Hello, everyone, and thank you for joining us for our growth stock conference and today's session with Cellebrite. My name is Jonathan Ho, and I'm the analyst, along with Louie DiPalma, co-covering Cellebrite for William Blair & Company. Our speaker today is CFO David Barter, who will be providing an overview presentation of the company, and then we'll go into a brief fireside chat. Before we begin, I'm required to inform you that a complete list of research disclosures or conflicts of interest is available at our website at www.williamblair.com. As a quick reminder, the breakout session will be held in the Adler Room following the presentation. With that, I'll hand it over to David for today's presentation and fireside chat. Thank you.
Thank you, Jonathan. Is this mic working well? Good. Jonathan, thank you so much. Thank you for having us at the conference. This is a real treat and a highlight for us. I'm going to start off and try and break up the time, about 15 minutes, just give you an overview of Cellebrite, what gets us excited, what do we do, where's our motivation in life. Then we'll try and reserve some time just for a little bit of Q&A and just to answer things that are on your mind. I know Jonathan has a few questions all keyed up as well. I'll let you read the safe harbor later on. When you think about Cellebrite, I guess, first and foremost, we are a public safety company.
What gets us up and what gets us going every day as a mission of around 1,300 people is just our focus on protecting nations and communities, every person, every business that ultimately represents in that group. We actually are really focused right now on delivering to all of our customers a comprehensive platform. This is kind of a newer thing for us in the sense that we started off with a lot of capability around a full file extract, then we kind of got in the business of being able to unlock devices. Increasingly, where we're going through a lot of our organic development, also a couple of acquisitions, is really being able to serve law enforcement, public and federal agencies with a full set of platform technologies. That's what I'm excited to share with you today in terms of where we've been going.
The Genesis of our company really was around the idea of we help you start to collect evidence. The richest piece of evidence going back over the last 15 years has been the mobile phone, and that's where our heritage started, around helping investigators quickly extract. What does it mean to extract? It means to be able to not just scrape a mobile phone, but to go through some of the most encrypted applications that somebody may use, maybe going and scraping all of their cloud services. A phone can be anywhere from 60 GB to ultimately a 0.5 TB . Our goal really is driving this phase of collection of evidence. There are some secular tailwinds to our business.
If you were to rewind the clock to 2007, 2008, when you first got your hands on an iPhone, there was a forensic examiner sat in the back room of any police office. They would drive the extraction. Today, you're going through a business where every detective, DAs, increasingly offices, even with the FBI, everybody wants to collect evidence. They're trying to compress the investigative life cycle. They're trying to get a lot of noise in the world and trying to get to really good signal intelligence. That kind of takes us to where we're really going with the business. About three or four years ago, we introduced a collections platform. It is perfect for law enforcement in the sense that it supports full chain of custody.
Rather than passing data and some of the very manual processes that ultimately jeopardize chain of custody, we've come up with a native cloud solution. It also includes an AI viewer. If you're trying to automate the entire investigative life cycle, and you have to look at this from the perspective of a detective. Detectives don't want to look at murder. They don't want to look at rape. They don't want to look at exploitation. With an AI viewer, we've been able to dramatically transform the investigative process to be able to attach metadata to the phone calls, to the images, to the videos, all associated with crime, where we can dramatically change how crime ultimately gets prosecuted by an examiner, a detective, and all the way up to the DA.
There's always a human in the loop, but we've been able to reduce dramatically both the time but also the investigative toil. That's a big part of what we've been doing up within the management. I'll lastly take you down to AI. AI has been a persistent element in all of our products. We've recently, as we shared on the earnings call, started to roll out a new product called Genesis. Genesis is purpose-built. It's designed for investigators in the sense that it takes the guardrails off any investigation to be able to look at highly sensitive data. It puts the guardrails back on in terms of making sure that a model doesn't hallucinate. We're really excited about the ability to start to transform. Now, lastly, I'll highlight just in terms of virtualize. We really think about the acquisition that we made of Corellium.
We have the only technology in the market that has kernel-level access to any ARM-based device. That has a number of superpowers. The co-founders built that business on the back of vulnerability research. You can do some pretty fancy tricks in the form of being able to look at a device before and after. If you are a three-letter agency and your folks have been overseas, we can actually look at your device before and after to find out what malware is on your device. If you want to forensically inspect a device, we have the only ability to forensically inspect a device. Having that ability to virtualize any ARM-based system ultimately accomplishes a variety of tasks, both at a federal level but also at a local level, if you are truly in need of having robust investigative capability. What's driving our business?
At a fundamental level, it's certainly data volume and complexity. I would also say structurally, you have a different challenge in the business in the sense that whether you're an operator in the field, whether you're customs and borders or you're law enforcement. There's a volume of data, there is the need to compress the investigative cycle. The environment is incredibly noisy with regard to the volume of data that's hitting any operator in the field today. There's the ability to be able to get through the volume of data, get to signal intelligence, and be able to make a decision as fast as possible. I'd say this kind of challenge that you see is at a federal level.
Many customers, I'd say, or prospective investors would say, "Gosh, you sell into the FBI, you must be fully penetrated." Even the FBI, with the size of their budget, they don't actually have all of our technology in every field office. If you were to look at state-level agencies, same challenge. Digital investigative capability is still not fully penetrated. It is a small fragment of, or a fraction of what you'd expect to see in terms of being able to have signal intelligence. Data volume and complexity is a challenge, penetration within the market, and then lastly, you are getting into the element where there are elements around an iPhone or any technology starts to lock after a certain amount of time. That's hastening the need to start to drive the adoption of technology.
The last part I'll highlight is that a big part of our business, and I think what separates us, is that a key part of our mission is the ability to focus on lawful investigations and ethical AI. We probably have a KYC policy that rivals almost any bank in the world in the sense that we don't sell to just anybody. We don't sell to any country, and we certainly don't sell with any given country to any customer. Our focus is there are people that are sanctioned and are officers of the court in the sense of they are empowered to be doing lawful investigations. We also believe that in our products, ethical AI is a very important part of our relationship with any customer.
We believe that's an enduring part of our business model because you do see people making it to the news in terms of pushing the boundaries of how they use data, and our view is there is just, again, a very lawful and ethical way to ultimately do warrant-based work with all of our customers. I've hit on this in a number of ways, but I think the element I would want you to really walk away with is whether you're protecting the perimeter of a nation and you are in customs and borders, or you are in a local PD. There is a compression that is going on in the world in terms of being able to really drive home the ability to understand the signal through all of the noise. Everyone is compressing the investigative life cycle. If you're the local PD, you're worried about an investigation.
If you look at the Guthrie case, people were very concerned around how do you use technology to change that process. That process became a very elongated investigation. I would say it's probably not what investigators aim for. They're really trying to nail investigations within the 24-48 hours. If you're an operator in the field or if you're at customs and borders, you have people right in front of you that are trying to enter a country. You really want to have that signal intelligence very quickly. That's a common denominator that pulls through a lot of our business. Lastly, I want to wrap up, and I want to be sensitive on time as I look at the countdown here. There is a lot in our business where we look at the mobile phone, when it gets extracted, produces a data element called a UFDR.
A lot of our customers will take that UFDR, and they will complement it. They'll complement it. It could be with something out of a records management system, potentially like a body cam or a CCTV. Maybe they will actually take that data, and they will marry it up with all of the calls that are coming into and out of a prison. They might marry it up with a ballistics report. What makes our business something special is we probably have the thorniest piece of data in terms of all of the data that people attach to their mobile phone. Again, lots of cloud services data, and they will ultimately enrich it with other evidentiary artifacts in order to drive this rapid insight. It's one of the interesting things about what's going on in the business at a very macro level.
This is what's driving the usage, I think, of our AI platform, is for every UFDR that somebody might get their hands on, they will ultimately enrich it with nine other data sources in order to get to that actionable intelligence. I thought it would be worthwhile to give you a flavor, because this is new for us as much as it is even for our customers around how to use AI in an ethical way and also within the bounds of search warrants and what represents a lawful investigation. I think what we're finding here with these case studies is that we are probably changing the world in a way that we didn't even expect, in the sense that when we started rolling out our Genesis to our customers, we offered it as an early access program.
Our hope was maybe we'll get 12 customers that will want to come in, and they'll help us harden the solution. We ended up with hundreds of customers, and I think we're well over 500 participants in terms of people that are now using it. They're not just using it to use it. They're actually using it to solve crime. That's when we started thinking about a great early access program, one where we're actually starting to change how communities work, whether it is unpacking. There was a terrorist organization that ultimately turned out that they ended up being a financing arm for Hamas, and this was all happening out of Asia, which was really an eye-popping incident. There have been cases of murder, cases of exploitation. For our standpoint, a big part of our journey has been how do we, again, protect nations?
How do we protect communities? How do we impact and protect citizens? As we look at our ability to compress the investigative process and to really change how our nations work, this is a product that we're pretty excited about. That product is still in early access mode. We expect to launch it sometime later this month. Our real focus, though, is driving adoption, and our focus is really, again, changing lives for citizens, but changing lives for our customers as well. One of the things that I figured I'd wrap up on is, and we'll just hop into some questions here in a second, is just a little bit of our journey as a company. A lot of people know Cellebrite, because when there was the attempted assassination of President Trump, the FBI called us to help.
There are other high-profile situations where people say, "Gosh, Cellebrite is the group that can either unlock a device or unlock an extraction." The piece that I think is increasingly interesting to investors is not only the natural expansion that comes from those things that we do well, but also all of the growth products.
What we really wanted to capture on this view is where we see all of our customers that are on the vanguard who have said, "Gosh, now that you have FedRAMP, how do I actually start to manage all of my data in the cloud?" "How do I start using AI in a very progressive way?" One of, I guess, the element that we're excited about is our customers, as we shared on the last earnings call, are starting to ask us for platform arrangements where they can democratize the usage of all the extraction capability, and then tie it together with all of our other products. Our focus on changing the investigative lifecycle is something that we're super excited about in terms of how it's helping our customers.
Why don't we stop here, maybe get onto some of your questions, because I think financial highlights will naturally take us into the things that are top of mind for you.
Perfect. Perfect. Thank you, David, so much for the overview. I certainly have to say, Cellebrite is one of the most impactful companies when it comes to solving law enforcement challenges and just impacting our society as a whole. We sat in at some of the sessions at your user conference where District Attorneys talked about the criticality of Cellebrite to solving multiple murder cases, and a lot of exploitation and just really crazy things that are happening in society. Thank you for the good work.
Thanks.
One thing I wanted to dive into is that you've talked a little bit in your slide deck about the transitions that have happened over the past year with the company, whether it's with management, product, or strategy. Can you help us understand the changes within the strategy and organization, and where we're going along that journey? Where's our endpoint here?
Well, it's a great question in the sense I'm not sure that there's an endpoint, but there is an opportunity. For the last three years, the company has been focused both, I'd say, organically, and then lately with a little bit of strategic acquisition around the idea that maybe I'll kind of observe that when I got into the job about a year ago, one of the first things I received was a police report. It was an assessment of one of our major states and the state of the IT infrastructure that was supporting the investigative process. The challenge, and what I realized through that report was they had a series of silos in terms of the technology solutions around both operational data and the judicial data.
It was a variety of point solutions all on-prem, of how they actually run a major police force across an entire state. For me, that was probably my first aha of saying, "Gosh, I now understand the problem." This is a digital transformation problem in the sense these are on-prem, largely, again, technology from 20 years ago. It doesn't support the nature of crime today. I think what we've done is actually use, probably arguably one the most important data to them, but then start connecting all of that data as it goes from an operational process into a judicial process of, how do I hasten the process of investigating? That really is, I think, what's unfolded over the last three years is both a product roadmap, a cloud journey, a transformation where just six years ago, the company actually sold perpetual licenses.
Today, we actually are selling consumption contracts. We really, if you ask any major law enforcement organization, they know how many cases they prosecute. Having a consumption business model actually works really well for them. Being able to actually put that technology in the hands of a detective all the way through a DA is really transformative for their journey. Again, I think almost all our investments have really focused on that compressing of the investigative lifecycle, where we can actually get insight into the hands of the operators who need it most.
Jonathan, maybe one other point related to transitions. If you think about what we've gone through in terms of leadership, and we're continuing to bring on new executives. Have a new president of product and technology who started a couple of weeks ago. If I think about where we were at this time last year with our product portfolio, the breadth and range of our capability is so much more extensive than where we were at this time last year. That reflects, I think, an increased level of both investment in development, but also you'd see that correlated with an increased emphasis on strategy. Whether it's organic development in products like Guardian Investigate and Genesis being at the forefront there, or acquisitions, Corellium and SCG in terms of drone forensics.
I think that what's on the truck today is substantially more impactful, or broader in scope, and we'll continue to bring new capability to market over the coming quarters.
Excellent. I don't think we can have these meetings without some discussion of AI.
There were some of the evolving things that are happening there. There's been a lot of concern in software, and particularly with cybersecurity regarding Mythos itself. How do you think about Mythos as either a potential threat or opportunity when it comes to Cellebrite? Specifically, you have to leverage vulnerabilities to be able to break into these devices.
Does it create potential competitors, or does it make your job easier? How do you think about it?
Well, it's a great question. It's actually, we will have a tech talk in about a little bit over a week from now. A little bit over a week from now, we actually wanted to be able to speak very factually about that point. We wanted to bring our CTO, who founded Corellium, who's a vulnerability researcher by trade, we also wanted to bring our head of product and also the head of our AI. We actually think, as we've talked to a number of investors, there's a fair amount of confusion around what is Mythos, what it is not. We've actually thought, rather than hearing from some finance folks, we thought investors would greatly appreciate hearing about from vulnerability researchers around how they approach it.
I guess, in advance of that, I think when Mythos came out, let me maybe offer a couple of thoughts. We certainly looked at it from a research perspective, and then our CTO reached out to Apple, I reached out to somebody else, who one of the mega caps that had actually had Mythos. We actually tested out, one, what were they seeing, and then we also back traced it to how we thought about vulnerability research, where we've been using AI for a number of years. I think to net it out for you, just in advance of that presentation in about a week or so, is the framework that we have actually, I think continues to hold true. We approach vulnerability research in a very specific way. Every OEM has to make trade-offs.
They're making a trade-off between cybersecurity and the security of their platform versus the user experience, the application performance, and what they term usability. This was actually played back to us because this was our thesis around how we build exploits. Recognizing that there are a series of engineering trade-offs that have to occur that make your platform either work or make your platform work with a carrier. Does it make it work between Apple and Windows or a Google app on an iOS app? All of these trade-offs create opportunities, and they really sit at the intersection of the software and the hardware layer with any device. We string, as our vocation, and what a researcher does is they will take 10 or 12 different vulnerabilities, and they will start to turn that into 10 or 12 different exploits.
That's ultimately how we go about the process of both unlocking a device, but equally unlocking the applications that you think are encrypted and secure, or unlocking and taking out the cloud services that you think are secure. That process, the investment we make in research, it's a global investment. It's actually not in one location. It's not one team in Israel. We employ researchers around the world who have a very unique skill set. They use AI, but they're using tools like Corellium, which we acquired in December, and other advanced tools. Vulnerability research, and it's hard for what we do, I'd say ultimately kind of attacks very specific engineering intersections between hardware and software.
We would look at something like Mythos as it's an incremental advance. It's certainly not an existential threat to what we do. We will get value from developments like that, as the OEMs will as well. Treadmill runs a little bit faster. Our level of investment, as Dave mentioned, is global in its nature, not only in people, tools, and partners. Again, we believe we're delivering a solution that has extensibility and value as we move forward. Barriers to entry into our business go up. The value that we deliver to our customers goes up as well.
That makes a ton of sense. Cellebrite has announced a number of new product announcements from Guardian Investigate to Genesis. Help unpack for us what does the product evolution look like, and help us understand sort of that journey for the customer as they, say, walk through from a traditional extraction customer all the way up until using the full suite of solutions? What does that customer journey look like?
Well, it's probably more a journey around how the company has moved from a forensic examiner almost all the way through to the District Attorney. Maybe it was halfway through my journey, I guess, in the last six months when I learned that actually, there is more diversity in practice in terms of what's happening in the ecosystem than I even gave it credit for. I'd say many investors will say, "Gosh, the idea of running an extraction always sits with the police chief." That's actually not true. In the state of New York and specifically in New York City, it's actually not the chief of police that drives the extractions. It's actually the DA and the District Attorney.
We've had a general push towards expanding the audience of, and the personas that we serve, from forensics examiners to detectives to DAs, and kind of that push through the entire judicial process. Our product roadmap really reflects that in many respects, where we've gone to make sure that we provide a full set of connected tools from how you run an extraction to how you collaborate on evidence and having a case management solution. You had a great call out around Investigate. Investigate is actually purpose-built for detectives and investigators, where they have work item tracking. They can build a criminal timeline. They have the ability of anything that you might have seen on "Law & Order," but to do that now digitally.
They can do that digitally, and they can bring in the UFDR, they can bring in all of their other data elements, and as we're innovating, they'll be able to tap into Genesis in the same console and in the same pane of glass. They'll actually be able to accelerate their investigations. Rather than, again, almost going back to that old investigative report that I saw of all the siloed apps, you now get to having a pane of glass that actually is really geared around the detective, the investigator, and the DA of how do they pick up all of the operational data and move it into the investigative process. That's where we kind of see, and I think you saw the customer conference where one of our customers out of Texas was one of our early design partners.
They said, "Gosh, now I have an application for myself." It's an application that really works for an ecosystem that's about a half a million detectives, investigators, DAs in the U.S., and that's about 10 times the size of the examiner population. Being able to hasten the journey that they're on is important.
Absolutely. Moving on to more sort of financial questions. When we think about sort of the broader transformation within pr oduct contribution for Cellebrite. As it shifts more and more to AI, how do we think about the margin structure? How do we think about the costs? How do you leverage AI yourself internally?
Well, let me kind of pop up, because you're right. There is a lot of transformation, and I think as a company, I think we feel really good about running as a rule of 50 company, but let maybe talk about how we get there, and we'll talk about the AI usage. The top line of our company has been shifting, and not only has it been shifting from where it was six or seven years ago where it had perpetual, and now today it's all term-based subscriptions for some of our federal customers or consumption contracts, but once upon a time it was 90% or 95% really geared around extractions. We'll end this year, and it'll be almost 80% extractions. About 20% of it will be all the growth products that represent that platform that we talked about earlier.
That transformation that's going on where we have some products that are still growing at healthy double digits, which is the extraction piece, but all of our newer products are growing plus 50%, or in some cases, 100% year-over-year. Kind of continuing to build out the platform I think strategically is an important part of what we're doing to really own much more real estate within our customers and within the investigative process. How AI is playing a role is we started off actually early on by bringing AI into the extraction process, then we brought it into the case management process, and now we have standalone AI applications. Continuing to meet customers where they are in terms of their readiness around having AI at their fingertips to hasten the investigative process has been an important part of the product strategy.
I'd say operationally, we've also been bringing it into how we work as a company. The first place where we used AI was on vulnerability research. That was the kind of the initial superpower. Now it's around software development and increasingly, quite frankly, it's how we run sales operations and even finance and investor relations. I think almost everyone looks at 2026 internally as a very pivotal year for us as a company where a software engineer will become. This was actually data from one of our engineering leaders where we ran. We started off with OpenAI as the first tool that we used in software development. Recently, we ran a pilot with Claude Code. Same thing that many people have seen. An average engineer suddenly becomes a 5x engineer.
I think the way we're going to get continued leverage on our P&L, we've talked about driving up to from plus 30% free cash flow margins to 40%. AI will be one of those ingredients.
Excellent.
That's R&D, go to market, and certainly the G&A functions.
Yeah. It makes a ton of sense. Cellebrite recently received FedRAMP High A uthorization. Just want to understand, this is something that none of your other competitors have, based on our understanding. What kind of opportunities does that open up for you? Is there a way to sort of understand the timing for you to take advantage of having this certification? Is it typically hunting license where you're starting the process, or are a lot of customers just ready to go and to start contracting?
Let me answer the second part of that question first, then I'll come back to the first. The hunting license, I'd say, was already there in the sense that the great news about the federal agencies is they were very well aware of the toll gates of working through FedRAMP. From that standpoint, the agencies have been tracking where we're going. It was about two d ays before we actually got our letter that we actually received a strong inbound inquiry from somebody saying, "Well, we know your letter's about to come, so now is a good time to start talking about and ordering contracting." Our view is whether it's Q2, hard to say, but probably Q3, first order probably starts to come in from that standpoint simply because of the physics associated with contracting officers and government procurement.
We believe that being the lead product makes tons of sense. Let me get to the first part, which is why. The federal government, as a taxpayer, I don't know if I have to be the one to kind of break your hearts, is way far away from digital transformation. Us having FedRAMP, this opens up that opportunity for digital transformation within the federal government particularly. This is why the Department of Justice sponsored it. To be able to prosecute crimes at a national level, be able to connect the federal level to the states, this is that opportunity.
The opportunities come from even in Congress, where there was a congresswoman who wants to sponsor legislation says, "Gosh, for internet crimes specifically, getting into internet crimes against children, there must be a better way to be able to protect this because it's all CSAM data, it's protected data." For a FedRAMP High environment, it's actually the perfect place to have highly sensitive content around the exploitation of children and what's happening." We agree. This is why even our AI is very specific because it deals with crime types and very sensitive data. We think we're early on, but we also think we're early on in terms of being able to help the government at a federal level and at a state level be able to work much, much more efficiently.
Excellent. Unfortunately, that's all the time we have today, and so we'll continue the discussion in the breakout session. Thank you.
Jonathan, thank you so much.
Yeah.
Thank you, everyone.
Thank you.