All right. Good morning, folks. We're going to get started in the interest of time. We have the pleasure to have Bipul Sinha, CEO of Rubrik, here this morning. Welcome back to the conference, Bipul.
Thanks, Matt.
All right. Well, let's get started. Bipul, you've called this a singularity moment for AI and cybersecurity. As enterprises become increasingly reliant on AI systems and autonomous agents, what do you think changes most about the way organizations think about risk and resilience?
We have been talking about this for the last many years, that prevention and detection is not sufficient. Folks have to really think about recovery and resilience because you can't prevent the unpreventable. What Mythos and frontier models have shown is that you can't really prevent and detect anything because these attacks are at machine speed, and at machine speed, you can't prevent. All the technologies that we have built for cyber in the last 20, 30 years was built for human operator and human attackers. We are in a completely different era. This is a new moment, and all you can do is to think about how do you patch your systems at machine speed, and how do you deliver cyber recovery at machine speed. That's what Rubrik is solving for our customers, doing a cyber recovery at machine speed.
Okay. Even over the last two years, I think Rubrik started with backup. You evolved into cyber resilience, and now you talk about security and AI operations. When you connect those dots, what do you ultimately want Rubrik to become? Three years from now, what do you think customers will be buying from Rubrik that they are largely not buying today?
Our goal is to deliver resilience to every aspect of operations. What are the different things we do? Number one is data. We want to ensure that your data is recovered and your applications are up and running. Number two is identity, because we want to ensure that the data risk comes from identity, and identity systems are up and running, and they are in the correct state. Then the third piece is AI. As we know, agents assume identity and operate on sensitive data. So you need to have resilience and security for agents. How do we ensure that agents are only taking the right actions? If they do bad action, how do we rewind the action of agents? We are very clear. There are two major trends in the market, AI and cybersecurity. Underneath AI and cybersecurity is identity and data.
We want to deliver complete cyber resilience across data identity and agentic world.
Okay. You talked about prevention and detection alone not being enough. I think you have been very consistent in that message. If attacks are becoming increasingly autonomous and continuous, what does the security architecture ultimately look like on the other side of that shift, and where does Rubrik sit within that architecture?
In my mind, since attacks are going to be at machine speed, it will be a world of continuous attacks. Today, operations and cyber are two different teams and two different things inside any business. I believe that these two, operations and security, will merge. You will have a situation of continuous attack and continuous recovery and continuous patching. In this world of continuous attack and continuous patching, you need to have a human in the loop at the very minimum level, where the humans are making decision, but machines are implementing decisions. This is where the cyber is going to go. It is going to be a world of no human in the loop patching, mostly no human in the loop recovery.
Let us pull that into the most recent quarter. Net new ARR accelerated to 35%. You raised the full year guide. I guess a two-parter here. One is what felt different in the business this quarter. I guess if we dovetail off of the previous question, are you seeing Rubrik sort of increase in relevance within sort of the security budget more broadly? How is that shaping customer conversations today, even relative to a year ago?
If you think about this idea of Mythos and frontier AI and machine speed, businesses, particularly board and CEOs, are realizing more and more that cyber has gone from a technology discussion, whether it is endpoint network, cloud, zero trust network, all of that mumbo jumbo, to a risk discussion. That can we keep our business up and running? What is our dollar at risk should we go down for a day or two or three? Do we have a situation where my large manufacturing will come to a screeching halt just because of the ransomware attack or cyber attacks? That is the discussion now. Rubrik plays in that discussion because we are giving assurance to our customers, saying, no matter what happens, whether it is AI attack, human attack, machine speed attack, you will always be up and running because of our Preemptive Recovery Engine.
We pre-calculate a clean data state in peace time to be able to deliver a machine speed recovery. This message is resonating. Obviously, Rubrik is a considered purchase, as we are not like a Facebook app that millions of people download overnight and we run the market. There will be a process. I like that process because at the end of the day, I want us to have consistent high growth for many years. We believe that we are set up for it.
Okay. A lot of the strategy increasingly is around data, identity, and agents. You have broadened the aperture from just pure cyber resilience into some new categories. Why is it important to see all three of those together, and what can Rubrik do with that combination that customers cannot get from separate point solutions?
Let us just take agents. If you think about agentic security and governance, there are many pieces to it. You need to have visibility into all your agents, sanctioned or unsanctioned. Second piece is, can you do identity-based, just-in-time regulation on activity of these agents? That is the number two. So that is an identity-based MCP server level, which database, which entity these guys can update. The third one is runtime security, and this is where the intent understanding of agents are important. What happened in the OpenAI Hugging Face is these agents to get to a goal, they actually circumvented the guardrails that was built for them. So you need to understand the intent of the agent and check the intent on every interaction of the agent to be able to stop the agentic action on runtime at the point of action.
Then finally, the rewind piece, that if the agent still does something that is not desirable, how do you undo it? Folks are now buying observability from one vendor, identity from a different vendor, runtime security intent from third vendor, and agent rewind or recovery from a fourth vendor. We believe that businesses need a consistent, fully integrated agentic security and governance platform, and Rubrik has the vision and the path to deliver that.
Just on the OpenAI Hugging Face point, I think in the past you have seen a lot of basically major ransomware attacks creating a catalyst for new spend within the security category. To what extent are you actually seeing that play out in your own customer conversations and pipelines, particularly for Agent Cloud?
Hugging Face incident is new, and the word is getting out in the last few weeks. But if you look at all the write-ups around it, and what is new is that there were attacks in Europe and in America coming out of a largely innocuous testing and sandboxing of agents. Just think about if it was a malicious kind of a situation where somebody designed these agents for attack and the goal was to attack, the goal here was different. We would have a completely different outcome. Now folks are realizing that agents and AI is making their world more dangerous. And obviously, AI has tremendous promise of productivity and benefits, but it also creates 100x more risk.
Now they are looking at a world where you have 100x more opportunities, but it can also do 10x more damage in one tenth of the time, and that's what they're grappling with.
Okay. Let's pivot to identity. I think it was sort of interesting, your disclosures at the Analyst Day. You showed how enterprise data security scaled to $100 million in 2.5 years. You did that with identity to $50 million in just over a year. So tell me about your sort of aspirations for the identity business more broadly. Could this be the next several hundred million dollar business? What are the biggest factors that determine how large that opportunity becomes?
Look, data security fundamentally is impacted by identity because user interaction on data is what creates risk. If you have more user interaction or identity interaction on sensitive data, you have more risk. So identity is critical for enterprise data security. And what we are also seeing is that identity has become the perimeter for enterprise. Hackers are not breaking in, they are logging in. As a result, identity systems have become ground zero for cyber attack. You have issues around destruction of identity systems, persistent identity where bad identity persists for a long period of time, and you can't just undo the identity system because then you'll not just undo the persistent bad identity, but you'll also bring your ex-employees back into the system.
How do you undo and redo both together, undo for all the identity changes and redo for only good identity changes so that you bring the identity system in a correct state? All these are very difficult problems for our customers to solve, and this is what Rubrik is delivering in the marketplace. If you look at the identity systems, it is not just one or two system. You have Active Directory, you have Entra ID, you have Okta, Ping Identity, just a number of identity systems, and you need consistency and recovery and removal of persistence across all of this. We believe that is a tremendous opportunity. We are in the early innings of it.
I cannot tell you here that if it is bigger than data protection or smaller than data protection, but if you look at the growth rate and acceleration in this market, we are very excited.
Maybe another way to think about this, I think Rubrik has traditionally priced identity like per heartbeat, if you will. With non-human identities, we have all seen the statistics, 80 to 1, 100 to 1. How are you thinking about maybe evolving the pricing mechanics to capture that opportunity as we start to see a lot more agents running on our behalf?
Look, we will work with our customers. We learn from the market as how they want to protect the non-human identity or agentic identity. Maybe agentic identities could be more important than human identity in the next several years. Ultimately, our goal is to meet where our customers are, create value for them, and I am confident that monetization will happen.
Okay. I want to get your perspective on a more recent development within the business, which is sort of self-hosted and sovereign. You guys have actually started to see a bit of an improvement in that business, and it's not just Rubrik specific. We are starting to see that across broader software. From your lens, what is driving that trend? Are customers thinking differently about where critical data and AI workloads should live? Does that make this a more durable opportunity than investors appreciate today?
This has been the trend for the last few years, and I will give you an example. I was in Germany and talking to one of our very large customers, CIO. She came into the room, and first questions she asked was that, "Bipul, we are using your cloud, and what if you guys decide to shut down the cloud for us because of geopolitical situations or the geopolitics risk?" Everybody in lots of countries around the world are thinking, "I want sovereignty in terms of operations, sovereignty in terms of data, sovereignty in terms of infrastructure, locality." We are giving them Rubrik Security Cloud private edition to ensure that their sovereignty is maintained. Sovereignty is not always going into their own data centers. It could be co-location, could be a bunch of controls around cloud, and cloud is hosted in the right country.
There is a lot of flavor to it. Ultimately, I believe that geopolitics will force more localization, and we have the solutions to meet our customers where they are. We believe that the non-cloud, sovereign, on-prem deployments, particularly international, could be a good part of our business.
Okay. Let us talk about Flex. You introduced a new consumption model. I think this sort of defines your pivot from, let us say, more of cyber recovery to a broader sort of platform play. What kind of early customer feedback have you gotten there? With the early deployments under your belt, what are you learning? Is it changing how customers evaluate, adopt, or expand with Rubrik in ways that you expected or perhaps did not expect?
If you look at our business in the last, say, three, four years, we are now a fully fledged platform play with many different products that has this complementary network effect. What I mean by complementary network effect is if customers adopt more than one product on Rubrik platform, the value of all the products go up. For example, if they are protecting data and start to protect identity with us, now we can give them information about threat actor on both sides of the equation. Same thing with data center in the cloud. If they are protecting data center, if they add cloud, we can immediately tell them if the same threat actor or the security's posture is same, different across these two.
Because of six, seven different products that we have on our platform, every time we wanted to introduce new product to the customer, we had to go do a new contract because we did not have a vehicle on which we can add new SKUs or have them try new things. Plus, they are buying many different products. They want to swap one for the other. If customers go from on-premises to the cloud, they want to increase cloud more and reduce on-premises or the vice versa. They need flexibility to have one contract, one commitment, one purchase across six or seven different product suite that Rubrik has. Flex made more sense to give our customers flexibility so that they can actually buy and consume Rubrik in a consistent way.
Let's drill into competition. As Rubrik expands into identity resilience and agent security, does the competitive landscape start to look materially different from the one you operated in a few years ago? Where are you seeing the basis of competition evolve most quickly as you expand into these newer product categories and markets?
Obviously, with identity, we are seeing new set of competition, whether they are legacy or the new age competition for identity recovery, identity resilience. That's the nature of the game, right? We are an ambitious company. We are building a platform play with many different products. As we expand, we run into a new competition. But what we have to make sure, what I have to make sure is we have products that are ahead of the market, that has a very compelling value proposition. As the customers adopt more of the Rubrik solution on our platform, we increase the value of all other products because it's naturally fully integrated as opposed to them buying different products. Ultimately, Rubrik is a platform company. We are not a vendor of tools. We are a vendor of one platform with many products.
And maybe just another one at a different angle on competition. If you think about the broader security platforms, they have all extended into new market categories. Data security seems to be one of the highest growth priorities within security budget. What makes this problem so difficult to solve? And I guess, what sort of sustains Rubrik's moat relative to some of these other vendors that could be looking at the space?
Dealing with the data infrastructure, and Rubrik, ultimately is a data infrastructure company. It is a very different ballgame than do risk analysis of attack. If you have like a, think about firewall or whatever, and if it tells you, "I have 90% probability that you have an attack," that is a high value thing. But if I give you 90% correct data, nothing will work in your environment. I have to deliver every single bit to the last bit right. It is a very deterministic, complex data management, data infrastructure issue. Obviously everything is a C program or Java or whatever kids write these days. Anybody can do anything, but these are completely different disciplines.
What we do is an extremely hard problem to solve, because not only we are extracting data from a running system, but we are restoring data back to the system and bring that back up. Think about your banks doling out money on ATM. None of that will work if Rubrik doesn't deliver the right data.
Got it. All right. At Rubrik Forward, you guys moved from preemptive recovery to autonomous recovery. How far can that evolution go? Does autonomous recovery ultimately create a new spending category, or does it mainly increase the value of the existing platform?
Here is the fundamental question. Everybody talks about fighting AI with AI. To fight AI with AI, they bring their 20-year-old software, where human beings are using that software and responding to a cyberattack. If the attacks are happening at machine speed, you can't respond at human speed with your old software. The first thing we did was we made Rubrik platform itself as an agent. That agent watches what is happening, understands the implications of it, creates a recovery plan, and brings human in the loop only for decisions. But the implementation and recovery is done autonomously. That's the vision for the future. Because if agents are attacking you, agents have to also respond and recover so that you are in the continuous recovery mode. That's the new world. It is our first step in that direction.
This is where the whole security industry has to go. Every aspect of cybersecurity has to be agentic response.
Is this having an effect on. We talk a lot about the newer products, Identity Agent Cloud, but even just in the core, there's a pretty large sort of brownfield displacement opportunity out there. How are the advancements on the core platform driving accelerated engagement or win rates across some of these legacy competitors that you compete with? What are you seeing out there?
Our win rate continues to be extremely high against legacy. The competitive landscape remains the same, as we have been saying. We do a lot of legacy replacement. The thing is that we are also adding more and more capabilities, because unlike infra discussion, where cloud is the new infra and on-prem is old infra, we discuss data, and data in the cloud is as important as data on-premises or the other way around. Data on-premises is, in many cases, more important because they may be running the most critical application on-premises. So ability to consistently apply security policy and autonomously orchestrate recovery and response is where the market is, and this is where we are actually driving the industry.
Okay. I want to talk about agents again. Enterprises seem to be experimenting with agents today, but it feels like relatively few are actually letting them operate autonomously. What do you think the biggest gating factors are here? What is the change for companies to get comfortable allowing agents to execute critical business processes on their own? Because that obviously dovetails with sort of the Agent Cloud selling motion broadly.
Just like in the world of SaaS, the same kind of things will repeat in the world of AI. If you look at businesses built custom software for their custom business processes. Then they bought horizontal software to actually do things that is not their core expertise. If you look at what is happening in AI, they are buying a coding agent, search, copilot. These are horizontal things that every business needs. These things are getting adopted very fast because it doesn't have impact or implication on their own business processes. But when it comes to their own business processes, understanding what is a customer for a customer, what is the order to cash process. Every business has a different process. The AI will be custom AI when it comes to the enterprise workflow automation.
Because you need to understand data and entity relationship, what Palantir calls Ontology, across different silos of data to be able to orchestrate AI across your enterprise to run your custom business process or your own proprietary business process. That's not going to be overnight, somebody flips a switch, and you automatically transform your enterprise into an AI enterprise. That's going to be a process. Our goal is to make sure that our customers can deploy agents, whether it's coding agent, search agent, copilot, with confidence that these agents are not doing things outside of the scope of these agents. As they build more custom agents for their own business processes, as they automate their own business workflows, we want to parlay the same platform, same technology on this custom AI. That's how this industry will go.
Early days for custom. The coding and search are going faster, and that's how these things go.
How do you think about this? Everyone seems to want a piece of this broader AI governance opportunity, observability, traditional security, ITSM. I guess as this market develops, what capabilities do you think will ultimately separate the winners from everybody else?
Typically, cybersecurity companies have not been in the online business operations. Because once you get the authorization, then you do your things. They are not in that process of doing things. All the log collection happens in the background and offline. So expertise in online business operations is going to be critical if you want to truly win in this market.
Let me ask you another question from earlier in the discussion. I guess, you talk about protection and defense and detection and prevention not being enough in an AI world. I guess, where could you be wrong in that scenario? Is there anything that the existing vendors could do to maybe meet the moment as it pertains to agent runtime security?
They have tons of opportunities. When I say that prevention and detection is not relevant, that doesn't mean that they go away. If you build a house, you have to have windows and doors and set an alarm. That doesn't mean that people will not break in. But you need to have those imperatives. So where the near-term opportunity for lots of prevention detection companies is that as the AI-based attacks ramp up, there has to be investigation effort from these companies to ensure that they understand what kinds of attacks are happening. Detection is impossible, but post-facto, once the things enter in your environment, you need to understand where they went. It's not that prevention detection companies are going to go away, but the focus of their strategy has to be resilience.
Okay. We've talked a lot about what enterprises need to trust agents, but underneath all that is, I guess, the question of trusted data. Annapurna was one of the more intriguing announcements or evolutions from the Analyst Day, because it suggests Rubrik sees an opportunity beyond resilience and security. What problem is Annapurna solving that existing data and AI platforms weren't designed to address?
If you look at businesses, they have much bigger size of unstructured data that sits in their files, other places than structured data that are in their databases. Most of the AI discussion so far has been on unstructured data or semi-structured data. Semi-structured mean textual data. But if you think about geospatial data, think about your X-rays, think about images and other data that comes from different sensors. That's a huge amount of data that is still not available for AI to operate on. These are not cost-effective to load them into a very expensive AI system or database systems just like that. Because you may be only wanting to see 5% or 10% of this huge amount of data to do certain AI analytics.
Since Rubrik has this unique technology of the understanding of the data and the metadata on the data, we have the ability to only give a slice of the data to the AI processes based on what they need instead of loading all their data. Our ability to load the metadata, customers to decide what part of the data they want to operate in, and then only bring the data that is relevant is a unique opportunity for us.
How early is this? Are you starting to engage with customers on this opportunity?
Yes. We are starting to engage with the customers. There is high degree of interest. Again, super early. I can't tell you how big and how fast it goes. But we are excited about what we see very early.
All right. Well, stay tuned. Maybe to close out in the last couple of minutes we have here, you created Rubrik X because large companies often struggle to build their second and third act. Looking across the portfolio today, which bet feels the least appreciated externally but has the potential to become a major business over time?
If you look at just the unstructured part of our bet, just the unstructured data resilience, unstructured data recovery. It's not as appreciated, but I believe that it's a tremendous opportunity for us because in terms of cyberattacks and risk on the data, it doesn't matter whether it's your structured data, your unstructured data, because you can't go explain to your customers, if you are a business that has got attacked saying, "Oh, it was attack on unstructured." It is not going to fly. On that unstructured data, we also have this opportunity to power on Annapurna, an updated Annapurna that we talked about. So that whole area is a high potential area for us. Again, we're relatively new and under scale, but we believe we have tremendous opportunity ahead of us.
Excellent. Well, I think that's a great place to leave it. Bipul, thank you so much for joining us today.
Thank you.