Good day, everyone, welcome to the Qualys first quarter 2015 investor conference call. This call is being recorded. At this time, all participants are in a listen-only mode. Later, we will conduct a question and answer session, instructions for asking a question will be given at that time. I would now like to turn the call over to Don McCauley, CFO of Qualys. Please go ahead, sir.
Welcome to the Qualys first quarter 2015 investor conference call. I'm Don McCauley, CFO. I'm here with Philippe Courtot, our Chairman, President, and CEO. We'd like to remind you that during this call, management expects to make forward-looking statements within the meaning of the federal securities laws. Forward-looking statements generally relate to our future events or to future financial or operating performance. Forward-looking statements in this presentation include, are not limited to, the following. Statements related to our business and financial performance and expectations for future periods, including the rate of growth of our business, our expectations regarding capital expenditures, including investments in our cloud infrastructure and the intended uses and benefits of those expenditures. Trends related to the diversification of our revenue base. Our ability to sell additional solutions to our customer base. Our plans regarding the development of our technology and the expected timing thereof.
Our expectations regarding the capabilities of our platform and solutions. The anticipated needs of our customers. The strength of demand for our solutions, including our Private Cloud Platform. Our strategy, the scalability of our strategy, our ability to execute our strategy, our expectations regarding our market positions. The expansion of our platform. The expansion of our development operations and support teams in India. The expansion of our partnerships and the related benefits of such partnerships. Our ability to effectively manage our costs. Our plans to expand our sales force. Our plans to explore acquisitions. Our expectations for the number of weighted average diluted shares outstanding, the effective GAAP and non-GAAP income tax rates for the second quarter and full year 2015. Our delivery of new solutions.
Our expectations and beliefs regarding these matters may not materialize, actual results in future periods are subject to risks and uncertainties that could have caused actual results to differ materially from those projected. These risks include those set forth in the press release that we issued earlier today, as well as those more fully described in our filings with the Securities and Exchange Commission, including our annual report on Form 10-K that we filed on March 6th, 2015. The forward-looking statements in this presentation are based on information available to us as of today, we disclaim any obligation to update any forward-looking statements except as required by law. We also remind you that this call will include a discussion of GAAP and non-GAAP financial measures. The non-GAAP financial measures are not intended to be considered in isolation or as a substitute for results prepared in accordance with GAAP.
A discussion of why we present non-GAAP financial measures and a reconciliation of the non-GAAP financial measures discussed in this call to the most directly comparable GAAP financial measures are included in our earnings press release that is available on our website. To begin the discussion, Philippe will provide an overview of the company's performance for the first quarter 2015. I will cover our financial results and factors that drove the quarter in more detail, as well as our outlook for the second quarter and full year 2015. We will open up the call for your questions. With that, I will now turn the call over to Philippe.
Thanks, Don, and welcome to all of you. The first quarter of 2015 was a good quarter, which included a number of important product releases that continued growth and success across our business. Don will cover the financial details of our performance for the quarter. These are exciting times at Qualys with the introduction of our Cloud Agents. As I'm sure you all have seen already, our first quarter revenue came in just below our expectations, and this has a modest impact on our full-year revenue guidance. This was due to slightly lower Vulnerability Management revenues in Q1 than we had expected due to the timing of a few large enterprise deals in the quarter. Although our Q1 revenues came in somewhat less than we expected, we met EPS expectations for Q1, and our EPS guidance for 2015 is unchanged. Don will provide additional details on this.
Let me start off with an overview of key highlights that are driving the momentum in our business and discuss in more detail our new product releases. During the quarter, we laid the groundwork for three major new services that we launched at the RSA Conference last month. Together, these new services double our addressable market with, first and foremost, our disruptive Cloud Agent platform. Second, the seamless integration of our Web Application Scanning with our Web Application Firewall services, an industry first. Third, the extension of our very successful Continuous Monitoring of perimeter solution to internal networks.
We believe that this technological innovation and enhancements provide Qualys with significant competitive advantages and make our solutions more strategic to our customers and partners, as we have now built a highly scalable cloud platform that provides enterprises of all sizes with a unified and continuous view of their security and compliance posture across legacy networks, virtual environments, web applications, and endpoints. Let me give you more explanation on these three new services. The Qualys Cloud Agent platform is a disruptive technology that brings a new approach to continuously assessing IT assets for their security and compliance posture, and better align IT with security. It extends our cloud platform by allowing the creation and distribution of one megabyte lightweight agents that scales to millions of devices, including endpoint, servers, or virtual machines in elastic cloud environments.
These agents continuously collect and consolidate vulnerability and compliance data in real time and update this data within the Qualys Cloud Platform for further analysis and correlation. We believe that this is an innovative game changer for both Vulnerability Management and Policy Compliance, as it eliminates the need for scanning windows and authenticated scans while making security assessments continuous instead of monthly or weekly, as it is currently done. It also expands our VM and Policy Compliance offerings to endpoints, which could not be reached with traditional scanning technology. Second, the Web Application Firewall version 2.2 release provides tight integration with our Web Application Scanning and delivers virtual patching and event response capabilities, enabling organizations to fine-tune security policies, remove false positive, and customize rules leveraging vulnerability data from the Qualys Web Application Scanning solution.
These bring web application security to a new level, as it now allows organizations to efficiently address web application security threats end to end. Finally, the Qualys Continuous Monitoring service for internal network is an extension of our very successful Continuous Monitoring solution for perimeters to include IT assets inside the enterprise, allowing businesses to proactively monitor both perimeter and internal IT assets and obtain real-time alerts to accelerate incident response. Let me now give you key highlights on the state of our business. In the first quarter, we added a number of important new accounts, including ACI Worldwide, Airbnb, Alcatel-Lucent, IT Source, CGI India, The Cosmopolitan of Las Vegas, Diligenta, HealthNow New York, Integrys Energy Group, the International Monetary Fund, Jaguar Land Rover Automotive, JCB Limited, KDDI Corporation, La Quinta Inn & Suites, MTN Group, Rightside, and Tampa General Hospital.
We continue to see greater than 50% growth from our new services, which include the Web Application Scanning, Policy Compliance, Continuous Monitoring, Web Application Firewall, and our Private Cloud Platform. We saw approximately 19% growth from our industry-leading Vulnerability Management solution, which was a slight decrease from its 20% growth rate in 2014. An indication of our success in diversifying our Cloud Platform offerings is that 58% of our customers have now purchased more than one solution. This is another data point and a promising trend line, as these metrics stood at 30% at the end of 2013 and 54% at the end of 2014. We continue to see strong demand for our Private Cloud Platform, which allows customers to use our full suite of security and compliance solutions while keeping all data on premise.
Demand is particularly strong outside the U.S. due to data sovereignty requirements from our partners and customers. Next quarter, we will deliver our private platform fully disconnected from Qualys SOCs in terms of receiving updates and monitoring. We expect that these, along with FedRAMP certification of our platform, will further our federal and defense sectors for us and other highly classified environments. We are also making good progress with our new solutions currently under development, including our real-time data analytics backend, as well as our malware detection and prevention service, both of which will be released later this year. We expanded our strategic alliances with the majority of the Indian outsourcers, including Cognizant, Infosys, HCL, TCS, Tech Mahindra, and Wipro, as a result of their new focus on delivering security services to their clients worldwide.
We were honored by Frost & Sullivan with the 2014 Company of the Year award for product excellence, continued innovation, and unique approach for delivering customers continuous security. We also won Best Regulatory Compliance Solution at the SC Magazine Award 2015 in the U.S. and the SANS Best of Awards for Application Security in 2014. Now for review of our financial performances and our guidance, I will turn the call over to Don.
Our first quarter of 2015 financial results were good. As Philippe already indicated, however, our first quarter revenue came in just below our expectations due to a couple of factors that I will review in more detail. These factors modestly adjust our full-year revenue guidance, but importantly, they did not change our full-year EPS guidance. First, our core Vulnerability Management business growth declined slightly from 20% year-over-year growth in Q4 to 19% in Q1. Since the solution still represents nearly 80% of our revenues, it did have a noticeable effect on revenue growth this quarter. However, in the first quarter of 2015, several of our larger deals came in later in the quarter than we expected.
As a result, our recognized revenues in the first quarter this year were a bit lower than we had expected. This timing difference also had an impact on our cash flow metric comparisons. In 2014, many of the earlier book deals were collected before the end of the quarter. This year, due to the later booking pattern, those deals are still in quarter-end accounts receivable and not reflected in cash flow from operations or free cash flow in the first quarter. That being said, while we came in just under our first quarter 2015 revenue guidance range, we effectively managed costs and leveraged the strength of our platform to beat our GAAP and non-GAAP EPS targets for the first quarter. Now let's review the quarter in more detail. Revenues in the first quarter grew to $37.5 million, which represented 24% growth over the first quarter of 2014.
The timing difference in bookings that we just reviewed was a factor that led to our lower Q1 revenue growth. Now a quick review of some related revenue metrics. For the first quarter, U.S. represented 70% of revenues, which is the same percentage as a year ago. Our current deferred revenue balance as of March 31st, 2015, was 23% greater than its balance as of March 31st, 2014. Finally, we derived 79% of first-quarter revenues from subscriptions to our core Vulnerability Management solution, compared to 83% in the first quarter of last year. GAAP gross profit increased by 26% to $29.5 million in the first quarter of 2015, compared to $23.5 million for the first quarter of 2014. GAAP gross margin was 79% for the first quarter of 2015, compared to 77% the same quarter last year.
Non-GAAP gross margin was 80% for the first quarter of 2015, compared to 78% in the first quarter of 2014. Adjusted EBITDA for the first quarter of 2015 increased by 156% to $12.0 million, compared to $4.7 million in the first quarter of 2014. Adjusted EBITDA as a percentage of revenues increased to 32% in the first quarter of 2015, compared with 15% in the same quarter last year. Net cash flow from operations decreased by 34% to $10.0 million, compared to $15.1 million in the first quarter of 2014. Free cash flow decreased 67% to $3.0 million, compared to $11.3 million in the first quarter of 2014. As I discussed earlier, the late timing pattern of first-quarter deals resulted in fewer dollars collected in Q1 compared to last year.
The cash flow effect of the deals still in accounts receivable had not flowed into cash flow from operations and free cash flow as of March 31st, 2015. This effect in the first quarter, cash flows can be seen in our statement of cash flows. In last year's Q1, there was a positive $6.7 million effect on cash flows from the change in accounts receivable. In this year's Q1, there's a negative $5.9 million effect on cash flows from the change in accounts receivable. We believe these effects are caused solely by timing differences and are not indicative of any change in our ability to generate cash flows from operations in 2015. In the first quarter of 2015, capital expenditures were $6.1 million, compared to $3.8 million in the first quarter last year.
In the second quarter, we expect capital expenditures to be in the range of $4.5 million-$5.5 million as we expand our cloud infrastructure to support more customers and add more solutions and functionality to our shared platforms, as well as to prepare for the increasing demand for our Private Cloud Platforms. Now moving on to earnings per share. For the first quarter of 2015, GAAP EPS was $0.08 per diluted share versus a GAAP EPS loss of $0.01 per diluted share in the first quarter of 2014. Non-GAAP EPS was $0.15 per diluted share in the first quarter of 2015, compared to $0.05 per diluted share in the first quarter of 2014. Now turning to our guidance for the second quarter of 2015 and the remainder of the year.
Since our core Vulnerability Management growth rate has moved from 20%-19%, we believe it's prudent to revise guidance for our revenue expectations for the balance of 2015. Our growth expectations for our other products are unchanged. For the second quarter, we expect revenues to be in the range of $39.5 million-$40.0 million. At the midpoint, this represents 23% growth over second quarter 2014 revenues. For the full year 2015, we now expect revenues to be in the range of $165.0 million-$166.5 million. At the midpoint, this represents 24% growth over 2014 revenues, compared to a midpoint of 26% growth of our previous 2015 revenue guidance range.
For earnings per share, we expect GAAP EPS for the second quarter of 2015 to be in the range of $0.02-$0.04. Non-GAAP EPS is expected to be in the range of $0.09-$0.11. Our second quarter EPS estimates are based on approximately 38.5 million weighted average diluted shares outstanding. For the full year, our EPS expectations are unchanged. For the full year 2015, we continue to expect GAAP EPS to be in the range of $0.22-$0.27. Non-GAAP EPS is expected to be in the range of $0.50-$0.55. Our full-year EPS estimates are based on approximately 38.4 million weighted average diluted shares outstanding.
In summary, despite the 1% reduction in our Vulnerability Management growth rate and the later booking pattern of Q1 deals, the company continues to perform strongly at the top and bottom lines, including record adjusted EBITDA and strong earnings per share growth. With a number of new product introductions in 2015, we believe that we are well-positioned to continue benefiting from our expanding product line and our land and expand strategy. With that, Philippe and I would be happy to answer any of your questions. Operator?
Thank you. Ladies and gentlemen, if you have a question at this time, please press star then one on your touch-tone telephone. If your question has been answered or you wish to remove yourself from the queue, please press the pound key. Our first question comes from Sterling Auty with J.P. Morgan. Your line is now open.
Thanks. Wanted to start with the Vulnerability Management. In terms of the deals that slipped, were these new customers or expansion deals with existing customers?
Yeah, really both, Sterling. We do a lot of business with our existing customers, constantly upselling, throughout the periods. It was included upsells from customers as well as new business.
The follow-up, I think the big question I'm already getting from people is, okay, you saw a very nice acceleration in Vulnerability Management through the height of all these data breaches, even though the rest of the business is growing as it has been and as you're expecting, should we now think that Vulnerability Management will settle back into, let's say, maybe that mid-teen growth as an industry?
No, in fact, I think it's going to be the opposite, specifically because of the announcement that we made with our cloud agent technology, which greatly simplifies Vulnerability Management, as I mentioned in my talk, by eliminating the windows, eliminating the need for authenticated scans, and also moving our application to the endpoints, which has significantly more devices than servers or desktop. I think we're extremely well-positioned for these reasons.
Philippe, maybe one last one if I can squeeze it in. The agent approach is very different than the history, the architecture of Qualys. Are there any other implementation challenges or technological challenges that customers will have to overcome to adopt?
Not at all. In fact, it's not a major difference. In fact, it's a huge simplification. The power of Qualys is still the back end that we have, which is capable of finding significant number of billions of transaction analysis, correlation, et cetera. We're in fact, even further continuing to expand the analytics capabilities of our back end. The fact here is that all of our customers have been asking us for years to be capable of scanning the endpoints, and both on Vulnerability Management and on Policy Compliance. As you may recall, we had more than 15 companies which were beta users. There's a huge pent-up demand for that technology. It's 100% compatible with the way we were doing VM and Policy Compliance in the reports and the data that we gather, so there's absolutely no change in the application that they currently have.
The only difference is that now they can, if they want to have agents on their servers, on their desktop, and as well on the endpoint, which they could not have. That's a major change with a significant operational efficiency.
Got it. Thank you.
Our next question comes from Philip Winslow with Credit Suisse. Your line is now open.
Hi. Yeah, thanks, guys. Just wanted to dig back in on the Vulnerability Management side. You mentioned both new and existing customers. Wondering if you're seeing any sort of change in just the competitive landscape there or pricing or if that's a factor at all weighing in, or is something changing as far as the buyer's mentality here and kind of to Sterling's point, just sort of the growth rate of this market?
No, the competitive landscape has not really changed except for the fact that some of our competitors are now moving into the cloud and as well as trying to move into web application scanning as well, which is a recognition, of course, of Qualys, where obviously we have a significant advance here. What we see today is more, again, if you look at the timing of things, we are more sensitive today than we were in the past because we do very big upsells. Sometimes if they come later or earlier in the quarter, it does make a difference in our revenue recognition because of the size. In the past, our business was much more a business of smaller deals, if you prefer.
When today we have essentially the opportunity to run, we are doing very, very big upsells, which change the dynamic of the business a little bit.
Got it. All right. Thanks, guys.
Our next question comes from Rob Owens with Pacific Crest Securities. Your line is now open.
Great. Thank you. I want to focus in on just the billings mix. I know you give us revenue percentage for VM, if we look at the billings and the fact that some of these deals were back-e nd weighted. Is the growth in billings relative to Vulnerability Management slowing as well, that's the reason for the caution and the taking down of a couple points of growth?
Yeah, that's correct, Rob.
Okay. Second, Don, on the sales and marketing line, it was actually down year-over-year. Was that your realization that the quarter was coming in back-end w eighted, there's some discretionary costs held off, or is this a new level? Can you help me understand why that number went down?
It's actually really simple. They moved RSA from Q1 to Q2.
Okay, perfect. Thanks, guys.
Our next question comes from Steve Ashley with Robert W. Baird. Your line is now open.
Terrific. I'd just like to start by asking about the Express Lite product and how that might have performed within the volume Vulnerability Management world this period.
Both our Express product line and the Express Lite are performing extremely well. It has been very significant, in terms of acceleration of our growth in this market. The Web Express Lite is more transaction oriented, so we're putting even more automation into that product line so we could essentially take orders online. Very successful product line.
I'd just like to ask about the go-to-market. Your sales force is now going to have a complete portfolio of other products to sell. Do you expect them to lead more with Web Application Scanning, Web Application Firewall, in the future?
Yes. In fact, what is happening here is that we have, in fact, the opportunity, especially with partners. The Web Application solution that we have done is becoming a platform, and we see significant interest in our Web Application platform or Web Application Security platform from the Indian outsourcers, which really see the opportunities to really build very powerful services, if you prefer. It's kind of another new market for us, another new entrance. Our sales force today is essentially focusing on selling the platform and in some cases, start with the Web Application Security if this is what the customer wants. The endpoint now is a totally new game because it opens up the Policy Compliance marketplace, which, as you may know, most of the big dollars were essentially at the endpoint because of the huge volume of endpoints compared to the servers.
This is where McAfee and CCS and Symantec CCS were doing bigger deals, very big deals. Today, of course, these are markets that open for us now that we have a solution for the endpoint. Which again, is significantly easier to deploy. It's only a 1 megabyte agent, does exactly the same things, and of course, reduces significantly the cost that these solutions need to manage these endpoints, as they need to have many servers inside of the enterprise just to collect the data from these endpoints where, of course, we bring all that data into our cloud platform, whether it is in private cloud and outside or whether it is in the cloud.
Great. Thank you.
Our next question comes from Erik Suppiger with JMP Securities. Your line is now open.
Thank you for taking the question. Philippe, I am still trying to get my hands around the billings. The billings were pretty strong in the quarter. I understand VM slowed a little bit more than anticipated, but clearly you must have had some pretty robust billings for the other services. If that's the scenario and you have better growth out of the other services, why are you lowering the revenue outlook? Well, answer that, please.
I think Don probably will give you a more specific answer.
Well, the basic reason, Erik, is Vulnerability Management in our core business is still 80% of our business and seeing a turn in that growth rate. Of course, we don't know what the future growth rate is. Philippe gave some reasons it could actually go back up. We don't know the next point on the graph, we certainly think it's prudent to bring our revenue guidance down since it represents the lion's share of our business. We have a lot of exciting new products coming out, but as you know, those take a while to hit and to have a positive effect and that could be later this year, early next year. We think it's prudent when 80% of our business is showing a sign of slowing, that we take that into account and do the right thing.
Yeah. Anything, the reason in the quarter why the non-Vulnerability Management billings seem to be pretty strong?
Well, those products continue to do really well.
Yeah.
Philippe went through some of them. Policy Compliance, we're seeing a lot of interest in that especially. That's an uptick. Expanded that web application security platform now to include the WAF 2.0. There's a lot of good stuff going on with our new products. Philippe touched on our Express product lines as well, which includes some of that stuff.
The reason for our prudence is also the fact that, as you know, even if we do a very big deal, it depends when these big deals, and today we are doing significant deals. It depends when they arrive because it's much, obviously, as we only take the revenues when we deliver the service. That's also the underlying reason of the prudence here.
Okay. Two other quick questions. One on the hiring. Can you give us the headcount, and how was retention in the quarter in the sales organization in particular?
Yeah. I think we started the year at about 135, and I think we added four net new folks, principally on the new business side of the house. Hopefully that'll pay dividends in the future. We're from 135 to 139. Our plan is still to see if we can add a total of 20-25 by the end of the year. We'd hope to end up at maybe 155, possibly 160.
Yeah. We have also increased our headcount in the strategic alliance group, which are managing our partners, essentially our big partners. We today have a team of five major accounts, if you prefer, or strategic accounts, dealer managers. This is also, again, because of the significance the strategic alliance that we have expanded with the Indian outsourcers . What is interesting here is that they all have essentially focused a lot of their energy in cybersecurity. They have essentially all created a division focused on cybersecurity, which happens to be in the $200 million-$300 million range already. They see that as very strategic for them. Of course, Qualys, we have a relationship with them, and we have the platform. This is something we're really expecting to see the significant differentiation partnering with them in the future.
Okay, lastly, I think you'd mentioned that you're seeing some of the competitors coming into the cloud. What were you referring to when you mentioned that?
Yeah, I make two comments, specifically, Tenable have announced essentially the fact that they want to move into the cloud, and in fact, they are looking for, from what we heard, from additional investment in capital so they could build their cloud solution. We saw recently, in fact, today, the announcement of Rapid7 acquiring NT OBJECTives on the web application scanning. It's very clear that the marketplace wants a consolidation, which Qualys has essentially already done, and the market is very now much more open to cloud delivery solution than the old enterprise software solution, which are becoming extremely costly even to maintain.
Very good. Thank you.
Our next question comes from Michael Kim with Imperial Capital. Your line is now open.
Hi, good afternoon, guys. Going back to the guidance, can you clarify the assumptions around the Continuous Monitoring for the internal networks and the potential for contribution as we exit the year and bringing the VM business above the 20% range? I have a follow-up question.
Yes. Hi, Michael. We're not going to get more granular about the calculations of our guidance. We just released Continuous Monitoring for the inside network, which I think you're alluding to, which goes on top of Continuous Monitoring for the perimeter that we did a year ago. We have a lot of customers interested in those products, hopefully they'll give us an uplift later. I can't comment on any of the specific metric we would have used for that product in particular.
Okay. Fair enough. Switching gears on the fully disconnected Private Cloud Platform, can you talk a little about the sales cycle or anticipate sales cycle? Presumably, the federal and defense markets may be a little bit longer, do you have some opportunities that might have a somewhat shorter sales cycle, especially internationally?
No, that will be a long sales cycle, this one, because really what we need to do now we have, by the way, we're very close to have our first totally disconnected solution accepted. In other words, we have now trained this entity, which is a very large German corporation, which I think I mentioned last time in the call. After that, of course, we're going to look for partners, specifically in the federal space. We have, of course, to discuss with them, selected them, and then train them, and then it takes some time to get the delivery. This will have a big impact next year. I don't anticipate much this year.
Conversely, if you look at our agent technology, the way we have priced it, I think we're expecting a significantly shorter selling cycle because we have already, for example, the contract with many of the large banks. For us to essentially provide endpoint security, we don't have to negotiate the contract. It's just about deploying this agent, which are, by the way, extremely easy to deploy. Essentially for $1 that we add, let's say on VM, we essentially are expecting to collect about $1.25, $1.30 as a comparison. As you can see, these agents bring significantly more value. As a result of that, we have been able to price them at a slightly higher value than our traditional scanning technology for both VM and Policy Compliance.
Got it. Great. Then, Don, one more real quick question for you is, did Policy Compliance and Web Application Scanning see similar growth rates north of 50%?
Yes, they did.
Okay. Great. Thank you very much.
comes from Aaron Schwartz with Macquarie. Your line is now open.
Good afternoon. Thank you. I was wondering if you could talk to sales productivity, in particular with the existing customer base. That's always been a big part of the revenue here. I'm just trying to better understand if this was just a couple larger deals that maybe the timing was a little uncertain on, and that's why you're being prudent with the guidance. Do you need to start to see productivity from some of the sales hires with new customer additions? Is the degree of difficulty in expanding VM within your installed base getting a little bit harder?
No, not really. In fact, we anticipate to expand VM significantly in our user base, with the capabilities of addressing the endpoint with our agent technology. If you look at typically the pattern for one device on the perimeter, you have about 10 device on the inside, on the service side, and you have at least 100 on the endpoint. We anticipate, in fact, that we're expanding the VM addressable marketplace for us big time. The selling cycle, we believe should be shorter. This also should help us to accelerate the displacement of existing solutions, because now we've really provided full solution for essentially Vulnerability Management, for Policy Compliance, and for Web Application Scanning. This is a huge displacement power, and we see that already happening, which in return allows us to now bid much, much bigger deals than we were doing in the past.
Okay. Don, I just want to make sure I understood correctly. Did you say that, obviously the linearity you covered, but that some of the adjustment maybe in your expectation for the VM growth rate was a couple deals that maybe just slipped out of Q1, if I heard you correctly. Have those closed at all yet?
Yes.
Well, yeah. Hopefully Philippe knows a lot more closely than I do.
Yeah. They absolutely all closed. Absolutely, we didn't lose any deal.
I guess I'm just trying to reconcile that within the expectation that billings is getting adjusted a little bit lower, if those still did close maybe in the month of April.
Well, to be fair, they closed in Q2, not Q1.
Yeah.
It's just a trickle through for the year.
Correct.
Yeah. Again, yes, right.
Okay. Just any update from the questions from last quarter about some of the shorter-term deals that you added in deferred in Q4. Have you started to see those annualized yet, or are they later in the year that you'd start to expect that?
I actually didn't study the individual deals, but the median deal would close around June 30th. We fully expect all those deals as they come up to their renewals, they've locked in a new higher level, and that'll renew. No real comment on Q1 in particular. I think most of those deals were probably Q2, Q3. It won't really show up in our numbers in particular because now we've established a new higher revenue level and those will just be renewing straight across now from the level they established when they did those upsells back in December.
Okay, thank you.
Thank you. Again, ladies and gentlemen, if you would like to ask a question, please press star then one on your touch tone telephone. Our next question comes from Matt Hedberg with RBC Capital Markets. Your line is now open.
Yeah, thanks, guys. I just wanted to ask on the geographic side. Were some of these deals that slipped, were they all U.S.-based or was it a kind of a mixture of U.S. and international?
In fact, they were essentially more U.S.-based.
Probably about the percentage of our business. We're 70% U.S.-based, Matt, that's probably a fair breakdown.
Okay. I know in the past you guys have talked about looking at M&A a little bit more from on the smaller tuck-in size, and you mentioned a competitive deal in the space recently. Could I get your updated thoughts on that with the growing cash balance?
We're actively looking effectively for acquisition. Of course, as we discussed the last earning call, we are looking at companies which essentially could either accelerate some of our product development cycles or help us move into adjacent market. We do that carefully. It's about trying to find the right company who can do that. There's a lot of enterprise security software solution on the market. This is something that we're not really interested in doing because we will have to essentially re-architect the solution and rewrite the code so we could integrate the solution into our platform. Since we have already a large customer base, and then we are going after looking at customer acquisition per se. We limit a little bit of our opportunities doing so, but we are actively looking at them.
What we see is a lot of new startup, which are all coming up with essentially a cloud architecture in mind. We see the ability to acquire younger companies much more. That will make much more sense for us.
Got it. Thanks, guys.
Thank you. I'm showing no further questions. I would now like to turn the call back to Philippe Courtot, CEO, for closing remarks.
Thank you all for joining us today. With all of our new products and features to our existing products, Qualys has never been very strategically positioned to play an important role in security and compliance market. As you all know, enterprise IT is shifting more and more to mobility and cloud architectures. Our new cloud agent platform has the potential to disrupt this market as it will allow our customers to effectively deal with this key transition in their IT environment. We already see that. We see a huge demand for that.
With the expansion of our platform and the well-received launch of the new services, we're expanding our sales force as we discussed, and partnership as well globally, accelerating the buildup of our development operation and support teams in India, which is already very successful, where we have passed, in fact, 100 people, and are looking for strategic acquisition, as we just discussed, to further accelerate the development of existing and new services as well as to enter new adjacent market. Should you have any follow-up questions, Don and I are available to you, and we look forward to speaking with you next quarter. Thank you very much.
Ladies and gentlemen, thank you for participating in today's conference. This does conclude today's program. You may all disconnect. Everyone have a great day.