Hey, thanks so much to everyone for joining us at the SentinelOne session. Delighted to have Tomer, founder and CEO, on stage with me, along with Sonalee, relatively recent CFO. Hey, thank you both for being here. We really appreciate it.
Absolutely. Our pleasure.
Super happy to be here.
Tomer, we were just talking off stage, and it's a really great time for us to pick your brain a little bit on some of the architectural shifts that are happening in cybersecurity. Maybe as a starting point, walk through what one of your more sophisticated customer conversations look like. When they pull you in and they say, "Look, we see the Hugging Face news. We see all of the agentic risks that we're taking on here. Please solve this problem for us," what do you say in terms of the customer journey response?
Yeah. I think what's really important, more than anything else, is to separate the hype from the actualities of these attacks. I think what's interesting in these recent incidents that we've seen, fundamentally, there's nothing new, and I would try and unpack that a bit. What these agents have done is nothing that a human attacker has not done in the past. In essence, we're not seeing any type of new behavior. We are seeing a new level of velocity, we're seeing a new level of speed, but we're not seeing new techniques. I think that's where it's becoming really, really interesting when you start to peel back, okay, what should people do right now? There is no magic solution out there from any cybersecurity vendor.
No matter what you heard, there's nothing that solves the issue that we're facing right now in terms of the speed and the velocity. But with that, if you invest in better fundamentals, and you can actually achieve better fundamentals faster, that is really your best shot at mitigating risk. Note that I'm saying not stopping the breaches, mitigating risk. I think in this day and age, if you claim that you stop breaches, that's unreliable. That's not credible. We're seeing all these breaches happen. You read about all these breaches happen. Products are failing. Everybody's failing. So this notion that we can stop it, we can prevent it, we can live in a world where these things are not happening, it's misguided. We can reduce the risk.
I think that is the number one thing that we're letting our customers do, is figure out, okay, where should I be focused? There's an ocean of different ways where attackers can actually leverage AI right now to find these nooks and crannies to get in your environment. Another reality is that nobody is able to fix all of those. Maybe a few companies, but the level of hygiene that you need is extreme. I'll take us as an example. We're a company, too. We need to protect ourselves as well. And our hygiene has been extremely high for many, many years. Pre-MITRE, post-MITRE, all that stuff doesn't really matter to us as much when you think about the fundamentals that are needed. Being vulnerability-free, you don't need MITRE to tell you that you need to be vulnerability-free and fix all your vulnerabilities.
The fact that awareness is expanding doesn't really mean that the problems were not there to begin with. I would even extend this to say that AI is not good at cybersecurity at all. We are bad at building secure infrastructure, all of us combined. That's why AI, which is a great search engine, is able to find all these things that we have basically fucked up for many, many years. So we got to really think about what's happening. It's not that AI suddenly is becoming so proficient. The problems were there. People were sitting on vulnerabilities for years. People were not fixing and configuring their environments for decades. The complexity, security vendors are also part of the issue. They're introducing more complexity into the mix. You're buying a platform. You're actually buying sometimes seven different platforms from the platform provider. You're trying to stitch everything together.
You're applying manual policies for something that moves at machine speed. There's complete misalignment between the pace of technology and the pace that AI brings, and the status quo of our infrastructure. I sincerely don't believe that AI, at this point in time, is so remarkably good, specifically and surprisingly, just in cybersecurity. We were talking so much about cybersecurity. The problem is not AI getting better, it's the state of cybersecurity itself.
Right. My favorite thing
everybody to look at
you said there is we're not seeing new techniques. Maybe I'll ask the question then, okay, so if the existing techniques get automated, scaled, happen faster, what is the limiting factor to being able to take the existing building blocks of the security architecture and make it more sophisticated to be able to deal with greater scale if it's the same technique?
Yeah. I think you need to do two or three main things. One, visibility. We've talked about it, I think, throughout years on this stage, in the context of AI, but also not in the context of AI. You need visibility. There's this nomenclature saying in cybersecurity, you can't secure what you can't see. It's very true. You got to really have visibility into each and every one of these workloads, those parameters. Every piece of your environment needs to be monitored, and that, I think, is the basis for anything that follows.
Then I think what's lacking is how do we get to the same type of velocity and speed to match what we're seeing with AI, and that comes through more automation, and leveraging AI or machine learning in these environments to basically take the visibility but find the signal fast enough before it turns into something that somebody else finds for you. The last piece, and I think this is where it gets really interesting, it's about building more and more generic ways to understand that something different is happening. I'll give you a simple story. This is, I don't know, maybe four months ago, and it seems like it was a lifetime ago, but we had all these supply chain attacks, Log4Shell, Axios, all these libraries that developers are using have been poisoned.
People using AI for development, Claude, Codex, all these tools, were automatically downloading these poisoned libraries, and Claude was just executing those on the device itself. So in essence, in a complete automated manner, hundreds of enterprises, Fortune 500 companies, got completely compromised. By the way, the moment Claude executed that innocent library, all the secrets, all the passwords, everything you had also laterally in your network was being pulled and sent out, which means that your collateral damage now, and the need to fix all the derivative kind of damages that happened because of it, is also a pretty long haul remediation story. We, on the other hand, with a piece of software that was built 10 years ago, the logic, we didn't know generative AI is coming 10 years ago. I don't think anybody did, including the people that built it, right?
With that technology focused on the most generic aspect of cybersecurity, which means behavior, not exploits specifically, not viruses, not signatures, not Trojans, not ransomware, not the actual private cases of how you do badness, but focus on what badness generally looks like or how different it looks like from benign behavior, we've been able to stop all of these attacks with no prior knowledge, no prior understanding. The system just saw something. It didn't care if it was Claude or the user or an attacker. It didn't really matter because what it exhibited looked different. So the more we focus on generic ways to take visibility and then discern good behavior from bad behavior, whether it's a human user or the agent that's running on the machine or some SaaS workload that's now downloading stuff that it shouldn't, to me, that's the only answer.
Very coincidentally, that's exactly what we built in the last decade or so. Now we're extending all of those models to also be applicable even in and through the introspection of the agent and the AI model itself. Right now, it's very focused on machine behavior. This is kind of the gist of Endpoint Protection. Now, when you add visibility, again, coming back to visibility, into what agents are doing, you're able to basically apply the same type of algorithms to discern, "Hey, is this agent really doing what it's supposed to do?" Then we go, I think, even deeper into what I believe is going to be required here for AI alignment in general. This is a problem cybersecurity never tackled. It's a complete new problem for everybody. How do you make sure AI stays aligned to what you want, to what humans need?
The only way to solve that is by matching intent with behavior continuously and all the time in a form that's external to the model. I think that is by far the only thing I would invest on for cybersecurity in the next 5 to 10 years, is solving AI alignment and AI safety. I think there's a lot of corollary things that we do today for enterprise defense, but the AI alignment issue is going to supersede pretty much every other problem we see in cybersecurity.
How do you do it?
You leverage a lot of the knowledge that you have today. I think that you need to also get to this realization that the model is never going to govern itself, that people that want to solve AI alignment should not be investing in building some super intelligence, because you don't need super intelligence to keep AI aligned. You need something that is more balanced, something that is designed to govern, not to be smart, just to know when intent differs from the exhibited behavior. That's the entire thing. It's not simple to build, obviously, but it does in many ways resemble the core EDR problems that we've seen in the past. There were much more binary and file and attacker inclined, but it's still about operations, it's still about what's happening, it's still about behavior.
To me, intent behavior equals eventually AI alignment. How you do it fast enough? How do you make sure that the model cannot temper protections, which is what we are seeing right now with guardrails. Yes, there are guardrails, there are safeguards, where we just train the model to be much more safe. The model does not care. We are seeing it right now play out in real time. The model does what it wants at the end of the day. The model does what it believes is serving to the goal that it was given. It looks at the guardrails and says, "Okay, I see the guardrails, but maybe I will do this." It is almost like a kid, right? You give it all kinds of, "Hey, don't do that. Don't do this. Don't do that." "Sure. Yes, absolutely, I will not." But then sometimes you do.
I kind of feel like there is really no way inherently in the transformer's architecture that allows for that determinism to ever be exercised. So it is a question of the current architecture for LLMs. By the way, I do not think there is any certainty that this is going to be the dominant architecture for years to come. I think what you are able to build today with the velocity that AI coding gives you is maybe a completely new architecture for the future.
Maybe it is time for us to contemplate how we build a new reasoning model and not one that leans on brute-forcing Chain of Thought and randomizing tokens and using language as the basis. Right now it works, and we are putting more money into it, and we kind of feel okay. The more compute we put in, the better outcome we are going to see. I have a question for everybody here. Where are the AI outcomes? Where are they proven in the market?
Coding, customer experience.
Revenues, dramatic growth, amazing outcomes.
I hear you. Yeah.
Transformative change for Earth.
Do you think this is because it's the wrong architectural model via transformers, or do you think it's a change management problem?
Probably a bit of both, but I think that underneath it all, it's a question of trust. I think we're just unable. If you're working with these models firsthand, you understand you can't trust this. It's just impossible.
If I just go down this thread for a second, if we solve the AI alignment problem the way that you're suggesting, then you get the trust, and then you get the unlock from a productivity and adoption standpoint.
I believe so, but I also think that that's a deeply rooted architectural problem because to do that in a way that is non-circumventable by the model or the software itself, you can't have security running at the same level, at the same layer, at the same ring that the model is running. Just in terms of compute, even today, if you take normal cybersecurity, if you're running in user space, I don't care what you do, you're toast. Everything can bypass you. These stories about user space becoming the thing, and in the wake of the CrowdStrike outage and blue screening eight million devices across the world, people were like, "Hey, get out the kernel. You have to get out. Everybody's going to get out." Nobody's out. What are we, two years, three years from that event? Nobody's getting out.
The reason you're not getting out is because the moment you're out, you're toast. You're in the same level that the attackers are, and you got no shot to prevent any type of an attack. The need to be as low as can be in the operating system is a dire need in the question of AI alignment. I would say that it's even more acute. You likely need at this point to even have either a new chip design where you can separate compute for whatever security you put inside versus whatever is running the actual software in the model-
or you need some form of a better security enclave. Even the security enclaves that we've seen today, Apple is an example. I think they got really great security enclave capabilities. They offer you protection. You can load your software, and then they protect it via hardware. That got compromised also. It seems like we would at some point need to really think about how we separate hardware in a manner that allows for security that cannot be bypassed by what it's supposed to be securing, which sounds pretty obvious, but it's really not the case today.
Yeah. Super interesting. Let me ask you about this concept of taking the proprietary data set that's in SentinelOne and applying it to some sort of LLM technology such that you're able to get, maybe it's Purple AI, or maybe it's a continuous penetration testing loop where you can run offense and defense with agents to level up the scalability of the existing architecture. What are your thoughts on how that makes sense for SentinelOne?
Yeah. I don't know. It's going to be a jagged answer. I think that there's a lot of focus on vulnerabilities, maybe too much focus on vulnerabilities right now. This entire notion that you're going to have the red agent and the blue agent, and they're going to handshake each other, and one's going to find, one's going to fix, and everything's going to be miraculously pristine after that. I haven't seen it. We've been red teaming our environments in an automated manner for years, and obviously, once we got access to more and more frontier models over time, we've used frontier models to do that as well. You find a lot of stuff. You still need humans in the loop. You still need to prioritize stuff. You still need to understand what's real and what's not real. The fixing element, it's not just finding and fixing.
It's finding, it's fixing, it's putting temporary controls, it's rolling deployment for production systems. Who's going to let AI roll out a production system completely automatically? Nobody's doing that today. That's the one place I would not exercise AI. To solve cybersecurity in this miraculous one's going to see them, one's going to find them, and we're good. Haven't seen that happen. Look, again, we're a Project Glasswing program participant. We're part of Daybreak. We got access to every model that you can dream of. Everything that's preview, we already have it. We've had it for a while. Obviously, all the open source out there. I think the other realization is that there is no supreme intelligence out there. These are largely, in terms of the level of reasoning and intelligence, these models are not very different from one another.
Some are better at keeping course, some are better at scale, some have better speed, better cost perspectives, better specialties. But in general, the reasoning quality is not dramatically different. Even when you take one of these models and you say, "Okay, I am going to pick a model, and I am going to start fine-tuning it, or doing some stuff post-training." Just to ground everybody, doing stuff post-training is very limited. You are not changing the true innate behavior of the model.
You are trying to keep it on track. It is all done post-training. To think that you have done something post-training that is so dramatically better that it is going to win against adversarial AI, again, I have not seen that in our research. Especially, at some point it also becomes a very linear and binary question. Let us say you are taking, what is it called, Nvidia Nemotron, that thing?
Yeah.
That stuff is not even top 10 in reasoning performance by any benchmark, honestly. Then you say, "Okay, I am going to use that as my basis." Just an example. "I am going to use that as my basis, and I am going to sprinkle some fine-tuning in my data from years of doing cybersecurity." The Chinese open source models are probably by a factor of 5 better than these models.
Today.
Today. I have not seen them lag. Moreover, I have seen them add incredibly sophisticated ways to scale their models that I think a lot of the frontier companies are copying today. That is, I think, the benefit they have when you are seeing something open source. All in all, to just pick one model and say, "I am going to train this to be the best thing of all models," I think that is total wishful thinking. No matter if you know Jensen or not, I do not think that changes stuff, right? At the end of the day, you have to be agnostic. You have to understand where the limits are.
I think in many ways, what we are trying to do more than anything, this has nothing to do with technology, is to stop confusing customers, to stop making pompous claims, to stop thinking that you can develop something that is completely unprecedented, it is going to win. "That is the solution. Here you go. It is right here. Let me open my jacket and give you the solution." None of that exists today, and that is part of the issue. We are all trying to think around corners and understand, okay, where this is going. I think it is proven very elusive. Not because we do not know exactly what the potential of damage here is, but more because these models are unpredictable. They not only improve in an unpredictable manner, but they also lack precision in an unpredictable manner.
It's very interesting to obviously go about and try and solve it, but then I always go back, in cybersecurity, it has to be fundamentals. People have not gotten their fundamentals together yet. Don't rush to deploy the AI security agentic spaceship/red whatever on your whatever. That's not going to help you. Spoiler alert, not going to get more secure. You really have to start with fundamentals. I think that's why also we're seeing this amazing traction around runtime protection and around Endpoint Protection because it's very obvious. You're running AI workloads someplace, you need to monitor that workload, that's it. We don't need to talk too much about AI at that point. You need the visibility, seeing the visibility, seeing immediate alerts, you're seeing amazing signal coming from all these newfound workloads.
To me, that has to remain the focus for at least the next year or so. The speed in which people are doing it, that has to change. If anything, this day and age needs to give us this wake-up call, which I think it's I don't know how many more wake-up calls this world needs to have about cybersecurity for things to move faster. Right now, we also have to recognize the limits of what the infrastructure can absorb. You can't just deploy overnight across the world. You can't fix this globally in two days. It's going to take time naturally. I think it is moving faster, but it's moving faster incrementally. I think just the level of confusion right now is also somewhat, I think throwing customers into a loop of what do they need to do? Who do they need to talk to?
Who's going to solve it? It's almost like they're sitting there, and they're waiting for their vendor that already is pre-existing to come and descend from the top and say, "Okay, now the problem is solved." To be honest, we're all trying to do it. We're absolutely trying to do it. We're also getting to the point that we understand that the fastest way to deploy is actually not by talking to us. It's just by clicking a button on your console and starting to do things in a much more automated way. A lot of what we're investing in today is this ability for our customers to just click a button and get it on with, and not Go to those protracted sales cycles that we're seeing in cybersecurity and deployment. We want to automate everything for you.
We believe that's the real power in AI right now, is it can really automate stuff. It's a great search engine. It's a great automation tool. Everything else we'll be really careful with.
[inaudible], this is the perfect opportunity
[inaudible]
To have your opinion on the future of the transformer architecture. Tomer was just talking about, look, it doesn't happen overnight. And you had this language in your script that I thought was actually very CFO-esque, which is
Appropriate.
Yeah. CFO appropriate, yeah. Architectural changes are multi-quarter and multi-year in nature. Now, you had a really clean July quarter. So I think two things might be happening. One, to Tomer's point, things are happening a little bit faster. And two, you have a little bit more of a handle on SentinelOne forecasting and having been in the seat for a couple more quarters. So, talk to us about both of those things. What are you seeing in terms of pattern recognition? Or rather, what's changing on the pattern recognition for deals in the pipeline, conversion rates, salespeople productivity, all that good stuff.
Yeah. You're right, it was my second quarter, this past one, and we do not just think it was a clean quarter, we think it was a great quarter. We are really proud of what we achieved. For those of you who did not go through our earnings, we actually beat on the quarter and raised our full-year revenue guidance.
I think the magnitude is important because I actually
Yeah.
Think it was one of the larger beats in a number of quarters.
Thank you for noticing that. It was, and we actually raised by significantly more than the beat, just showing our confidence in the outlook in the business. You asked a couple of questions there. In terms of how customer conversations are going and this, I think you were alluding to the mythos moment, and how is that impacting our pipeline and our deal cycles and conversion rates. We see a really strong demand environment, and that is very, very clear in our pipeline. My comment around this being a multi-quarter, multi-year tailwind for us in the industry still holds true because borrowing from what Tomer just said, we need to focus on the fundamentals. We need to focus on how quickly customers can actually absorb all this new technology.
And I think from our perspective, one of the areas where we're seeing a lot of strength and traction is in our AI security products. That was one of the things that really drove the strength in our net new ARR and will continue to drive that. Those are great conversation openers with our customers. Just to give you an example, I was on a customer call this week. It was a very, very large infrastructure provider, global infrastructure provider. The CIO was saying, "Look, we need to clean sheet our stack, and specifically our security stack, because we don't want security to just be something that we do to protect ourselves and protect our customers.
We want it to become strategic for us and for our business." That is a multi-quarter conversation, and that is something that I want to bring all of the team across this company into. Yes, we want SentinelOne to be part of that journey, and please tell us what products you think we need. Again, this is where the power of the platform comes in. The reason they wanted to speak to us is because we bring a true platform approach. It's something that is going to take place over many quarters. Whilst we're definitely seeing it in the pipeline, like when you actually see that hit the revenue numbers, that's going to be over time. I think that's great actually, because it's cumulative impact. The other question you asked was around the sales productivity and efficiency.
Tomer talked about where we are seeing the benefits of AI. One thing that's very dear to my heart and a metric that my team focuses on all the time is net retention. Because we all know that it is way better business to keep and expand a customer in SaaS than to go out and acquire a new one. You've seen really strong net retention metrics from us in the last two quarters, particularly in that cohort of $100,000 customers and above, which tend to be our stickier customers. Again, I think that's validation of the platform strategy. They are buying more and more products from us. Guess what? When you buy several products from us and you're adopting our platform, you're much less likely to churn. I think that is one of the things that's driving that productivity and that net retention.
Then the other thing is just amongst our sellers. We are seeing improved productivity, and we are seeing lower and faster deal cycles. Again, these conversations that do take six to nine months or sometimes 9- 12 months in the case of enterprises, large enterprises, we are seeing a slight contraction in that sales cycle, which is starting to come through in the numbers. Then finally, on the renewals process, we started automating our renewals process, particularly for that really long tail. We can touch way more customers, and we can actually reach out to them earlier in the cycle, and that's giving us a lot better predictability.
One of the things that I'm really going to be focused on as we go into fiscal 2028 planning, Tomer and I are planning for the first time together, is how do we bring that number that as we think about net retention, how do we improve that number and really work on that churn and downgrade, particularly with all these new products to just drive it higher and better.
One of the debates in cybersecurity for some time now, and especially over the last couple of years, has been the importance of scale. In some ways, you have well-scaled relative to some of the new entrants in the space. On the other hand, you've got two or three really large competitors that sometimes have a larger microphone and throw more dollars at the problem. From a CFO perspective, if you're trying to reduce churn and grow NRR, how do you do that in a way in which you can use your middle-of-the-road size as an advantage, and maybe there's a better expression for that, relative to the companies that just have much bigger R&D and S&M budgets?
Yeah. So I'll answer that, then I'll let Tomer comment on R&D as well. Look, I think a couple points I would make there. We feel like we are able to make the investments we want to make, and look, you can see for yourself how well some of those emerging products are doing. We've seen record growth, and in some cases, like in the case of AI security, so Prompt Security and Purple AI, like meteoric growth. We tripled our ARR year-over-year in that product. So we feel like we are able to make those investments that we need to make in the products where we see real outsize opportunity to grow. And that's notwithstanding the competitors, and yes, they are formidable competitors. We feel like we're formidable. And our win rates continue to improve year-over-year.
So we're seeing those competitors, and our win rates are getting better over time. The second thing I would say is we also invest in our go-to-market, and one of the things that I just touched on earlier, automating renewals, that's something where actually we're seeing better productivity from our sellers, and we're able to take some of those savings and reinvest in areas, again, where we see the ability to deliver outsize growth. So, I feel like from where I'm sitting right now, we really have the potential to take advantage of the time and this opportunity in this space to make the kind of investments we need to make to continue growing and hopefully accelerate our growth.
Yeah. I would say R&D and our technology, versus the competition, that is not my number one concern. It is far from being my number one concern, honestly. You would say with our size, with our position, with all the stuff, we still have the best technology in the market. We show up every day to POCs with the world's leading companies, and we win time and time again, regardless of the size of Microsoft or Palo Alto Networks or CrowdStrike. I would say size is just not a good reflection of quality of technology. Bigger microphones, for sure. More confusion, for sure. Controlling a narrative or weaving a narrative, for sure. I think that is our challenges, by the way, as a company at that size, which to me, by the way, is quite foreign. I am a technologist.
To me, it is like I just want to build the best stuff ever and make sure the customers are protected. Instead, we need to come up with all kinds of counter-fairytales for what these other people are telling and saying and trying to promote. It is part of the game. We all get it. I wish that in this day and age, people would actually focus on what is important and what matters, and not the fairytale stories about how identity is going to solve agentic protection today because I just bought a company, but three months later, identity is just going to be one sliver. I just bought another company.
That is going to solve it for you. And we all eat it. Customers eat it, analysts eat it. Everybody is eating it. And I look at it sometimes with deep frustration on why do people continue believing in those stories? These stories change. If you just go back three months, four months, six months, it no longer holds. What they have said, what this market has been saying six months ago does not hold today anymore. The brilliant acquisition that you have done nine months ago, nobody cares about it today. But we all have very distinct short-term memory, I would say, and we move and move, and the human brain works in a very susceptible way, sadly, and I think that a lot of folks have learned how to manipulate that, to be honest, and I think that is the main thing we are dealing with, right?
It is dealing with confusion, it is dealing with the fear, uncertainty, and doubt that people are fueling into the space instead of really being almost in a very dry way, technical about the problem and technical about the solution, and let us just go and solve it. Let us not tell stories all day long. Let us just focus on how this thing is getting risk from here to here in a quantifiable, measurable way. Those stories that you are telling on earnings calls, they are not doing it. I am saying it also about myself. To me, it feels like a cybersecurity theater that is completely disconnected from what is actually happening in environments. Sorry to be so blunt today, but
No, that's why we love you, because you're direct and blunt. So hey, please join me in thanking Tomer and Sonalee.
Thank you. I appreciate it.