all. I've been at Zscaler for about 3 years now. The first 2.5 of that, I was successfully running our largest geography, the Americas. And in the last roughly 6 months, I stepped into the worldwide sales leader role, where I was responsible for delivering on our global sales number. As part of that role, I've been heavily engaged in the annual planning process for both our operational and financial plans. We have a strong strategy, a strong plan in place and the entire team is focused on executing. I am very confident this will be a seamless transition. There are some key messages that we want to make sure we get across in this session. The big one, as Adam and Dhawal and Jay have mentioned, is Zscaler was and is built for this AI moment. We have the right platform, the right team, it's the right time right now to be successful. We've built this durable go-to-market engine, and we'll talk about how we're leveraging that go-to-market engine to capitalize on these AI tailwinds. I'll begin with a few key reasons we are well positioned to capitalize on this moment. First, scale and global presence. Our customers are global, their security challenges are global and we have local geographic coverage all over the world to provide the best customer experience possible. We serve customers in more than 185 countries globally, with 25 countries generating over $10 million in ARR and 7 countries exceeding $100 million in ARR. This worldwide reach is a differentiator for us, and our international scale and strength is evident with greater than 45% of our ARR coming from international markets. Next, we serve an incredibly diverse customer base, spanning across all industries and verticals. Overall, we serve over 50% of the Fortune 500 and and over 40% of Global 2000 customers and accounts. This broad presence demonstrates the universal relevance of our solution to enterprises globally. You can see a few examples on this slide of verticals like hospitality, technology and retail where we work with a majority of the top companies in those sectors. This broad coverage has a strong network effect. CSOs and CIOs often buy based on advice from other CISOs and CIOs. So this places Zscaler in a unique position for continued growth. Now I want to talk about how we go to market by segment, how we're organized internally. Our major segment at the top of the pyramid generally includes accounts with 40,000-plus employees or a very large propensity to buy from Zaheer. These are covered by sales executives that had just a very few accounts so that they can focus on a high-touch sales-led approach, often in conjunction with our GSI partners. And these partners are in every 1 of the largest global accounts. Our middle enterprise segment covers 5,000 to 40,000 employee accounts. And these are jointly led by Zscaler and a partner, either a GSI or a national VAR. We see this part of our business as an area where we can accelerate new logos, and so we've invested in creating more hunter territories to drive this growth. And finally, our commercial and SMB space, these are businesses and organizations under 5,000 employees. This is increasingly shifting towards a partner-led motion with simplified bundles. This segment is a high-velocity new logo generating machine that is bringing on new customers who will 1 day be our next enterprise accounts. But regardless of segment, building trust, building trusted relationships and having executive alignment is an important part of our go-to-market approach. This allows us to be a consultative partner as part of a customer-centric strategy. Put simply, we focus on understanding the problems they are trying to solve to help them transform their security architecture and address every security challenge. Now, I want to double-click on our vertical strategy because this is a very important part of our growth plan. We have established dedicated teams for the last few years, focused on certain verticals, such as U.S. public sector and U.S. health care provider. This year, we launched a U.S. financial services vertical as well. All these are critical verticals that require additional coverage and expertise. For example, in our federal business, our FedRAMP High and IL-5 accreditations, an ability to deliver solutions for highly regulated environments, are a competitive advantage for us. And we see opportunities to expand our vertical strategy in the future. As AI in the increasingly regulatory environment create tailwinds in the space, we see a path to future growth and opportunities in areas like international public sector and sovereign cloud. Sovereign cloud is a big focus for us. And we are seeing a lot of demand, both in public sectors as well as regulated industries around the world. Okay. Now that I've covered how we structure our go-to-market organization, I'm going to focus the rest of my presentation on the 4 key levers driving our growth. First, platform expansion. The AI security tailwinds are undeniable and tremendous, and we are seeing significant momentum from our new product offerings. Second, we are accelerating our new logo engine and the team is focused on landing new customers with these expanded offerings. Third and crucially, we are scaling through partner leverage, working closer than ever with our ecosystem to reach more customers wherever they are. And finally, everything we do is underpinned by customer obsession. Ensuring relentless focus on our customer success translates into tangible results with platform expansion and new products being purchased. I'm now going to touch on a little more detail on each of those areas. First, starting with platform expansion. As you've heard, Zscaler is truly a cybersecurity platform. And here, you can see a snapshot of this platform. You've seen it before many times today already. Our 4 product categories are built around a common architecture, as you've heard from others. What we haven't shared is, there are more than 30-plus distinct products underpinning each of these categories. And that number continues to grow as Adam and Dhawal and their product innovation teams build more products. This is a key differentiator for us versus other companies that claim to be platforms, but are really just a collection of point products that have been acquired. We see substantial demand as our customers continue to invest with us and consolidate point solutions in exchange for a platform they can trust and 1 where they can realize significant long-term savings Today, the majority of our ARR comes from customers who have at least 1 product across 3 or more product categories, demonstrating the breadth of our platform and the value proposition of what we offer. These customers not only have significantly higher ARR, they also have a higher retention rate. And critically, there is still significant upside potential for Zscaler inside of our existing customer base. Today, on average, customers have purchased only 9 out of the more than 30-plus products we offer. So there's a lot of opportunity to grow. And when you look at the white space across our installed base, the opportunity is significant. As you can see, we conservatively estimate our current TAM, not including our future TAM, but our current TAM of $19 billion. When you consider our FY '26 ending ARR of $3.8 billion, we have a significant $15 billion worth of white space available to capture. That represents a 5x expansion potential just by cross-selling our existing products to customers who already know us and trust us. Notably, this expansion potential is spread across majors, enterprise and commercial segments, with roughly 3/4 of the expansion opportunity among majors and enterprise. But regardless of the customer, the story is the same. Once a customer experiences the power of the Zscaler platform, they want to consume more of it. And as our customers navigate a rapidly evolving threat landscape, we are perfectly positioned to grow alongside them. Let me give you an example of that growth. This is through the lens of a global investment firm. This is a customer that we landed with a $2 million ARR that was Zero Trust SASE for users, and that was in FY '19. In FY '22, they expanded into data security, and then they added Sec Ops in FY '24. Then recently, last year, they added Zero Trust Sassy for cloud and security for AI. Growing this ARR to more than $15 million or 7x the initial land. This growth is fueled by deep executive alignment on strategic transformation, which drives the customers continuous investment as our platform expands. But the most important part of this chart is the trajectory to the far right. And even at $15 million, we still have a substantial upsell opportunity ahead of us as this customer continues to consolidate on our platform. Next, our new logo engine. We have a significant untapped opportunity remaining in our target market of organizations with more than 1,500 employees. Our current customer base represents just 4,600 of these estimated 20,000-plus enterprises globally. There is over 75% of the market that we have not yet reached, and as we head into FY '27, we have made some changes to ensure the field is best positioned to capture this significant opportunity. For example, as we approach territory design for FY '27, we put a strong emphasis on new logos. We significantly increased the number of hunter territories globally, and we have also focused and incentivized our field for new logos and driving that growth. And finally, we worked very closely with our partners to provide further leverage in opening doors for new customers that have been shut for us. And I'll touch on that a little bit in a moment. You've heard it from Adam, you've heard it from Dhawal, you heard it from Jay, our platform has expanded. We now have a multitude of solutions to land with new customers with entry points across each product category. Here are just a few examples of use cases where we can help prospective customers address with our growing platform. I won't go through all of them, but I do want to call out security for AI as it is a huge area of interest in every conversation that we are having. You heard that from our customer panel today. I'll also call out Zero Trust Branch, we're winning very large new logo 7-figure deals with ZTB. And they do not have users. Great landing spot. And let me give you an example of just one customer. We recently had a 7-figure win with a Fortune 500 life sciences leader. This deal is a perfect illustration of the power of the Zscaler platform and our security for AI innovations. It was led by a newly appointed CISO who is a repeat Zscaler customer. You heard that from Jay, this is a very common theme. And we won this customer thanks to our superior security for AI capabilities. Our platform gave this customer the specific controls they needed to safely adopt AI without compromising sensitive data, allowing us to displace a legacy firewall-based SASE platform. Next, I'm going to talk about partners. So -- all right. Okay. I want to talk about partners. Sorry, technical issue. I got a pointer problem. Our partner ecosystem is the engine that allows us to scale across the entire market. At the top of the pyramid, in our majors and enterprise segments, we are seeing incredible progress with GSIs with greater than 75% year-on-year TCV growth in FY '26. These partners are leading multiyear board-level digital transformation initiatives where security for AI has become a central theme. Strategic VARs are also -- remain an important partner for us. We work with these partners across all of our segments, especially in our enterprise business. These organizations have local expertise, long-standing relationships, and we've recently launched a new incentive program to further penetrate this market. Now moving down market into commercial and SMB. Our strategy shifts towards scale and velocity. Here, we are intentionally leveraging distribution and managed service partners for scale and speed. One example that we announced is our recently expanded partnership with Carahsoft targeting commercial and SMB accounts. This shift towards a partner-led motion is designed to drive high-volume new logo acquisition. And you will continue to see this strategy deployed in other geographies of the world in the future. Finally, our tech alliances with hyperscalers and frontier labs. They act as a force multiplier across all segments. They ensure that Zscaler remains at the forefront of AI innovation regardless of company size. And in FY '26, we captured a record $1.5 billion in TCV through marketplaces and saw over 125% year-on-year growth in TCV through our tech alliances. And our final growth lever, this is so important for us. This is a huge focus for our sales teams and for the company as a whole. And that is customer obsession. So many of you may recognize this infinity loop from our 2024 transition towards an account-centric selling model. It represents a continuous cycle where presales alignment and post-sale success are inseparable. On the buy side, we focus on deepening CXO engagement and differentiating the Zscaler brand to ensure we are not just a line item, but a strategic partner. Our teams are highly engaged, and this is a consistent point of feedback we hear from customers when they choose to partner with us. And on the owned side, we introduced Z-Flex 6 quarters ago, and the results have been incredible. Ultimately, Z-Flex allows our customers to do larger and longer-term deals with us to test newer offerings and to swap products at their own pace. This has led to more strategic engagements with customers and prospects. So it really is a win-win all around. We've seen tremendous momentum with Z-Flex bookings increasing over 60% quarter-over-quarter in Q4. And Kevin will go on to these results in more detail when he speaks. In addition, by leveraging partners for expert deployment, we ensure that first year adoption is seamless and scales as our customer base expands. And the big takeaway here is this. We have evolved the way we go to market, to ensure customer success is at the center of everything we do. Let me give you an example of how focusing on customer success pays off. I want to highlight a public sector customer where early adoption led to rapid scaling, thanks to our focus on customer success. We began the journey with this customer in FY '23 with a small land with our foundational Zero Trust for SASE for users and data security solutions. Growing the ARR to $1 million in FY '24 as we expanded in both of those categories. Importantly, because we established Zscaler as the architectural standard early on, we were able to rapidly repeat this success across more than 100 agencies in this country. Most importantly, we layered on Agentic SecOps, providing these agencies with a single pane of glass for risk-based prioritization within their specific business context. This drove our footprint to $16 million, a 170x increase from where we landed initially. And we have even more upsell opportunities in our sites. So on the next slide, our go-to-market growth levers. They are all underpinned by a relentless focus on go-to-market productivity. One of the most encouraging indicators of our go-to-market health is the consistent double-digit growth in sales productivity we have been able to deliver over the last 2 years. I have been deeply involved in the team that is shaping and driving this transformation. And as you can see, the productivity is trending. And we aren't just growing our headcount, we are making our AEs more effective. This is driven by 4 specific strategic levers. One, I mentioned customer-centric selling. The scale of our platform. I talked about partners being force multipliers and the intentional work we've done with territory design and optimization. And as we enter FY '27, continuing this upward trajectory is a top priority of mine. By ensuring our territories are healthy and our partners are activated, we are building highly efficient sales machines that can sustain significant growth while maintaining sales productivity. And I'm going to very briefly touch on how we're using AI internally in our go-to-market strategy. We think about how we use AI initially as being -- it should be fundamentally reimagined. We aren't just talking about productivity, we are embedding AI across the entire life cycle to drive velocity and quality. In pipeline, we're moving from manual prospecting to agentic outreach, targeting the white space recommendations at the right moment when the customer is ready to engage. And the results are notable. We've seen a 2x higher reply rate to these e-mails, demonstrating our ability to reach the customers at the right time. And in sales productivity, we launched an AI copilot that has become a force multiplier, handling everything from account intelligence and building complex business value cases, and we are now extending it to agentic quoting. This allows our reps to spend less time on administration and more time on high-value strategic selling. And in customer satisfaction, our AI customer support agent has driven a 40% reduction in ticket volume, freeing up our human resources to focus on the most complex customer challenges. Taken together, these are the primary reasons our go-to-market effectiveness continues to outpace the market. And finally, key takeaways that I hope you heard. I cannot be more excited about stepping into the CR role at this moment, at this time with this trajectory. Zscaler was built to capitalize on this once-in-a-lifetime AI era. Our Zero Trust architecture, it is highly, highly differentiated. And our platform continues to expand in ways that are clearly resonating in the market. We have taken action to enhance our ability to penetrate the new logo opportunity we have, and we're leveraging our partner market as a force multiplier. And we are doubling down on all the reasons customers are obsessed with Zscaler in the first place. Our team, we are laser-focused on executing, and we are laser-focused on achieving our financial objectives. And Kevin, Kevin is going to walk you through these financial objectives. Thank you.
Kevin Rubin
executiveAll right. Hello, everybody. Thank you for being here, and thank you for sticking with us. It's been a lot. Okay. I'd like to start by briefly recapping what you've heard today. We've talked about the structural steps we've taken to increase our TAM, strengthen our product portfolio as we enter the AI era and enhance our go-to-market engine. These are each important pieces of the growth opportunity ahead of us, and I'm going to walk you through how all of this fits together from a financial point of view. I'm going to focus on 3 areas. First, our multiple growth engines that we believe position us to deliver continued compounding ARR growth. Second, the success we are having in driving broader adoption of our platform, which is supporting new logo growth and upsell opportunities. I'll provide some data that helps make that clear. And finally, our updated long-term financial framework. Let's start with a quick look at -- look back at our track record. We're entering our next phase with a proven track record of growth at scale. In fiscal '26, revenue grew by 25% year-over-year, while ARR also grew by 25%. Excluding Red Canary, revenue and ARR both grew 20%, and we delivered 14% net new ARR growth for the year. That momentum gives us a strong foundation to capitalize on the significant growth opportunities ahead. As we've scaled the top line, we've also continued to improve the profitability of the business. In fiscal '26, non-GAAP operating margin reached a record approximately 23%. Free cash flow margin was also 23%, and we reached a Rule of 49 performance. Since fiscal '23, we've expanded operating margin by approximately 8 points. So alongside strong growth, we are driving operating leverage and building a business with a meaningful profitability profile. Okay. As you heard from Jay earlier this morning, we are operating in a large $220 billion addressable market, which you can see here mapped to our platform. We use this Investor Day as an opportunity to refresh our market forecast, and we are now leveraging industry forecasts from third-party market research firms as the inputs to our TAM. And in addition, you heard from Adam and Dhawal today, we continue to innovate and introduce new products which has significantly expanded the markets we play in today. We strongly believe our platform is perfectly positioned to capture a growing share of this market. Others have presented a similar view of our platform this morning, but I want to drill down on how we organize the platform from a financial point of view. Fundamentally, our platform consists of 4 product categories with different levels of maturity and growth profiles. Zero Trust SASE Everywhere is the foundation. It accounts for approximately $3 billion of total ARR and has grown at a 20% CAGR over the past 3 years. Since this is the first time we're breaking out the platform in this way, I also wanted to double-click on two distinct offerings within this category. Zero Trust SASE for users, which include ZIA, ZPA, ZDX and Zero Trust Browser, is our largest business. Zero Trust Branch and Cloud are much newer offerings on a relative basis and growing considerably faster at 75% ARR CAGR over the past 3 years. Combined, these have now reached $250 million of ARR, an encouraging milestone, and one that reinforces our confidence in the long-term growth potential of the solution. The second product category is data security, which has grown at a more than 30% CAGR over the last 3 years. Under this new view of the platform, we have shifted Zero Trust Browser into Zero Trust SASE for users to better reflect how we go to market with this offering, and as a result, have updated our data security ARR accordingly. The two newer product categories in our portfolio are Security for AI and Agentic SecOps. Within Security for AI, we ended the year with approximately $70 million in ARR, an incredibly strong momentum as evidenced by the growth we've been seeing. We are very pleased with our results to date, adding to our optimism about the future. Finally, looking at Agentic SecOps, we just launched our new integrated offering, so the historical performance here is less important than where we're headed. Across this portfolio, we see three growth engines that will continue to propel our growth going forward. Zero Trust SASE for Branch and Cloud, Data Security and Security for AI. Combined, these 3 growth engines delivered 60% ARR growth year-over-year in fiscal '26. You can expect that we will continue to update you on the performance of these growth engines as a group quarterly and on an individual basis annually going forward. I want to spend a few minutes double-clicking on each part of our platform, starting first with our Zero Trust SASE Everywhere portfolio. We continue to see healthy growth from our Zero Trust SASE for users solution despite running into the law of large numbers. While today, these solutions form the foundation of our portfolio, our business continues to shift more towards nonuser products, and our goal is ultimately for our growth to not be tied to seats. We are making great strides in this regard. As we shared at earnings, 30% of our new and upsell ACV in fiscal '26 was from non-seat-based [ ordered ] products. Branch and Cloud are key contributors to this, and both have been strong contributors to our growth with Zero Trust Branch and Cloud ARR growth exceeding 60% for each and every quarter over the last 2 years. Even more encouragingly, we still see significant white space opportunities for these solutions, with just 10% penetration in the Global 2000. Looking holistically at our Zero Trust SASE solution. Our customers who are Zero Trust SASE Everywhere enterprises, or those who have purchased ZIA, ZPA, Branch and Cloud, are also our most valuable customers. These customers delivered over 5x the ARR of customers who did not have Branch or Cloud, and they have a 121% NRR or 6 points higher than our overall NRR. Next, our data security portfolio has become an increasingly important contributor as enterprises confront a new wave of data exfiltration risks. Data Security ARR accelerated to 34% in fiscal '26, with bookings increasing more than 40% year-over-year. As you heard from Dhawal, our data security solution is the most comprehensive in the market with products that span both data in motion and data at rest. We have seen over 40% ARR growth from customers who deploy multiple data security products. And today, less than 20% of Zscaler customers have multiple products, representing a meaningful upsell opportunity as we look ahead. Finally, our new Security for AI offering is becoming an increasingly meaningful contributor to our performance. In the fourth quarter of fiscal '26, Security for AI bookings increased more than 50% sequentially on top of a strong Q3, and our pipeline increased more than 75% sequentially. This is exciting progress, and we are still in early days, with over 65% of our Security for AI ACV in Q4 coming from products that have only been in market less than 2 quarters. This gives us significant confidence that these products will become increasingly meaningful contributors as adoption grows. And as more products within the portfolio enter general availability later in fiscal '27, including our Zero Trust Exchange for agents, we expect even further momentum. As we've expanded our product portfolio, we've naturally created more ways for customers to land with Zscaler beyond foundational Zero Trust SASE for user offerings. We are seeing tremendous interest in our newer products, and they are becoming a meaningful part of our new logo ARR. In fact, roughly 1/3 of our new logo ARR today is being driven by these offerings. This is up 3x versus 2023, demonstrating that Zscaler's platform value proposition is increasingly resonating with customers. Once customers are on our platform, we see consistently strong retention and healthy expansion. Net revenue retention has remained consistent around 115%, while gross revenue retention remains in the mid-90s. This reflects both the mission-critical nature of our solutions and expansion opportunities we are unlocking with our customers. The power of this expansion story is evident in our largest customers. As customers expand their investment with Zscaler, we see growth accelerate. In fact, our [ $10 million plus ARR ] customers have grown ARR 9 points faster than our $1 million to $10 million ARR customers over the last 3 years. And among those, our top 10 customers are growing even faster still. That is powerful validation of the platform strategy and the results that we are providing to our customers. As you heard from Ross earlier today, one of the tools helping us accelerate platform adoption and drive customer expansion is Z-Flex. By giving customers the flexibility to consume capabilities across the platform, Z-Flex lowers friction in the buying process and encourages broader adoption from day one. And these results have been compelling, with 30% ARR uplift in fiscal '26 from customers with Z-Flex. And as I mentioned on our Q4 earnings call, Z-Flex bookings exceeded $1.7 billion in fiscal '26, which equates to nearly $500 million in ARR. This is how we will be sharing Z-Flex progress going forward. We've included both Z-Flex TCV and ARR in this slide, so you have the history. Importantly, even with the excess of expanding within our customer base, we still see significant opportunity ahead. Today, our approximate $3.8 billion of ARR represents only a fraction of the $19 billion plus of addressable spend within our existing customers. That leaves over $15 billion of white space opportunity sitting inside our installed base. This includes our Zero Trust for SASE user solution, where we see approximately $6 billion of expansion opportunity. As you heard from Adam, this includes the meaningful expansion opportunity in our installed base from ZPA with 30% of ZIA users today who have not yet adopted ZPA. But more broadly, we also see significant expansion opportunities with our newer solutions. The fact that over 40% of our installed base has not yet purchased any of our solutions beyond Zero Trust SASE for user underscores the magnitude of this runway. Bringing all this together, I wanted to walk through a customer journey that reflects what we are increasingly seeing across our customer base. In this example, our relationship with this Fortune 500 technology company began with a relatively modest deployment focused on Zero Trust SASE for users and data security. Over time, this customer expanded into additional use cases, including Branch, Cloud and SecOps. We ultimately saw this customer commit to a Z-Flex deal in fiscal '25, enabling them to adopt the full platform and accelerate deployment across the organization. Then in fiscal '26, following the launch of our Security for AI portfolio, they expanded their deployment with us to include these new solutions, and as a result, further expanded their investment with Zscaler. Over 6 years, this customer grew their ARR roughly 30x, with ARR increasing at a CAGR of approximately 74% to $20 million-plus ARR by the end of fiscal '26. While, of course, every customer journey is different. This demonstrates the growth drivers we see as customers move from an initial deployment to a broader platform adoption. As we look ahead, it is the power of our customer growth flywheel and the meaningful runway for new logo growth that Ross shared that reinforces our confidence in the opportunities ahead. We are reaffirming our fiscal '27 guidance, which you can see here on the slide. Beyond fiscal '27, where do we see the business going? You've heard us speak about our aspiration to reach $10 billion in ARR. As we execute on this trajectory, we see a clear path to grow ARR organically to over $8 billion in ARR by fiscal '31, more than doubling our current ARR within the next 5 years. How will we get there? We expect continued strong growth from these -- from our 3 growth engines: Security for AI, Data Security and Zero Trust Branch and Cloud. At the same time, our Zero Trust architecture is more important than ever, and we expect our foundational Zero Trust SASE for Users offering to remain strong, delivering sustained double-digit growth. And as you heard today, we see significant opportunity driven by the adoption of Agentic AI. This is still a new and emerging area, and so we're not asking you to underwrite this upside today. But we believe it has the potential to be a meaningful accelerant across every part of our business. Let me talk you through this scenario. While this is not in guidance, it is intended to show the potential of the business, assuming a more rapid adoption of Agentic AI. Our Zero Trust architecture uniquely protects against the threats created by Agentic AI, which we believe will accelerate demand for our Zero Trust SASE Everywhere solution across users, branches and workloads. With the increasing prevalence of AI, Data Security and Security for AI become even more critical as enterprises look to safely deploy Agentic AI at scale. And with AI-driven threats operating at machine speed, we believe our Agentic SecOps offering is poised to disrupt the SecOps market, opening a meaningful adjacent growth opportunity. We believe these tailwinds could be significant over the next 2 years and could contribute nearly $2 billion of upside to our ARR. This would put us on a path to reaching $10 billion in ARR by fiscal '31, with each part of our business growing at a faster rate than in our base case. Let's now turn to our financial framework for -- this assumes over $8 billion in ARR by fiscal '31. I'll start with gross margins. As you can see, our gross margins have consistently been around 80%, and we expect this to continue. We have been driving productivity in our go-to-market organization, and we expect this to continue as well, with sales and marketing as a percentage of revenue trending down. For R&D, we expect modest leverage from our more mature products while continuing to invest in new innovations. And in G&A, we see this ticking down modestly from AI adoption and automation. All of this leads to continued operating margin expansion by fiscal '31. Regarding free cash flow, we expect margins to be above operating margin. However, there are some timing considerations given the current memory price backdrop. Specifically, we are expecting CapEx as a percentage of revenue to remain elevated until fiscal '28, then normalize back towards high single digits as manufacturing capacity comes online and memory and component prices decline, which aligns with the forecast from Gartner and IDC. Finally, I want to touch a little bit on stock-based compensation, as this is a key factor in driving GAAP profitability. Over the long term, we are focused on bringing this in line with our peer group average. This excludes any future M&A, which has historically contributed 1 to 2 points. With this in mind, we are always evaluating the best use of capital to maximize shareholder value, and our capital allocation framework is clear. Our first priority is reinvesting in the business to drive continued innovation, resiliency and product expansion to drive sustained long-term growth. Second, we deploy capital into M&A, focusing primarily on technology and talent tuck-ins to strengthen the platform. And third, we are committed to maintaining a strong balance sheet to preserve financial and operational flexibility. To wrap up, I'd like to leave you with a few points. First, we are operating in a very large and expanding market, and our innovation continues to broaden the opportunity in front of us. Second, we have a demonstrated ability to translate that opportunity into profitable growth at scale. And third, with multiple growth vectors, significant white space in our target market and the tailwinds from Agentic AI across the platform, we are positioned to drive durable and compounding ARR growth for years to come with both new and existing customers. Taken together, we have a strong foundation clear visibility into the path ahead and confidence in our ability to create long-term shareholder value. Thank you. Okay. All right. Up next, we have our Q&A session. So I'd like to bring all of our speakers up to the stage for this section.
Kimberly Watkins
executiveOkay. I see the hands up. So when we call on you, just remember to state your name and your company name for the webcast. Really, really appreciate that. Brad, I think you had your hand up first, so we'll go with you.
Brad Zelnick
analystThat's one of my skills. Brad Zelnick, Deutsche Bank. Thank you for an amazing day, really great, compelling presentation. I want to direct my question at Ross and maybe for Jay to chime in as well. It seems there's been a lot of change in the sales organization. Great to see you stepping into the role as well. I guess as we think about the underlying drivers of turnover that you've seen, what it is that there is -- there might be to know, why we shouldn't be concerned by any ongoing disruption as a result of these changes? And then I'd also love to hear from you, what's new? Like from going from one leader to the next, usually, there's your fingerprints that you're going to want to put on things. As I look at the presentation you gave today, it sounds like with the 75% of the market that you haven't reached yet, it would seem like there's a real opportunity to go further down market. And related to that, just wondering, the resources put behind that versus maybe not then allocating enough towards this amazing $2 billion AI opportunity that we see and how you balance that? So I know a few different questions, but all related.
Ross Tackett
executiveFour part question, I think. Let me see if I can remember all those. So I'll start with the latter part. So new logos, as you heard, are a real emphasis for us. And with the expanding platform and things that we've done in our go-to-market machine around focus and incentivizing our teams, I feel like we'll accelerate there. As we look at the down market opportunity, that is not a discrete focus for us. It is an opportunity, and that's why we're leveraging relationships like Carahsoft that I mentioned. We need to drive velocity and scale, and that's what we're focused on there. We will remain very focused on enterprise and majors. We do have an opportunity in that space. We're not ignoring it, but that's where we're really going to leverage our partners. You asked what I would do differently. Yes, you led the witness a little bit in that new logos are very important for us. We're driving verticals. I think I talked about vertical strategy. We have a lot of opportunity in public sector, international, as well as sovereign cloud. So we are really leaning in there. And then obviously, the platform opportunity. I have a long history of selling platforms. I know how to do it. I know how to lead those teams. And so we're very focused on that. And then I think coming around to your first question -- and Jay, I'd encourage you to chime in as well. I mean, yes, there have been some changes, and they've all kind of been unrelated to each other, frankly. So there's not any individual macro thing. We've got a strong leadership bench. We have our leadership team in place. I'm very happy. And as I've mentioned multiple times, we are really focused just on execution.
Jagtar Chaudhry
executiveIf I may add, you saw us reiterating the guidance. That tells us the confidence we have. You also saw us give long-term guidance as well that could tell you that we are very confident on the opportunity. The overall platform need for cyber, our role as being the linchpin is fundamental. The sales process and strategy we put in place is doing well. We just need to keep on accelerating on it. And I think we have a strong leadership team, and there will be some changes from time to time. Very confident.
Kimberly Watkins
executiveOkay. We're going to go to Fatima, and then we'll head over to Joe. So Fatima and Joe in the first row. Can we get a mic over to Fatima in the middle? Can you keep your hand up for a SEC? Webcast. Thank you.
Fatima Boolani
analystFatima Boolani from Citi. Thank you so much for an insightful set of comments and presentations. Dhawal or Adam, for you. Dhawal, you mentioned something that was really interesting to me in your session just around this intersectionality of security for AI and data security. Now those two seem to be very interrelated because you can't have secure AI usage without having a handle on your data assets. And the data attack surface or the data risk surface, as you pointed out, is absolutely metastasizing. So why is there still a distinction from a product standpoint if presumably, data security is going to be a conduit for security for AI and vice versa? And then as a related question to Ross, why not unleash Z-Flex to the entire base? What are some of the limiting reagents? Because if you are going full force from a platform perspective, you talked about only 9 of the 30 individualized SKUs are being uptaken. Why not just tear up kind of the traditional motion? You've seen the success with Zscaler -- I'm sorry, Z-Flex, and go all hands on deck.
Dhawal Sharma
executiveSo probably I'll start with the first part. When we look at the AI security broadly, right, or security for AI, data security is a very strong tailwind, as I was explaining the numbers. But security for AI is broader than that. A lot of new cyber attacks that we are seeing, think about how users are being tricked to -- get fished these days is happening through prompts, right? Prompt injection, jail breaking is happening through that as well. So there is definitely more to it, but -- and as you saw, securing AI also needs to secure applications and infrastructure that you're using from what goes into your models. And data security then becomes a key pillar on that. You're absolutely right that AI agents are not just consuming data, our models are not just consuming data. They're [ trans ] data. They also leave [ remedies ] of this data in multiple places. And this is why we've been classifying data, and we have a strong DLP business that has grown significantly. But the challenges that come with data security in the AI world are also different, and this was one of our core thesis for acquiring Symmetry Systems that we can discover data everywhere. We can discover AI everywhere. What is really hard in this world is understanding the relationship between data and how that data goes into AI and how identities are [ playing pay ] with very excessive permissions enrolled. And that problem is getting compounded with stat that Jay showed, there are 75 agents for every single user. So the short answer, in my opinion, is like, yes, data security is a big part of it, but AI security in itself is much broader. That's why we are keeping it that way, but we are bringing it together. Adam?
Adam Geller
executiveYes, maybe just one quick add on that. The -- this is why data security is part of the platform. And it's a consistent capability that crosses everything. I didn't spend much time talking about it, but it's foundational in everything we're doing in Zero Trust SASE as well. What we've been recognizing is where does that need to evolve. And primarily, AI is just solved as a major accelerator of -- if we knew this was important before our customer knew, now it's really, really important. And then you're seeing these specific pieces around data security is always about find the data, classify it and then enforce policy. What we've learned in AI, there are new elements of what that policy looks like. And it's broadly applicable not just for AI, but AI is driving that, and that's why we're doing it at a platform level so we can use it across every one of our product areas.
Unknown Executive
executiveRoss?
Ross Tackett
executiveZ-Flex. And Kevin chime in if you have any thoughts. So that is a growth enabler for us. We don't have any limiters on -- I mean, there's some obvious baseline, you need to spend x minimum. But yes, Z-Flex is kind of a core motion for us.
Unknown Executive
executiveAnd we did give an example where a customer actually in the case study is able to take the entire AI security portfolio through Z-Flex as well.
Jagtar Chaudhry
executiveWith so many questions coming up. We're going to keep our answers short so we can take more and more questions.
Kimberly Watkins
executiveThank you, Jay. He's taking my role. Now we're with Joe.
Joseph Gallo
analystOkay. So I have a question for -- Joe Gallo, Jefferies. Thanks for this. A question for Adam, primarily on SecOps. So I know it's early, but who are you competing with? Like I assume in your existing customers, you are the network security platform. So I assume your competing with the endpoint centric platform. So I'm just curious, you're right to win there because those vendors also have a lot of data.
Adam Geller
executiveThey certainly do. And I think the data gravity is the main point. Every customer that we work with when they're figuring out SecOps, they're going to orient around some center of gravity. And in some cases, in many cases, that's going to be us, it can also be other players that they have. And so the solutions, anyone who has a SecOps solution, if they're not -- they don't have that data gravity, they're a new Agentic SecOps startup, I don't think they have that easier right to win compared to a Zscaler or a larger platform play. SecOps has become a more and more of a platform play. That's why I think we have that right and that shot to be competing in that space with the telemetry of the data we have and that agent-first approach that we're taking. I think Kim likes to bring it up, I have this commentary and say, we get sometimes a second mover advantage. We weren't first to this space. We recognize that, but the benefit is we didn't spend all of our time building a solution around log collection and storage. We build our time -- we built it all around an agent-first approach.
Jagtar Chaudhry
executiveBut Adam, we are fast mover when it comes to solution built for agents. Others build solutions for humans and try to add agent into it. That's point one. The second short answer would be data. We got full in-line data. We got endpoint data. We've got cloud workload data. We also got branch devices data. We have better telemetry than anybody out there.
Kimberly Watkins
executiveAnd we bring in third parties.
Unknown Executive
executiveYes.
Kimberly Watkins
executiveWe'll go Ittai, and we'll do you too, Adam. Can we get a mic right here in the front? Thank you.
Ittai Kidron
analystThank you very much. Ittai Kidron from Oppenheimer. Great presentation. Really appreciate the disclosure. A couple of questions from me for you, Adam, first, on the technology side. You talked about the importance of context. I guess, why not on the identity side of the equation? It sounds like you are drawing from identity in order to create context some of your -- your biggest competitor has decided to own that layer. We already see some data security companies moving into the identity side to create that context more likely, more closely linked. I guess the question is, why not own that category instead of partner over there and potentially end up with no partners if they get acquired? So that's question one. And for you, Kevin, on the financial side of the equation, I appreciate the long-term targets on fiscal '31. I guess if I think about just that $8 billion target, just kind of doing back of the envelope, it sounds like new ARR needs to be growing around the 10% plus/minus on a consistent basis for you to reach that target. That's already well ahead of your target right now for fiscal '27. So are you already raising the numbers? Or should we look for a little bit -- are you going to grow into this fiscal '31 number? Or how should -- how do we think about that?
Kevin Rubin
executiveYes. I guess I'll go first. So the 17% CAGR is in line with the midpoint of the guidance for this year. So that's -- that would be my direction there. As we think about the opportunity to $8 billion and potentially $10 billion, let's remember, we have a huge opportunity in a giant market. We've talked about new logos. We've talked about continued extension of the platform. We've talked about moving even beyond into adjacent SecOps. So I think there's a lot of opportunity and a lot of reason to be really excited about the opportunity, but that's how I would think about the longer-term model.
Jagtar Chaudhry
executiveIf I may add, I'm only focused on $10 billion number.
Kimberly Watkins
executiveAdam, do you want to finish off the question?
Adam Geller
executiveWe try to. So on the -- from the identity piece, needing -- leveraging identity as context is part and parcel to everything we've done in Zero Trust. It requires that. It does not require you necessarily owning it. Customers use identity for lots of different things, and they have identity players and components that bridge well beyond security. So if you want to get into that space, you have to sign up to do all of those pieces. So we've been very successful in leveraging it as key context. The other piece is identity players are not typically in line. They're in line for 1 piece of it. They're not an in-line processing engine, which is what we are. That's where we are focused. We're focused on leveraging that context. It's a relationship for sure. It's getting a lot of attention. But I don't see the burning need to say we have to own it because I think that brings a lot of other distraction. And you saw what we have to go after. We have a lot in front of us, and I think focus is going to be very important as well.
Jagtar Chaudhry
executiveIf I may add. In the agentic world, identity, basic identity, who are you is coming from the party that's creating agents. That's the starting point. Identity doesn't give any more context than who you who are. The rest of the context come from sitting in line. We have lots of context today for user identity, as Dhawal talked about, without having the core identity. Would I go and spent $25 billion and hoping that this business will become agentic identity? Not really. Will I work with Microsoft and Azure and AWS and Google on the world and take identity from them, add context to it, add intent to it? That's a winning formula.
Kimberly Watkins
executiveAdam?
Adam Borg
analystAwesome. Adam Borg with Stifel. Thanks so much for the time, and really appreciate the conversation today. Maybe for Ross. So talking about the new logo opportunity, especially down market. Talk about the confidence you have there, especially given investor perception, it's a lot more competitive down market. So like what changes will need to be made, if any, on the pricing and packaging side to be more competitive there?
Ross Tackett
executiveSure. So at a high level and to keep this brief, a couple of things. A, we are looking at more simple bundles like T-shirt sizes that we are then leveraging our partner ecosystem. I talked about Carahsoft, and we are looking at doing similar relationships in other geographies. And so having those simplified bundles through a partner machine that can leverage and touch all those organizations that we just don't have the human capacity to do is why I feel confident that we can grow the new logos in our commercial and SMB space.
Jagtar Chaudhry
executiveI mean, an interesting challenge we have is the upsell opportunity is so big, the new logo opportunity is so big. We are trying to do a balancing act rather than saying a versus b.
Unknown Executive
executiveAnd the only thing I would add to it is, remember, we have about 4,600 of what we've determined to be 20,000 of the largest customers. So there is a 75% white space, if you will, relative to new logos. So there's a large opportunity for us to continue to replicate the excess that we've had with existing customers into the 75% that we've yet to serve.
Kimberly Watkins
executiveOkay. Let's go back to John in the corner, and then Saket up in the front.
John DiFucci
analystGood eyes, Kim, way back here. It's John DiFucci from Guggenheim. I guess, I want to go back to Fatima's question because AI does look like a discrete opportunity at this point out there. And that's how all cyber companies are addressing it. But if AI becomes part of everything, it is much broader, as Dhawal mentioned earlier, doesn't it just become part of everything you do and everything everybody does? And if that's the case, that's -- that $2 billion number you put out there, to me, I just wonder how we should be thinking about that and frankly, help the risk in it? And then just a quick follow-up for Kevin. Why in '26 did the delta between free cash flow and operating cash flow narrow so much in '26. And I don't think it was just that CapEx.
Jagtar Chaudhry
executiveYou want to start?
Kevin Rubin
executiveYes, I'm happy to go with the last one. John, we did see a pretty significant tick up in CapEx as a result of pricing and supply chain-related items. The other deviations is really just timing.
Jagtar Chaudhry
executiveSo maybe I can start on the AI and data side of it. We're going to give the answer short this time. Yes, AI and data are interrelated. You saw the presentation for the first time, I've seen any presentation with AI and data is sitting together. Discovery of AI, data, risk of AI and data, who accesses what, they're all related in our solution. So we are selling it as a combined solution, but also giving options to customers to buy individual solutions. There are separate buying centers for data security today. AI is separate, but they're coming together. As time goes on, you're going to see more and more stuff being sold together.
Unknown Analyst
analystI'm sorry, it's more than just data. If you think of endpoint, you think of identity, you think of -- I mean, they're all related to data, but it's more than just data. It's process. It's things happening, everything happening out there, right? And it's -- I'm just concerned about the $2 billion out there because I have -- I think you guys are doing a great job, but it seems like some risk to put that out there. That's all.
Jagtar Chaudhry
executiveLots is happening, but we need to figure out. Our job is to make sure right entity connects right entities, so saying don't get compromised and data doesn't lose the count. So we're not trying to figure and fix every workflow in the company. Right security, the right access for that identity plays a role, inspection plays a role. And AI is a main source, and data is one of the key pieces to look at. So we can take it more off-line.
Kimberly Watkins
executiveThank you, John. Saket, right up here in front.
Saket Kalia
analystSaket Kalia at Barclays. Great session as always. So Jay, this question is for you, right? The message on the mix shift, right, as part of this long-term plan is very clear, right? There's about 25% of ARR, give or take, right, that will become a bigger mix by 2031. Right? But what about the user part, right, which is right now is the vast majority. I think let's just assume the $8 billion right now, right, just for a base case. That will still be the majority, I think, right, by 2031, you correct me if I'm wrong. I just want to ask the question. Can the user part of the business grow faster than double digits? And a question that hasn't been asked yet today that I think is on all of our minds is, what about competition? Can we just do a level set on competition in the user market?
Jagtar Chaudhry
executiveSo if you think about competition, first of all, we pioneered securing users of Zero Trust. Largely, competition is now trying to secure users without Zero Trust. When you guys talk about all the final vendors as a competition, none of them are Zero Trust even for users. All this SASE and SSE is still firewalls and VPNs running in the cloud. That's a starting point. And they cannot afford to change to a Zero Trust architecture because of cannibalization that's going to cause because all the firewalls go away. Our customers are telling us that they need to take care of that. So number one. The next part, we are not sitting end users. Customers are asking Zero Trust Everywhere. I'm not going and saying buy my user stock. I'm going saying you need Zero Trust Everywhere. Users, branches, devices, cloud workloads, and next becomes agents. You need to look at the solution and customers buying us, holistic story, use it as one part of it. It's an important part of it. But I think if you ask me what piece will be the biggest piece, it's too early to tell, but I tell you, agents will become the biggest piece because that number will grow significantly. That's even more risk than users. And we are so well positioned to sit in line, understand how to deal with agentic traffic. And also, we've taken 1 other approach. A lot of stuff will happen in the cloud and exchange, something will happen on the endpoint. And they've all talked about having a solution that takes our endpoint and exchange gold. We are pretty unique in that area.
Kimberly Watkins
executiveOkay. We'll do Peter in the second row and then up to the front for Roger.
Peter Levine
analystPeter Levine, Evercore. A follow-up question to Saket's, when you think about competition, your predecessor, what are you keeping? What are you changing? So if you think about you now stepping in the role, like what are you thinking about? Just help us level set some of the changes. Anything that you're thinking about that worked? And then second, Kevin, to John's question, I was going to ask, it's similar, but maybe if you think about the $2 billion, is that a base case? Is that like bull case, bear case? Like how did you come up with that number and the realistic -- based on the products you have today, I think, what does that fit?
Kevin Rubin
executiveYes. So I'm happy to kick it off. Look, we outlined a base case that gets us to $8 billion by fiscal '31, more than double the ARR. And I kind of articulated through how we see the growth opportunities to achieve that case. The $10 billion is really a scenario where AI happens faster and in a much more meaningful way, and it happens across the totality of what we offer, right? One of the things that you've heard from us this entire morning is we believe that the architectural foundation of what we offer is uniquely going to be driven by AI, right? When you think about all of the different threats and exposures that exist, the ability to reduce your tax service and eliminate lateral movement is just fundamental to how you secure AI. And so we think that everything in the platform will ultimately benefit. So I'm not trying to put a $2 billion bogey on just AI, it really is the momentum that likely could play out with AI and the benefits across the totality of the platform as a result of that. I don't know if Jay, if...
Jagtar Chaudhry
executiveIf I may add, I think the demand is growing, everything is growing so rapidly. And we will not be constrained by market size. I don't believe we'll be constrained by competition. The main thing will be how will we execute as company. Our execution on internal products and go-to-market is really what we are looking at, and that's why we've given you the targets we're giving you.
Unknown Executive
executiveYes. And on your first question, a great segue, Jay. What I'm thinking about is execution. I've been at Zscaler 3 years. I've been part of every strategic conversation. I was part of the annual planning. So we have a plan, and it's time to go execute it. And the elements of that plan, we've talked about, I think, a bunch new logos, platform expansion, international public sector, sovereign cloud, maximizing our specialty sales team. Those are the things I'm focused on, and it's really about execution versus a change in strategy because I think we have the right strategy, and it's time to put the foot on the gas.
Jagtar Chaudhry
executiveJust to add on, the question was, what changes? As Ross has said, we aren't expecting any meaningful changes. The approach is working. We just need to keep on executing with focus with a strong team, strong bench. Changes from time to time are a good thing. So I'm very confident in the leadership and go-to-market. And we will execute, and we'll deliver on our numbers.
Kimberly Watkins
executiveRoger, right here at front.
Roger Boyd
analystRoger Boyd with UBS. Jay, it felt like 1 of the themes today was the strength that new products are having in driving new logos. And you talked about 40% of Zero Trust Branch customers that are new Zscaler, the [ 350,000 ] Branch win that you had and the ability to land with AI gateway. It seems like a lot of this may be product led. You talked about the differentiation you have compared to SD-WAN as well as AI gateway. But can you talk about like how these customers are finding Zscaler? And maybe for Ross, how do you think about building like sustainable sales motions to go after these non-ZIA and ZPA lands? And how does that kind of factor in kind of the next 5 years?
Jagtar Chaudhry
executiveSo your first part, Zero Trust Branch, it's growing very rapidly. And the new logo -- actually, new logos aren't coming because of just the Branch. New logos are coming because when the customer buys Zero Trust for users, they want Zero Trust Branch at the same time. So the deal is getting bigger. And this is helping us win bigger deals and a bigger part of the solution. You've always seen us do early on. Remember, we used to have ZIA, just for business, enterprise, we combine the bundles, ZIA, ZPA. It's natural when customers want a bigger part of the platform, Zero Trust users and branches happening together. We'll see as we're starting to see more and more cloud verticals happening together. Our goal is to sell the platform since its integrated platform, it's working.
Ross Tackett
executiveAnd I think your other question was around sales plays?
Roger Boyd
analystJust when you think about kind of investing around kind of landing or something like AI gateway?
Ross Tackett
executiveVery important. And so Adam, maybe you can chime in. But -- so we work with the product teams very closely to develop the sales plays and make these sales plays consumable for our field as well as our customers, pardon me. And then we work with our marketing team to launch that out there. So we've got roughly 5 to 6 sales plays that our teams have been enabled on, which are at a high-level conversation, and then they bring in the real technical people to get under the covers.
Unknown Executive
executiveYes. Very quick add on that. And the reason why I highlighted this in my presentation. So yes, I'm glad you did pick up on it. I'm 2 years at Zscaler. This isn't -- that was not as high a priority, but that did involve -- you have to change your -- you have to adjust your products so that they are easier to land and more focused, and that's what we did. And so that creates this new opportunity for messaging and how to explain to customers where you can start with us and then the selling motion of that. And so that -- this is really the year where we're driving that with force. So we're excited to see where that plays out. And that's why we wanted to articulate that to this group.
Kimberly Watkins
executiveOkay. We'll go to the second row here, Shrenik and then Gray, and then we'll move down to Gregg.
Shrenik Kothari
analystShrenik Kothari from Baird. So all of you guys did reinforce the reacceleration potential, the reaction embedded in the long-term framework. Well, it did not go too deep into what is still relatively the undermonetized, opportunity to monetize the Zero Trust Exchange for Agents, right, which is going to be indexed towards traffic and agent transactions. So just how should we think about that agentic monetization evolving? And then how is that contemplated in the long-term framework beyond just kind of reaction through new logos and users and seats?
Jagtar Chaudhry
executiveI'll start. So if there's #1 thing that's holding enterprises back from fully rolling out agents is the security policy governance concern, okay? And it's not easy to do. Everyone seems to talk, when I got a control plane, I got this in plan. How do you even get the data, right? And agents can be -- the control plane can be sitting on an EDR end point. It can be sitting here. You need to be able to take agentic traffic coming from Salesforce, coming from Snowflake, Databricks, hyperscalers, endpoint, all these places. We've done some of the same kind of stuff before when we did cloud workloads when we did the users part of it. So we are pretty well positioned. We have a product that we launched in June. It's an early availability right now. And this is going to take some time, even though there's more interest in the design partners, customers for this product than any other product. When you're sitting in line, you need to understand things, right? There are many things that are nuanced in the agentic world. Intent all those contexts, our team is figuring or working with them. But agentic product, agentic exchange will take some longer time.
Unknown Executive
executiveYes.
Jagtar Chaudhry
executiveThe other products, visibility, discovery, access graft, all this stuff is good saving for us. I think we're well prepared. So are we really factoring exactly in what we know about agentic [ change ]? It's a little bit too early to say. But early indicators are very positive.
Dhawal Sharma
executiveYes. I'll add to what Jay said. One of the advantage we have is that we already have a footprint where agents are getting deployed. On the endpoint, we have a client that can steer traffic to our AI gateway already, right? Then we have seen in public cloud, neo cloud, edge compute platforms, SaaS services where the agents are embedded, we are able to steer traffic from them. So a lot of that complexity is what we have saw. Now building the functional layer of features and policies and intent and context is what we are building. So very strong design partnership, and we expect this to grow in a meaningful way.
Kimberly Watkins
executiveLet's head to Gray in the second row right there.
Gray Powell
analystGreat. Thank you very much. Gray Powell with U.S. Bank. So actually, I wanted to follow up on Roger's question earlier. And Jay, you hit on this. But we frequently hear that customers, they want to buy secure service edge and SD-WAN together like in the same motion. So I guess my question is, what gets customers comfortable with your product over a dedicated SD-WAN product or something that just gets bundled in with network security. And then I mean, it sounds like you're seeing good demand for it. So just -- I'm just curious, like what kind of uplift do you see to the typical Zero Trust for user ACV or whatever metric you want to give when customers take Zero Trust Branch?
Jagtar Chaudhry
executiveSo first of all, analysts -- industry analysts have asked us, go into SD-WAN business, right? I said we want disruptive technologies that have no lateral movement. So we refused to really go with SD-WAN market, when everyone kind of said, I'm SD-WAN, I'm SD-WAN. So it took us some time. We build Zero Trust Branch, no lateral movement. It's becoming more and more important today. When we're rolling out the -- getting the product out last year, or early stage, I was thinking that perhaps 2/3 of our customers will embrace it. Others will still say, "I want my SD-WAN." I can tell you every Zscaler customer I talked to, they're all ready to dump SD-WAN and go with Zero Trust Branch. I am surprised, but that's what results are. And this frontier model world where risks are growing of breaches and lateral movement, SD-WAN is a risk. The only time customers buy SD-WAN now, when we haven't been able to spend time and show them the merits of it. When we engage, we tell them, SD-WAN elimination and having Zero Trust Branch and user is a very natural thing. And in next year, I want to be here and say, Zero Trust Cloud workload is a natural thing. And for the same thing and agents. Being able to do Zero Trust everywhere is the key strength of Zscaler, and we build upon it.
Kimberly Watkins
executiveGregg?
Gregg Moskowitz
analystIt's Gregg Moskowitz from Mizuho. I thought you did a really good job today outlining your Zero Trust Everywhere solution and specifically the benefits of it, hiding all applications, strong micro segmentation, preventing lateral movement, layering on extensive AI security protection, et cetera. But the SASE market does seem to have become more crowded or minimally noisier, I would say, in recent months, if not last year or 2. When you speak with customers, Jay, Ross, how much confusion exists? And I think we can -- all of us here can appreciate that strong execution can drive a winning outcome. But over, again, in the past year or so, has it become a bit more difficult to articulate your value proposition to customers and to close new and upsell transactions?
Jagtar Chaudhry
executiveI'll start by saying, look, when we get engaged, we almost always win because we're able to clarify it. It is true that every vendor in security wants to be in SASE because if they aren't in SASE, SASE is a big part of it, then they want all in. SASE eventually,, if done right, will consume all the firewall business. Okay? So if really firewall vendors were to do 3 of SASE, they'll be worried about SASE because no firewalls will be needed. But our goal is really not to pigeonhole SASE for users. We bring the story together. Our goal is to show differentiation of branch level, show differential in cloud workload level. Wherever we go, who offers Zero Trust Everywhere? Who offers Zero Trust SASE Everywhere? What do you do in the cloud? It's same old virtual firewalls. Nothing, nothing is new. Branch is same old SD-WAN. And in the user level, it's firewall in the cloud as a virtual firewall, it's VPN in the cloud as a virtual. That's not real competition. And I think a lot of bundling that has happened, that will come out. And I'm feeling very bullish and confident, we just need to keep on executing on the sales side.
Ross Tackett
executiveJay, I don't have a lot to add. I'm very bullish and confident as well. It's about execution. As Jay mentioned, we are fundamentally different, and it's our job to explain the value in that difference.
Kimberly Watkins
executiveLet's go to Eric.
Eric Heath
analystAll right. Eric Heath with KeyBanc. A question for Dhawal, I guess. Those was really interesting, the comment you had that you were the only vendor with the context and intent to understand agentic and AI action. So can you just elaborate on that point a little bit more? And maybe help us delineate the lines of where the endpoint visibility ends and where you're visibility picks up? Because obviously, there's a lot of rhetoric that a lot of the agentic activity happens on the endpoint. So help us understand what's incremental in terms of unique data that you can provide and be that enforcement point?
Dhawal Sharma
executiveYes. So I'll start by saying that context layer in a lot of agent security platform is tied to agent identity only. Going back to what I said earlier, the visibility we are building with connecting the dots of data identity and AI and using that as the context with our gateway and endpoint is unique. So that context layer is the golden layer. Lot of new AI gateways that are coming in the market are very intent focused or use case focused. I think our -- one of the biggest advantage in that area is, yes, the intent policy stack will become very commoditized over a period of time. But being able to build AI gateway at scale at which we run our cloud is something as a muscle that we as a company have built. So bringing context from a Zero Trust perspective and intent from a function perspective, when you bring it together, we are seeing that validation coming from our customers, from a design perspective that we are unique. Your point on endpoint AI security is good because when we think about where policies can be enforced, the amount of [ attack erase ] that gets generated to the endpoint with the actions that AI agent applications can do on the endpoint with data as well as actions they can take. They actually are becoming hard to control before even it hits the network. You can do a lot of damage within the network itself or before it hits the gateway. That's why being able to meaningfully do when things are happening within a prompt and controlling that kind of skill files that people are downloading, for example. So those kind of controls could be implemented there. But one thing we have already done is our endpoint AI security product is fully integrated with our gateway. When the traffic needs to leave to the Internet or to a agentic application, that is subject to gateway policy if the agentic action on the endpoint is not triggered. So it's best of both our approaches that we are taking in such things as there are.
Kimberly Watkins
executiveHands, 1 more time. Josh, right there.
Joshua Tilton
analystJoshua Tilton from Wolfe Research. There's been a lot of talk today about reaccelerating new logos. If you look at the other side of that, it's been pretty impressive that you've been able to sustain a mid-teens NRR over the last 3 years. When you look at the FY '31 target, maybe just in the context, that $8 billion, do you still expect to be achieving a mid-teens NRR rate?
Kevin Rubin
executiveI didn't call out a particular longer-term target for net expansion, but it's fair to say that I would expect that we continue to have significant success upselling based on everything that you heard today, the broader platform, et cetera.
Kimberly Watkins
executiveOkay. Probably time for one, maybe two more. We'll go over to the second row, aisle. And then I think we have one here, and you'll be our last.
Michael Cikos
analystMike Cikos from Needham, and thanks again for hosting the day. Maybe just building off the building blocks here. But Ross, I know you were saying we're looking at execution. And you had spoken about the hunter territories earlier. Can you just give us -- or elaborate on that further, like where are we? Was that something that we just established at sales kickoff and what's required as far as hiring bodies to stand that up, ramp time to start seeing the fruits of those investments?
Ross Tackett
executiveYes. And Jay, if you want to chime in as well, you and I've had a lot of discussions about this. So historically, we have had new logo hunters around the globe, and we have expanded that here in FY '27. That is not our only new logo motion though. We have territories that have a combination, they're hybrid territories with new logos and existing customers, where that makes sense. So we are building out those additional territories. Or they have been built out, I should say, and hiring is almost complete for all of those. I do -- we've talked about new logos. I do want to come back and remind everybody the white space opportunity we have within our existing customers. We've only got 4,600 out of the 20,000. And then if you look at those 4,600, there's like a $20 billion TAM, and we have $3.8 billion of that. So yes, new logos are important, but we have a tremendous opportunity within our existing customer set.
Jagtar Chaudhry
executiveIf I may add, yes, as a part of the fiscal '27 plan, the territories were very well done. We spent a lot of time understanding each territory. What's the mix of new logo versus upset current customers? Because ideally, you want to give a balance of both too many apps, but then having some of the very focused hunter territories. Both are in motion. So I don't want to send a message that we are expecting new logo only from hunter only territories. That's 1 more step. Or combination that and existing reps who have both new and upsell opportunities. We expect good results this year.
Ross Tackett
executiveYes. Spot on, Jay.
Jagtar Chaudhry
executiveYes.
Kimberly Watkins
executiveOkay. We'll do Junaid, and then I'm going to add one more, Rich Poland, and then we're going to wrap.
Junaid Siddiqui
analystThank you. Junaid Siddiqui, Truist Securities. Jay, we've seen some of your competitors expand deeper into observability. And we're seeing some of the inline conversion security. Where do you see Zscaler uniquely positioned in that conversions? And given your in-line architecture and vision around Agentic SecOps, do you see evolving towards an operational control plane beyond just security?
Jagtar Chaudhry
executiveSo we generally got very strong convictions about where we want to go, where we don't want to go. And generally, it's not driven by somebody buying a vendor A, vendor B or vendor C. We think our customers want meaningful interior solutions are in areas. You saw the TAM we had today. It's a massive TAM in a very synergistic area. So do we need to get into observability to look at performance across everything? That's a secondary area, not really. The core markets we share with you, they are so being so massive, I would rather dominate those markets than trying to expand into other markets.
Unknown Executive
executiveWhere it becomes complementary really quick, and additional though, is, as I said, if we're mission-critical infrastructure for our customer with our Zero Trust SASE Everywhere, understanding the end-to-end experience on that is quite important, and that's why we do have our ZDX, but it's specifically about the experience for things on Zscaler's platform across the [ ultra SASE ], not general IT observability. So I think that's the right lane for us to be important, and it is a big value for our customers.
Kimberly Watkins
executiveOkay. I'm going to try to squeeze one more in. Rich Poland in the front row.
Richard Poland
analystThank you, Kim. Rick Poland from Wells Fargo. I think just to kind of bring it all together, I think 1 of the questions that we've gotten from investors is just thinking about SASE and the architectural shift that Zscaler proposes is a large undertaking. And so I think part of the reason why you've seen some of the SD-WAN is because it's kind of almost the path of least resistance in some cases. And so while customers are thinking about AI and all these other things that are going on right now in this current environment. Just kind of how do you think about getting customers that would be new logos or embracing Zero Trust Everywhere over that hump?
Jagtar Chaudhry
executiveI'll start. Actually, moving to Zscaler Zero Trust is not a large undertaking. We're seeing customers deploying say Zero Trust users in a matter of weeks or a few months. All you need to do is start with a lightweight agent on the endpoint. You don't even touch your network. The traffic starts taking whatever path is available. You define some policies, we can be fully up and running. Now it can take time to dismantle all the stuff that's sitting there, but customers typically get moving with rolled out to Zscaler, start getting the benefit of security and then have the benefit of moving the stuff. Now if we get some inertia and pushback, generally, that comes from a lower level. People who own those stuff, a little bit job security, a little bit of inertia, I know this thing too. That's why we have very strong relationships with CIOs, CISOs, CTOs, AI offices, who drives change because leadership does. When they want to embrace AI, they really become a catalyst for us. So we are seeing AI as a catalyst. Not to say that Zscaler requires a big infra change. The world has moved to the level where the management is buying our story. That's why we're seeing a lot of expansions. I mean, the customer you heard today and an example we shared with you today, these customers starting with $1 million to $5 million, to $10 million to $20 million. This is real, it's happening because of the benefits we offer.
Kimberly Watkins
executiveOkay. That's it on Q&A. Jay, do you want to wrap this up?
Jagtar Chaudhry
executiveYes. Thank you again for joining us today. We hope that today's presentation have given an opportunity to see that one, Zscaler is the cybersecurity platform for the AI era. Two, AI is the largest tailwind our business has ever seen. And three, we have strengthened our go-to-market engine, and we intend to keep on penetrating it, driving it to achieve our large TAM. We have multiple growth engines that will accelerate our growth to move forward. And we look forward to proving you that we can do it in coming quarters.
Kimberly Watkins
executiveOkay. Thank you, Jay, and thanks for all of you for joining us today and making the time. For those of you online, this will end our webcast.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Zscaler, Inc. transcript — plus 255,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Zscaler, Inc. earnings transcripts and 255,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.