Good day, everyone. Welcome to the Qualys first quarter 2019 earnings conference call. This call is being recorded. At this time, all participants are in a listen-only mode. Later, we will conduct a question and answer session. Instructions for asking a question will be given at that time. I would now like to turn the call over to Vinayak Rao, VP of Corporate Development and Investor Relations. Please go ahead, sir.
Good afternoon. Welcome to Qualys' first quarter 2019 earnings call. Joining me today to discuss our results are Philippe Courtot, our Chairman and CEO, and Melissa Fisher, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to future events or our future financial or operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and in our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today. We undertake no obligation to update statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures.
A reconciliation of GAAP to non-GAAP measures is included in today's earnings press release. As a reminder, the press release, prepared remarks, and an accompanying investor presentation with supplemental information are available on our website. With that, I'd like to turn the call over to Philippe.
Thank you, Vin. Welcome everyone to our Q1 earnings call. Melissa and I are pleased to report another good quarter in terms of revenue growth and profitability. We're also pleased to report that we continue to make great progress on our product roadmap and on our go-to-market activities, which will help us grow our solid foundation of recurring revenues and profitability. We are also very pleased to report the continuing progression of our Cloud Agents with nearly 18 million subscriptions now, more than double the subscription of a year ago. Furthermore, with the release this month of our new Qualys Gateway Service, our customers can now deploy our Cloud Agents effortlessly and cost effectively at a huge scale.
This solution eliminates the need to deploy costly proxy to secure and capture the data the Cloud Agents continuously beam up to our cloud platform, which now indexes over 3 trillion data points. With such new capabilities, it is now our strategy to make our Cloud Agents ubiquitous, because we enable our customers to consolidate a plethora of traditional enterprise agents such as Vulnerability Management, policy compliance, IOC, FIM, asset inventory, and now Patch Management that are, as we all know, extremely difficult and costly to deploy, as well as to manage. For example, a large credit monitoring service expanded this quarter its deployment of our FIM solution by over four times, effortlessly leveraging the agents they had already deployed for Vulnerability Management. Significantly, they achieved this at a fraction of the cost it would have been to deploy a traditional enterprise FIM solution.
We also see early momentum in Container Security driven by the greenfield nature of the market, as well as the unique capabilities of our cloud platform. For example, a large financial institution deployed our Container Security solution this quarter, selecting it against competing point solutions because it is natively built into our platform, and therefore provides them with full visibility across their entire hybrid environment in a single pane of view. In addition, we are also happy to announce that Microsoft Azure selected our Container Security solution for their own development teams to help with early identification and protection against vulnerabilities at scale.
These examples illustrate how we are well-positioned to expand our revenues from our growing user base, as well as to gain new customers while allowing our customers to buy at their own pace, thus minimizing churn, which is a key element behind our highly sustainable and profitable model. Now let's talk about product innovation. As we have previously shared, we are delivering on our product roadmap and have recently released for general availability the Global IT Asset Inventory Cloud app, which provides security and IT teams a single source of truth for IT assets spread across their complex and interconnected hybrid IT environment with synchronization capabilities to configuration management database, CMDBs, to keep asset data up to date.
Second, the Patch Management app, enabling IT and SecOps to quickly target critical common vulnerabilities and exposures, then deploy the patches across endpoint on-premise or cloud assets and verify remediation, all from one console. Finally, as mentioned earlier, the Qualys Gateway Service app, a major extension of our Cloud Agent platform, enabling customers to securely connect Qualys Cloud Agents from sensitive environments like DMZs, while also drastically reducing the bandwidth demands of large-scale deployment. We also continue to make good progress on other innovative solutions, including the Passive Network Sensor solution based on technology from the Nevis acquisition, which will enhance our global IT asset management offering by adding visibility of unknown assets to the existing capabilities. Which is expected to go GA early in Q3.
Second, the IOC 2.0 app, which will include a unique activity-based malware scoring to bring prioritization to malware remediation, is also expected to go GA by the end of Q2. It will bring additional threat feeds directly integrated into the platform for more comprehensive coverage of malware, IOCs, and enhance orchestration capabilities with customized alerting and integration into Splunk. Third, the secure enterprise mobility app, which extends our platform to secure visibility to mobile devices by leveraging their core technology from 1Mobility, and it's planned to go into beta during Q2. Four, the runtime Container Security app, coming from the Layered Insight acquisition, which we expect to go beta in Q3. Finally, the CloudView app 2.0, which will include threat analysis and direct remediation capabilities, which we expect to release in Q3.
As we shared at our investor event during RSA, we're currently developing a data lake solution that we expect to have in early beta in the beginning of 2020. This is an important new milestone and new opportunity for our company as current incident response solutions have become quite complex and costly, requiring organizations to use multiple vendors to collect the data needed and bring it into their SIEMs with full contextual information. Qualys' unique advantage is that we can leverage our robust, scalable backend and its array of sensors which already collect, enrich, normalize, and correlate trillions of data points across on-premise, cloud, and soon OT and IoT environments. Let me add that our product innovation has been bolstered by the successful acquisition we have made in the last two years.
We expect to continue acquiring small companies with innovative technology that can help accelerate our time to market of new solutions our cloud platform then can deliver to our customers. Now let's talk about our go-to-market initiatives. Given the increased breadth of our product suite, we have now embarked on a comprehensive go-to-market initiative leveraging the efficiency and effectiveness of our cloud platform, which allows us to deliver all of our solutions over the internet. Our go-to-market activities include, one, new targeted campaigns, which enable prospective customers to easily click and create their own trial accounts. Building a new team of Technical Account Representative, which we call TARs, Technical Account Representative, who onboard and support customers utilizing our applications. Third, developing a multi-city conference whereby organizations will speak about the digital transformation and the best practices they have learned on their journey. Finally, expanding our partnership.
We recently announced a partnership with the Center for Internet Security, CIS, whereby CIS will integrate Qualys' CertView into its Multi-State Information Sharing and Analysis Center to provide its members with building visibility of their externally facing website certificates and SSL TLS configurations. We remain very optimistic about the opportunity to increase growth in the future because our solutions offer greater visibility, accuracy, and scalability across hybrid environments, while ultimately enabling customers to reduce their overall spend. We also believe that security is at a crossroads, and that we believe the market will rapidly evolve into four segments, which will all require broad security and compliance cloud-based platforms serving different use cases. The first one, the large enterprise segment.
Only the largest enterprise have the resources to drive their own digital transformation, and they will do so by consolidating their stack and migrating application to clouds to more effectively protect their assets while achieving greater business flexibility. The second segment, the cloud provider segment. Cloud providers have all now developed a security center framework offering customers an environment in which security and compliance is already built in. Companies moving fully to the cloud via cloud providers will primarily need to worry about only their endpoints. The third segment, the next generation managed security service providers. The remaining companies will have hybrid environments, and due to a lack of in-house resources, will outsource the security to the next generation of managed security services providers.
While existing MSSPs will have to retool their existing stocks, a new generation of MSSPs is emerging to fully address the security needs of small and mid-size customers with hybrid environment. Finally, the OT and IoT environment. This is an emerging market where security must be built in, and it requires a combination of agents and passive analysis. Qualys will be providing an SDK for OT and IoT suppliers to build their own agent, and Qualys will also provide the required highly scalable cloud platform to analyze the data in real time, leveraging our forthcoming and fully integrated passive sensors. We believe that because of our cloud-based architecture and the priority we made to invest in the extensibility and capabilities of our platformQualys is one of the few companies well-positioned in the security market evolution.
Our highly scalable cloud-based platform enables us to address all four market segments, providing a single pane of glass across on-premise assets, endpoint cloud, and soon mobile OT and IoT environments. With that, I will turn the call over to Melissa to discuss our financial results. Thank you.
Thanks, Philippe, and good afternoon. Before I start, I'd like to note that except for revenue, all financial figures are non-GAAP, and growth rates are based on our comparisons to the prior year period unless stated otherwise. We're pleased with our solid Q1 results, which we believe reflect the unique value proposition of our cloud platform and its orchestrated applications. This is evidenced in the following financial and operational highlights. Revenues for the first quarter of 2019 grew 16% to $75.3 million. Platform adoption continued to increase as the percentage of enterprise customers with three or more Qualys solutions rose to 42% from 34%, and the percentage of enterprise customers with four or more Qualys solutions increased to 22% from 16%. Cloud Agent adoption increased with 17.9 million cloud agents purchased over the last 12 months, up from 16.2 million for the 12 months ended in Q4 2018.
New products released since 2015 contributed approximately 23% of total bookings in the quarter, up from 15%, and average sale size continued to increase, growing 15%. Our scalable platform model continues to drive superior margins and generate significant cash flow. Adjusted EBITDA for the first quarter of 2019 was $30.6 million, representing a 41% margin versus 38%. Normalized for software capitalization for comparability purposes, Q1 adjusted EBITDA margin would've been 40%. Q1 EPS grew 37%, and we generated strong operating cash flow for the first quarter of 2019 of $44.3 million. In Q1, we continued to invest the cash we generate from operations back into Qualys, including $9 million in capital expenditures, including principal payments under capital lease obligations, $850,000 on the acquisition of Adya, and $7.9 million to repurchase 94,090 of our outstanding shares.
We remain confident in our model, driven by our foundation of recurring revenues and expanding suite of applications. Current billings in Q1 were $85.2 million, or 23% greater. Our current billings growth rate benefited from large deals that were invoiced in Q1 this year, rather than at their anniversary in Q4 2018. As we have consistently communicated, we do not manage to quarterly billings and are focused on the long-term growth of our business. We're raising the low end of our fiscal year 2019 revenue guidance, and therefore our midpoint. Our current fiscal year 2019 revenue guidance is now a range of $320.5 million-$323 million. We are raising fiscal year 2019 non-GAAP EPS guidance from a range of $184-$189 to a range of $189-$194. For the second quarter, we expect capital expenditures to be in the range of $5.5 million-$6.5 million.
As Philippe mentioned earlier, we believe we are well-positioned in our markets given the unique nature of our integrated, highly scalable cloud platform and our strong suite of IT security and compliance applications, as well as new ones to come in 2019. Our new solutions provide us the opportunity to accelerate revenue growth as well as expand margins in the future, driven by our highly scalable model. With that, Philippe and I would be happy to answer any of your questions.
Ladies and gentlemen, at this time, if you do have a question, please press star and the number one key on your touch-tone telephone. If your question has been answered or you wish to remove yourself from the queue, please press the pound key. Our first question comes from the line of Erik Suppiger of JMP, your line is open.
Thanks for taking the question, and congratulations on a good quarter. Could you talk a little bit about the contribution from the new products? It was 23%, which is up from a year-over-year, but I think it was 26% last quarter. Can you just comment, is that going to hover around at this level, or will that continue to expand from 26 as we go forward?
Yeah, we feel good about how the new products are doing. As you mentioned, it was 23% of bookings this quarter, actually the growth rate was close to 100% year-over-year. The mix of what people buy shifts every quarter, as we've talked about in the past, it's hard to forecast by product. Given that we have new solutions coming out, we do expect that to expand over time.
Okay. Philippe, some of your comments talking about the Cloud Agent, you're making that ubiquitous. Can you talk a little bit about what you're doing to make it more ubiquitous? Are you doing anything in terms of the go-to-market with that or in terms of pricing?
It's more in terms of go-to-market rather than the pricing. I think our pricing is very fine. As I mentioned on the full market, I was aligning, you have two of them, which I believe are more like what you could call OEMs, which is all about building the agent in, namely the cloud providers as well as the OT and IoT devices. Again, we are coming up with an SDK, companies could build their own agent. At the end of the day, the agent doesn't do much. That's the beauty of our architecture. The agents capture data continuously and beams that data up to the platform for correlations. In addition, our agent is also now moving into the response, which is very important, and that you see that with Patch Management.
We have so many angles today that now we can penetrate the marketplace through many different segments. That's really the way you reach ubiquity. Either you have one single solution, which is broadly for everybody, then of course, you push it. As you package it, in our case, we see this whole market as absolutely the agents are critical. They need slightly different packaging, that's what we do from an engineering and pricing in that sense or terms. Again, we feel very well-positioned, with our agent, where now they are at huge scale. We're going to make future announcements of more partnerships around the agents.
Very good. Thank you very much.
Thank you. Our next question comes from the line of Alex Henderson of Needham. Your line is open.
Thanks. I was hoping you could talk a little bit about the amount of traffic you're planning on sending up to the data lake and to what extent your agents are able to minimize some of that processing by smartly determining what's relevant, what's not relevant, or whether it's sending all of the content up, in which case, do you run into traffic volume issues on your customers' networks as they beam that traffic up to your cloud? It seems like a lot of data relative to some of the other companies we've talked to relative to efficacy. Thanks.
No, that's in fact, this is a very good question. In fact, the beauty of our agent architecture is that because we only beam up changes, the amount of data that we have to beam up is significantly reduced than if we were continuously to beam up that data itself. We have significantly less than other solutions in our approach. This being said, the issue is not so much about the traffic. We don't see any issue with the traffic itself. The issue is with your capacity to under correlate, enrich, analyze that huge amount of data that at the end of the day, we have.
To give you an idea of our current back-end, about a year and a half ago, we had index on our Elasticsearch clusters about, see if I recall correctly, but the number is around about 600 million data points, and now we're under 3 trillion, about a year and a half later. You need to have the back end, and that's where your traditional enterprise solution, obviously, they don't work anymore, and you need to have this kind of a cloud back end, highly extensible. To answer now your question about the data lake, that's exactly why we're moving into the data lake. On one hand, we capture the data very well.
The problem that the current SIEMs have is that for them to bring the data into their SIEMs, they need to take multiple solutions, inject the data into their SIEMs, which costs a fortune, do all the correlation, all the analysis, et cetera, themselves. When for us, our agents and our forthcoming passive scanning bring all that information. Qualys does the cooking, the normalization, everything. Then, of course, the question becomes, now you have significant amount of data, and how do you also communicate with other data lakes, to essentially bring the next generation of SIEM solution, which is exactly what we're working on. Stay tuned. We are going to communicate a bit more about where we are on the progress with that data lake. It's going very well. We have now four design partners, which are companies, which are helping us design that the correct way.
We are very, very bullish about it, and it's a very natural extension, again, of our platform.
If I could just extend that question a little bit. The data lake is then correlating in the metadata cloud above it. Can you just remind us how that works?
Yes. That's something, what I would like to do is to push that maybe to another day where we could have, in fact, probably at our next analyst conference, I think that would be the time where we could go into the architecture of our data lake and its scalability. At the last investor event, we did mention about the architecture, about some of the questions that we had, because now you handle data. Almost every large company today is building their own data lake. Of course, in our approach, we will also communicate where the data lake that they create, because the amount of data becomes significant. It's about the storage, about many other aspects. That's a much deeper conversation that our Chief Product Officer, Sumedh, would be very happy, and I think a good subject for our next analyst day.
By that time, we'll have our architecture pretty well-defined.
Okay, great. Thank you.
Thank you. Our next question comes from the line of Robert Breza of Northland Capital Markets. Your line is open.
Hi. Thanks for taking my questions in a solid quarter. Melissa, just to put it into context, when you talk about customers coming in and taking more than one product per se, if you look at that, if I came in today and I bought all the products, how much is that approximately, give or take 10%?
Well, thanks, Rob. It really depends on the size of your environment. I think a good way to think about it is, what we have said is, this includes a few things that aren't yet released, but if someone were to buy all of the solutions that we've talked about that are either recently released or are coming out, including with passive scanning, et cetera, their spend would be 10 times out of a $1 VM. I think that's the way you should think about what the potential spend could be.
Got you. That makes sense. That's very helpful. When you think about the overall demand market out there, I think Philippe touched on it in his prepared remarks with IoT being kind of a growth category, I guess from an industry perspective, I still think of IoT as early stages in the industry, yet the fact that they're thinking about security seems like they're a little bit ahead of the curve. Am I thinking about that correctly, or how are you thinking about that industry trend within that marketplace?
No, I think, Rob, you're in fact very correct because, yes, it's an emerging market, yes, again, this is the opportunity for these companies to think about security and instead of bolting security on after the fact, now this is, of course, they see very clearly, especially because of the amount of devices that you have to deal with, that building security in it's absolutely paramount. You need three elements to do that. One is you need preferably an agent. You cannot put always an agent everywhere, but if you can put an agent, that's absolutely the way to go.
You need also to have the passive scanning, which then you can look at what's coming in and out of these devices, so you can analyze the traffic, so you could detect suspicious activity or malfunctions, which is also important because here in that new environment, you've got both IT, security, and compliance, which all have to be fused into one single solution. Finally, you need to have the platform to absorb all of that. That platform needs to have the scalability, but also needs to be very portable. That's one of the reason why we, by the way, containerize our platform. We have not totally done, but let's say we're 70% there. When having containerized our platform, we can deliver it anywhere, whether it's on a Google cloud, whether it's on Amazon cloud, Azure cloud, whether it's on your own private cloud.
Our platform has become very portable. Let me remind you that we have today more than 80 private clouds today, which are functioning around the world. That's what I mentioned, in my remarks that we think we're extremely well-positioned to be a major actor in that market. However, this being said, this is an emerging market as you just pointed out.
Thank you very much.
Thank you. Our next question comes from the line of Daniel Ives of Wedbush. Your line is open.
Yeah, thanks. In terms of Azure deals or just large sort of deals in that channel, are you starting to see, without getting into specific details of the pipeline, more strategic deals, just larger deals come through, maybe companies with a different sense going into 2019 in terms of budgets for this technology than maybe 2018, Philippe?
You meant, to make sure that I understood the question, is that you mean, with the cloud platforms like Azure?
Yeah. Mm-hmm.
I think we have a very different view than you could see. We see these platforms as fantastic platforms to deliver solution software. Like our platform is, of course, the platform to deliver software across, I would almost say, soon the universe, if we continue with the pace of innovation. Essentially, we see security in that environment as more security being built in, because if not, that's really what you want to do. Then there could be also delivery solutions, to essentially deliver security solutions. At the end of the day, there is many other ways of doing that. I don't see them as primarily the vehicle for delivering security solution. We see them conversely at places where we can embed our security solution and essentially making security totally transparent. That's what we've done already very much with Azure.
I just mentioned also that we are now moving also with on containers, That's the way we see the market. It's all about building security in, That's again, where our agents are very unique because they fit. We have some of these large cloud providers, as you may remember, or all of them, in fact, are customers of Qualys, and they use our agent technology to in fact ensure the security of their own platform. Now it's about putting and embedding our agents on the top. We could now provide the same capabilities for the applications and the environment of their customers. That's the view we have. Very different market than essentially, again, you cannot build in. It doesn't make any sense.
Microsoft showed the way very well with their security center, which now have been copied essentially by Google, which create an environment where embedding the security into their infrastructure, into their solution becomes significantly easier, as long as you have the right architecture, of course. You could not take an enterprise software and put it inside. Does that make sense?
Yeah, totally. In terms of the platform today and even newer solutions, how penetrated do you think typical Qualys customer is today?
We have, in fact, published the data. In fact, we see continued adoption of our solution, and Melissa will remind us the exact numbers, because I'm always wrong by one or 10%. I think she's got it right, not me. What is significant for us is for a few things. One, it's fantastic for our customers because they can, one, reduce their spend because everything is centrally managed, everything is self-updating. The second thing, they increase their visibility. That's what is in it for our customers. What is in it for us is that, of course, we have significantly more retention from these customers because if I recall again correctly, customers which have now four solutions, the gross retention rate is 99%. Today we have, Melissa, how many customers now today have four solutions or more?
42% of our enterprise.
42% of our enterprise. Of course, now we're looking at five, and then we're going to look at six and seven and eight, et cetera. I think that's the power of the model that we have created. It starts with a platform. We spend significant amount of time and energy. I remind you that now today we have about 700 people in our offices in Pune, India, which are essentially engineering, QA, customer support and production and engineering, of course, a significant pool of talent that we have there. Then, of course, is building this application on the top of it.
Yeah. To just add on, Dan, I think our view is that the penetration is rather low relative to what it could be. Let me give you a few specific examples. For example, when you even think about VM, which is the longest or most tenured product for the company, it's still very early in terms of deployment on the endpoint. Companies have many more endpoints than they do servers, so that'd be very low penetration for us. The Cloud Agent itself is only in 18% of customers. Again, still significant opportunity there. Then on the multi-product statistics we talked about, we feel good about the progress we're making, but when you think about the metric of enterprise customers with five or more solutions, we're only at 11%, and we have easily more than 10 applications that customers could have.
We would say the opportunity is very large relative to where we are currently penetrated.
Yeah. Very insightful and a great quarter. Thanks.
Thank you.
Thank you. Our next question comes from the line of Howard Smith of First Analysis. Your line is open.
Yes. Thank you. Congratulations on a strong start for the year. My first question deals with the Technical Account Representatives or TARs, as you call them. Maybe a little more about that. Is that replacing the current customer service onboarding team or is it augmentation or what's kind of changed or added here to what you're currently doing?
Very good question. This is my favorite subject. Designing scalable delivery model essentially. What we're doing here is a part of this campaign that we have now already started. We are packaging our solutions so they could be easily, not only easily they can be distributed, but easily consumable. For example, today, we very reliably, in few weeks, we're going to launch a repackaged version, not a special, a repackaged version of our CertView, which is that free service allowing you to discover all of your digital certificates on all of your internet-facing devices, as well as the security of the SSL, et cetera, implementation. Currently today, the way we do that, we do a campaign, you click on a link, and then you request a trial, and then you are now on the Qualys application, and then you have to configure everything yourself.
In this new campaign that we are designing, it's going to be different. Let me explain. One, you click on the link or on the link on the email or on the banner ad, and immediately you're going to be directed with a place where you can automatically create your own account. You have nothing really to do. The only thing you will have to do is to put your domain names, and then we'll have dynamic dashboards already pre-populated, prepared for you. As we collect the data, you have all the results. That's what I meant by absolutely immediately consumable information. You have nothing to do. You just click on the link, create the account automatically, essentially, and then the data becomes populated automatically for you, and you have your results.
In parallel, what we have is what we call the TARs, which is another category, Technical Account Representative. Today, our technical people, essentially we're building the team in Pune again in India. Which would take young people from the technical schools, highly technical, and their job is not going to sell. It's going to ensure that if these people have questions, we have now essentially a bot agent, which is coming, which we call Mr. Q. Mr. Q will come, and behind you have this Technical Account Representative, which are going to help you, if needed, onboard you, answering all the questions you have when you try the product. As you can see, this is all to increase the velocity. We're taking all of our solutions today, and we're going through that packaging.
That's the bottom-up approach that we're making to make now people aware of all the solutions that we have for them. We are, as I mentioned in my prepared remark, embarking also preparing to do a top-down campaign, which is now to go more to the CIO and the CSOs and explain to them the power of the cloud platform. This is the combination of the two. I didn't want to do that early because we needed to have a platform, the scalability, all these applications. Our philosophy has been always, we all know it's not good enough to be good, you need to tell, but you better tell when you have something to tell, rather than go and create all that, unfortunately, vaporware that we are hearing so much in our industry.
That's very helpful color. Thank you for that. Maybe for you, Melissa, although Philippe, you can chime in if you want. The expense management continues to be very good. I'm just curious where you are on your hiring and maybe marketing spend relative to kind of your own internal plan.
I think we feel very good. Obviously, our performance this quarter reflects what a scalable model we have, and we benefited both from the beat on the top line as well as, we did have lower headcount expense across a number of areas from a variety of factors, people getting hired later in the quarter, hires being done in India, some positions where we haven't found the right person yet. We do believe that our EBITDA margins now will come closer for the year to roughly 38%-38.5% versus what we originally provided on the Q4 earnings call of 37%-38%. We do expect benefit for the year.
I may add something here is that we have been, since the very beginning, and this is something I mentioned quite a few times, we have really put a huge effort to understand the scalability that the cloud model offers you, and also of the advantage of having a pure subscription model, which in fact is in a way more predictable. We know our revenues ahead pretty well, so we could manage our expenses as a result significantly better. On the other hand, if we would add a mix, like many others, of having a mixture of recurring revenues and perpetual, it's absolutely fascinating, and I just went through the exercise very recently, is that if we were to take 5% and only 5% of our recurring revenues today and turn them into perpetual license, it will have absolutely incredible effects on our numbers.
For example, we will come from 11% earning growth to 35%, 36% earning growth. Our revenues will go to 26%. You realize that if you do the reverse and take some of these other companies which have essentially a mix of perpetual license, if you will be moving them back as recurring, purely recurring revenues, it will have exactly the opposite effect. Their losses will be bigger, and of course, their revenues will be significantly lower as well. The reason why I'm making that point, answering your question is because the model, in fact, that we had allowed us to have since the very beginning, a very disciplined approach to our expenses and not try to go to be ahead of ourselves, because that's essentially the price you've got to pay to have such a recurrent and highly profitable model.
That's something people want to think about because that's very unique to Qualys.
Great. Appreciate the color. Thank you.
Thank you. The next question comes from the line of Melissa Franchi of Morgan Stanley. Your line is open.
Thanks for taking my question, and good afternoon. Philippe, the 23% of bookings coming from the new products, I think previously you had said that it's mostly Cloud Agent and maybe threat protection. I'm just wondering if that's still the case or if you're starting to see some contribution from the new products may be released in the past 12 months in 2018.
It's starting to vary, but it's about the same still. However, we can see that the changes are taking place. For example, we mentioned earlier that the FIM, we can see today now the FIM is getting maturity. We still need to add two more features, essentially, to make the FIM solution totally complete, which are essentially the alerting, which we don't have yet. We have the APIs now, the alerting. It's some kind of reporting that we need to tune for certain regulations and so forth. We see the traction. We see people now starting to deploy FIM at a much larger scale. Remember, again, one of the things which requires for us to be patient is that typically, as we mentioned, our customers, what do they do?
They evaluate the product, and then after that, they do a first small deployment, and then they finally deploy. It takes time. FIM is really starting to take off. Also mention that the Container Security, which is a hot market. Containers. We see very good success. Again, this is early days, so in terms of, they don't move the needle yet, but we could see them coming.
Okay. That's great. I just wanted to follow up with Melissa on the commentary on EBITDA margins for this year. You noted that there was slower hiring, I guess, in Q1. Is that just a timing dynamic, or are you maybe seeing better-than-expected productivity out of your sales force such that you can maybe moderate your plans for sales investments?
Yes, let me answer that with a couple of points. First of all, it was really a variety of factors. I think some of what I talked about was people just getting hired later, hires that are in India, because it's not just about sales and marketing, it's also R&D and operations. On the sales and marketing front, I think as Philippe had said earlier, we're very happy with the sales force. Remember, we're using our platform, we're leveraging it as a distribution channel. Our model is not just about adding heads and pushing product onto customers. We are looking to add, in the area of sales, a few new people focused on new business who have a solution-selling background, and that'll be our area of focus.
Okay. Thank you very much.
Thank you. Our next question comes from the line of Garrett Talburt of Stifel. Your line is open.
Great. Thanks for taking my questions. Philippe, could you give us some color in terms of customer interest in doing full VM lifecycle management? Meaning, you're the only vendor right now that can go from device discovery all the way to patch, including inventory. It's a pretty broad roadmap and a pretty broad product set. What kind of response do you get from customers these days when you sort of approach them with that more end-to-end focus that you have?
Oh, the response, I mean, this is something we knew. It's not new for us, the demand from the customer. That has always been there. The issue is that we needed to do it. Again, to do that at the scale, you have so many variables to put all that together. It's absolutely something that I think we see a very big demand for our customers, as well as we see a significant opportunity, and this is coming from our customers as well, to integrate with ServiceNow, their VR solution, which in fact is the other side of the trouble ticketing and so forth. Obviously, our customers are asking us to do further integration, so now suddenly you have an environment that you have really then the full vulnerability management cycle.
Okay. That's very important for large companies as well, as well as for small companies, because they are different issues. The small company, they don't have the resources. They want more automation, more things already available or totally packaged. The large companies, of course, they have the complexity of that hybrid environment, and especially these critical vulnerabilities that they need to fix pretty fast. These are the two dynamics, and I think the packaging that we've done, again, packaging, it's easy to say, but it's not something easy to do. I think we're really very happy with that. Very big response. Let's put that like that. Again, we're still at the beginning, same story again. They are doing evaluations, then they're going to do a smaller deployment, and then the bigger deployment.
Okay. That's helpful. Then in the transcript, you noted interest in maybe doing other small acquisitions. Could you maybe expand on that a little bit and give us some color as to where you might be looking to augment the current strategy?
Two things. One, I think we have really established a significant image in India, which now we see companies coming to us in India because as I mentioned, I think in some other talks, is that while the Israelis have fantastic technology, and have learned how to really bring that technology to the U.S., for some reasons, in fact, I think I said to myself, I need to understand the reason why, that will be for another discussion. I think I find the reasons why India was not able to do what the Israelis done. There were a lot of companies there which have very good technology. Of course, there's a lot of good engineers there, they could not really bring them to the U.S. as well as Israelis did a fantastic job, in fact, at doing so.
For us, that's a godsend because they come to us now for acquisitions. They come to us, we don't have to go to them, which is of course very different. We are currently in discussion with quite a few of them in India as well, which have the advantage, of course, of having essentially significant lower cost of acquisition than if we were doing that in the U.S., but as well as more loyalty, if you prefer, because then we represent a very good company there for them essentially to join the company. That's thanks to the effort we make like now, 10 years ago, about 12 years ago, of selecting Pune and really making a big investment. Let me remind you, we're also going to move early next year in Pune into a new campus where we could have up to 2,500 people.
We currently have 700 people. We see, of course, that very significant. We're still also entertaining companies in the U.S., and we see more and more of these feature companies, as we call them, which are now put on the block by their investors, except that they really want big multiples, we're not ready for that, to be quite candid.
That's really helpful. Thank you for that.
Thank you. Our next question comes from the line of Matthew Hedberg of RBC Capital Markets. Your line is open.
Thanks, guys, for taking my questions. As a follow-up to an earlier question on your sales force, Melissa, you mentioned you're looking to hire a few more solutions expert. I'm wondering, though, when you kind of step back and take an even broader view and thinking about scaling the business to a half a billion and beyond, are there additional things that need to be done to kind of your hunter farmer strategy, as you think about if you need to ramp multi-product sales?
I'll start, and Philippe will join in. The background behind the focus around these new business sales people is really about, as I mentioned, people who have consultative selling backgrounds. That's because as we have so much more to sell from the platform, we want to sell more top-down. We've traditionally sold more bottoms up. I think, our view is that represents kind of the evolution of us becoming a much more strategic sale, people buying more solutions from us, which will then significantly add to the revenues.
Yes, if I could add to what Melissa said, is that we have done already some restructuring in our model, which essentially on the post-sales side, on the renewal people, we have now these MASA, we call them, the Major Account Solution Architects, and that is working very well. We have essentially promoted some of our best technical account managers to take on that role, which is essentially having less accounts to manage, but bigger accounts we can grow significantly well above the multimillion-dollar accounts. That already has well progressed. As Melissa mentioned, on the new business side, we're also expanding to have people who know how to sell to the C-suite. We still want them technical. That's a very big difference between us and most of our competitors.
As we just discussed earlier about these TARs, as we call them now, which is more for the high velocity, lead generation business or an SME, SMB, which is a much higher velocity business. Well, as you can see, I've tuned our model to answer. Then there's another component which we are now investing as well, which is the strategic alliance group, where we have a fantastic VP, which has been with Qualys for a while, now we're establishing a lot of partnership. This is more on the OEM side that I mentioned earlier, starting to really discuss about embedding the Qualys technology into other solutions, which we will make some announcement relatively soon, we hope.
Great. Maybe just a quick one for Melissa. I appreciate the color in calling out some of the Q4 deals that closed this quarter. I'm curious if you can provide a little bit more color, maybe in terms of how many deals or perhaps the $ value, and then maybe just more holistically as these multi-product sales increase, can you put a little bit more color around the large deal pipeline in general, versus, say, this time last year?
I'll take the first part, and I'll let Philippe handle the second part. It's really hard to perfectly normalize what billings would be because there's really multiple scenarios where renewals are not done at the same time as the initial deal because we're not managing to quarterly billing. We share the fact that we moved some large deals in collaboration with our customers from Q4 into Q1, and it was a benefit to our Q1 billings because since we've shared when large deals slip and negatively impact billings, we think it's appropriate to share when we see the positive impact. As I said, because of the constant movement, and the fact that we're not managing to quarterly billings, this is why we believe the trajectory of our annual revenue guidance is really the best proxy for business momentum because our current bookings inform our guidance.
I will add to what Melissa said, two things. One, when we say we're not managing our billings, another way of saying it is to say, we are not pushing customers to do big deals and say all you can eat type of deals, bring the things upfront. We let the customer, essentially, we follow the pace of the customer. Sometimes some customers, they want to realign their renewal time. They say, "Okay, we'd like to renew only for three months, but then we'll do a three-year contract later on." We let that happen. We don't try to really push anything onto our customers. We follow them. That's why these billings, if you prefer, are very different. It's almost impossible, if you prefer, to normalize them. It doesn't really affect the revenues at the end. That's the key point here.
It's not about revenues; it's more about billings. Now, the second thing, fundamentally, is that if you look at our large deals. We mentioned, I think, on our earnings presentation that we have, in fact, we could see the large deals are expanding very nicely. We are now into having more and more customers having multimillion-$ deals. You realize that it makes us very sticky. We can sell them more solution. We're becoming more strategic. We still are not pushing deals. What I'm hearing these companies, some of our other companies, they do this $10 million deal, et cetera. We could do that. We don't want. We don't want because fundamentally that will go against our model of trying to avoid absolutely the down-sell. If we sell to a customer more than what they can take, guess what will happen?
Remember, we are 100% renewal base. They will not renew for that amount. How are we going to compensate? Trying to shove it onto other customers. That's not a healthy model. In the enterprise software, which is perpetual license, as long as you have big enough of a market, you can do that for a certain long period of time. With Qualys, the average length of our contracts are 1.1 years. If we were playing these games, we would see the pain pretty quickly. Of course, that's why we are not doing it. Does that make sense?
It does. Thanks a lot, guys.
Just to put some numbers around it, there's a slide in our investor deck to something that we monitor, which is customers with greater than $500,000 of revenues. The number is, I think, 75. It's up 32% year-over-year. We feel good about our customers growing with us.
Thank you.
Thank you. Our next question comes from the line of Joshua Tilton of Berenberg. Your line is open.
Hi. Thanks for taking my questions. In regards to the Cloud Agent gateway, it seems like this will allow you to leverage the agents with operational technology. From my understanding, I thought Passive Network Sensor was to be used for OT, could you maybe explain how these two will work together?
Yes. You're right. One of the things that Cloud Agent is a proxy. Now, this is nothing new in terms of technology. What we've done here is that companies have already proxied. The problem with the proxies is that they are very expensive. You're speaking about $100,000, also they are managed by IT. Then you would have to build the security into it, et cetera. At the demand of our customers, which were starting to deploy the agent more and more, they say, "Guys, we need a much easier solution." We created a kind of a proxy ourselves, well-packaged, totally secure, high availability, and we price it extremely attractively. On the virtual side, it's slightly less than $1,000 per year. That will absolutely allow us to deploy the agent much more better and more broadly.
Now, as far as OT and IoT are concerned, on the OT environment, most likely you cannot really put agent. The only person who can really put agent, if you can put an agent, are the vendors themselves, and same thing on the IoT. That's why we have introduced, we have already, or we will introduce, we have already an SDK, but we have not really published it. We will be publishing an SDK. Now the vendor of these devices can build the agent, which is pretty easy. Remember, it's only a three-megabyte agent that we have currently today, which only essentially takes the data and beams it up.
Of course, the big advantage of we have the platform again, that we can distribute or deliver as the customer wants, as that IoT vendor wants, or either in a cloud environment, wherever you like. That's where that combination and full integration of, on one hand, that Qualys Gateway Service, the fact that we have an SDK and the fact that we have a Cloud Agent, or the fact that we have the passive scanning and the fact that we've got a platform. You realize this significant barrier to entry we have created for ourself, and by the way, we've been working at that since quite a long time. It's not by accident that all these pieces are coming together.
Okay, that's helpful. Just real quick, maybe sticking with operational technology, it seems like the spend on securing these environments is still relatively low, even though we keep hearing more about OT/IT convergence. I'm just wondering, what is the catalyst needed for your customers to increase spend on securing their OT environments?
I think today, as you very well said, I think this is a very small market, we have already large customers which already have, in fact, that requirement. We're working with some of the car manufacturer, and others, we're working with them so they could have greater visibility, what they are looking at in these environments. It's just a question of, again, you need to get the technology well mature, well packaged, etcetera, and it has to be built-in. You cannot really go and say, "Okay, we're going to discover all your things after the fact." That was the nightmare of the enterprise software and all these new environments. When everything connects almost directly to the internet, unless you're on air-gapped network, which is another challenge, which by the way, we're also resolving as well, but that's another discussion.
To me, a lot of people make a lot of noise about that market. I think it's going to take some time for that market to mature, and it will require a lot of packaging from company like ours. I think in having the right architecture. We feel well-positioned, but again, one by one, we're going to do and have more of these solutions, with some our existing customers or new customers who really wants to work with us, so we could help them to build security into their environment.
Thank you very much.
I could give you, by the way, one example. There's one of our customers today that will explain to you, which has the fulfillment center, which are fully automated with a lot of robots. They have absolutely the full view of their entire inventory of things that they sell across the internet, essentially. They have absolutely not the view they would like to have on all these kind of OT devices which are there, which are absolutely fundamental to their fulfillment centers. Of course, their worst nightmare to say, "What if some kind of malware comes into it and cripple us?" They will not be delivering. You realize the impact. But again, it's easy to talk about it. It's another thing of really doing the right things so you can gain that visibility and then, essentially ensure that everything is properly secured.
That's a lot of work.
Thank you. Our next question comes from the line of Sterling Auty of J.P. Morgan. Your line is open.
Thanks. Hi, guys. Just one question. I just want to connect the dots. When you set the guidance for revenue for 2019, you talked about the time needed to get the new products out, get them in front of customers, get them to understand it and ramp. If I look at the sales and marketing line drove a pretty big part of the beat relative to, I think, consensus on our estimates. Is that connected where you're just waiting until certain milestones on the development front to step on the gas on marketing to drive those products, or are those two unrelated?
It's very unrelated, and it's more according to your model than to ours in many ways, Sterling. For us, I think we're pretty much in line to where we were. As you know, we fundamentally continue our business, and we believe we're going to get accelerated growth. I wish it would come earlier, but, as I made the mention earlier about the fact that we don't have any perpetual license, which would essentially, we could throw on the top of what we do and look much, much better. At the end of the day, I would say that not all growth are made equal. You have the good growth, which is ours, and you have other growth, which are more essentially pumped, if I may say so. For us, this is our model, so everything is coherent here.
Maybe just to add on to that. Think about what we've talked about in the past is that, many of our salespeople will double their accounts. You don't need two salespeople to do that. The acceleration that'll come as people are adopting more solutions isn't going to necessarily be tied to the expense of the sales and marketing.
On the top of that, we don't want, and that sounds absolutely an heresy for some others, we don't want to incentivize our sales force to create bigger deals than what the customer can take. Even on the new business side, we have the tendency of taking the customers young, as we call it, and then growing them, which is significantly more cost effective, it's better for the customers, and ultimately, it's better for us. That's our model.
Understood. Thank you, guys.
Okay. Thank you.
Thanks.
Thanks. Our next question is on the line of Patrick Colville of Arete Research. Your line is open.
Thank you for taking my question. Can I just ask you about the market in aggregate? If I look at your growth, the growth of Tenable, the growth of Rapid7, the vulnerability management market looks very buoyant, and I'd love to know what you see driving that and, just any color or insight as to where you think it could go over the coming periods, which would be great.
As I mentioned earlier, I think we believe that the Vulnerability Management market is healthy. It's very healthy, and it's growing. I follow the numbers of IDC, which are more in the low teens. I know that some other people make it like it's a marketplace which is accelerating. When you look again, I mentioned that not all growth are created equal. You can really pump your numbers with a perpetual license pretty easily, when you are essentially recurrent, like we are subscription-based. Of course, it's different. In a way, if we would take the present value of our recurring revenues, we would be significant, dwarfing everybody in that market because you multiply our current revenues by 2.7 and then you have the present value. It's significantly bigger than any of our closest competitors.
That's what people lose the perspective on it. As I was mentioning earlier that if we were just taking 5% of our revenues and turn them into perpetual license, which we could do in a beat, suddenly we'd be growing at 26%. Our profitability will go through the roof because we'll add $25 million to the bottom line. Today, sometime people say, "Guys, you're too profitable." Oh, my God. We'll be extremely profitable. You're comparing here apples with oranges at the end of the day. I think the marketplace is very healthy. Again, it's not a marketplace which suddenly is going to go or deal to the roof. We don't buy that. I think low teens is very reasonable, and that's what we see. Now, what about the market of the IoT/OT devices?
Yes, you could say there's 50 million devices, but how much are you going to be able to get? Yes, this is future growth for that market, but it's going to take time. We don't see the revenues coming anytime soon on the OT and IoT front. It's going to take a few years.
Understood. Can I just ask a very quick follow-up on the, kind of on-premise vulnerability scanner? Why would an enterprise use an on-premise tool versus a cloud-based tool? What are the kind of main advantages of that deployment model?
No, there is no advantages at all on the on-premise solution. I will tell you why. The problem with the on-premise solution is the architecture of this on-premise system, you are limited by the database you have, you are limited by a lot of factors inherent to the client-server architecture. The cloud really gives you a different architecture, and which give you more scalability, et cetera. You have no interest whatsoever today when you have, in fact, a hybrid environment, you have more devices, more things. You are not just there to do your critical servers. You have to do it all to go to an enterprise model. Why are people not moving very fast? You have the people which are managing these services, they don't want to lose their job.
When we replaced McAfee in one of their large customers in a bank, they could relocate 15 FTEs. Needless to say, these FTEs were the ones doing the evaluation of the replacement, and they didn't recommend our solutions because they could see pretty quickly that their job was in question. These are the natural resistance to change that you see, of course. You still have in some time orbit. What we did very uniquely and very successfully is to take our cloud architecture and to turn it into a private cloud. Now you can have all the benefits of the cloud architecture, but then delivered on-premise. Today, we are also looking, and in fact, we've done one successful installation to even push that model into an air-gapped network.
We could still be capable of going into this air -gapped network where you don't have any access to the Internet, and yet provide those customers with the scalability that a cloud architecture provides you.
Got it. Thank you very much, Philippe and Melissa, for taking my questions. Thank you.
Thank you. That does conclude our question and answer session for today. I'd like to turn the conference back over to Mr. Vinayak Rao for the closing remarks.
Thank you all for attending our first quarter 2019 earnings call. We look forward to seeing you later this month at the Jefferies Software Conference in Los Angeles and J.P. Morgan Global TMT Conference in Boston. We'll also be at Bank of America Merrill Lynch Global Technology Conference in San Francisco and Baird Global Consumer Technology and Services Conference in New York in June. Thank you.
Thank you. Ladies and gentlemen, thank you for your participation in today's conference. This does conclude the program. You may now disconnect. Everyone have a great day.