Potential conflicts of interests available on our website at williamblair.com. Guy and David are going to go through some slides, and then we'll have some time for Q&A.
Great. Would you all be more comfortable if I went up there? You don't care. I'm David Gibson. I'm SVP of Strategic Programs at Varonis. I've been with Varonis since 2006 or so. Guy, do you want to say hello?
Hi. Very glad to be here.
I'm going to walk you through a little bit of an overview of Varonis today, and then we'll open it up into questions. Varonis has always been about data security, long before data security was a thing and it was cool, and we've learned a lot over the past couple of decades about securing data and what that means. Really for a while now, most security folks realize that their mission is to protect data. The end users get phished all the time. There are vulnerabilities. It's a bad day if data was taken, right? If somebody gets phished or their account was compromised, it's just another day. The mission is really, from a security perspective, about securing data more than it's ever been.
One of the big challenges with securing data has always been that identities, people, systems, have access to too much just by logging in. Whether this is in on-prem data stores or cloud data stores, in structured data or unstructured data, the amount of access that people have just by logging in is way more than they need. We've been talking about this in the context of insider threats and external attackers and ransomware for many years. If you think about it, if you haven't locked your data down appropriately and you're an insider, you've got an easy job. Just by being there, you've got access to a whole lot of sensitive data that you probably shouldn't have or maybe don't need anymore. If you're an external attacker, you have an easy job.
You compromise one account, and then you have access to all that data that that account has access to. If you think about that from a ransomware perspective, it makes that much more devastating when you compromise one account, and you can encrypt and steal all the data that that account has access to. This has been a motion that we've been talking through for many years. These days, it gets to AI really quickly, because people realize that when you type in a chat at a prompt, or when you ask an agent to do something, everything that that account has access to is fair game. Whether it's your account or an agent's account or an agent's agent's account, this concept of the blast radius, how much data do you have access to by logging in, is more important than ever.
Every day, I'm talking about locking data down in the context of enabling AI safely. That's really one of the big forces that is, I think, behind the momentum that we're seeing. AI runs on data, and only 3% of an organization's data has been connected up because it's unsafe to do so yet. You can't do it. The whole application stack is changing. Where you used to have to go to different systems like your Salesforce system or your ERP system, or whatever database you wanted to get access to that data, it's changing. Now it's at a prompt. It's through an agent. Agents are non-deterministic. If you tell them to do the same thing 10 times, they'll do something different each time. It makes it hard to predict and hard to secure.
A third concern, I'm sure you guys heard about Mythos and Glasswing, AI is making attackers more dangerous. You can find vulnerabilities in software faster, and you can exploit vulnerable humans more quickly. We're seeing attackers use AI to write more creative, more persuasive phishing emails, more social engineering attacks that are more targeted. You've got multiple forces that are at play here and making protecting AI and the data that powers it more important than ever. This is really, I think, where our product suite has a great fit. We've been protecting data for years, since we started. With our acquisition of AllTrue.ai, we now have complete protection for the AI stack. Because of where we have sat, we've had a front-row seat to dozens of breaches every day through our Managed Data Detection and Response service.
A couple of years ago, we realized that almost every compromise is due to a compromised account, often from phishing. We acquired a company called SlashNext, which we feel is head and shoulders above any other email solution in terms of effectively blocking these phishing attacks, whether it's through email or through somebody getting sent a link through a WhatsApp or other application. These are really the three pillars of our solution, and I'll take you through why each of these pillars is differentiated on its own. But having all three together is really special, and this is something that's unique for our company and unique in the landscape. From our Data Security Platform perspective, we have support for almost every enterprise data store out there now. Coverage has become a huge weapon.
We've added more coverage in the past two, three years than we did in the first 16 while I was at Varonis. We've been able to expand. We started with the very tricky data stores, very large data stores on premises, and we followed data out into the cloud with SaaS applications, collaborative applications in the big hyperscalers, the object stores, and the databases in the cloud. Supporting databases in the cloud led us to support databases on premises as well. Now, wherever data is stored, we think you need to really understand three main things in order to protect it: what's important, who's got access to it, and who's using it. If you start with one or two of these dimensions, sometimes you can see a problem, but you can rarely fix the problem safely.
For example, if I find a bunch of sensitive data, is it overexposed, or is it locked down correctly? If it's overexposed, how do I fix it safely? I don't know who's using it. This is what our platform is built to do, is to go very deeply into what is the data, what's sensitive, what's regulated, where do I have source code, where do I have credentials in clear text, where do I have personal information, where do I have intellectual property? How is it controlled? Who has access to it? Is it locked down from a permissions perspective, entitlements perspective? Is it an unmasked column in a database that should be masked? Is it labeled correctly? Is it in the right place? All of the things you can do to control and protect data, we're interested in. How's it being used? Who's opening this file?
Who's doing a select statement from this database and grabbing all these rows? Who's dropping tables? How are they authenticating? How are they getting in? What are they doing with data? These are all ingredients that we have in our platform more deeply and more broadly, I believe, than any other solution out there. From there, not only do we have deep, continually updated visibility, we can automatically fix the risks we find and alert when we see something that looks out of the ordinary, like an insider threat, like ransomware, an external attacker, or AI abuse. This is what our Data Security Platform is. Wherever you've got data, we will find data in harm's way, we will fix those issues, and then alert when we see abuse. Find, fix, alert. One of the ways that people access data today is through AI.
As I mentioned, it's changing. When you've got agents accessing data, it's really important to understand the intent. Also understand the AI system itself. Through our acquisition of Atlas, we now have complete visibility into the entire AI stack. I guess we acquired AllTrue.ai in February. We announced it, then we've rebranded that product to Atlas. It does a complete set of things to protect AI. It generates a full inventory of all the AI systems that you have. It finds where they're at risk, both through scanning and automated penetration testing or red teaming. It provides runtime protection, so you can actually see what's going into and out of a prompt or what an agent is doing, and control what's going into and out of your model. We're also using that same information for AI performance. Where do we have models that are hallucinating?
Where do we have people that are burning tokens unnecessarily? Then it automates completely a lot of the compliance and third-party risk management problems that people are facing today, but as they're adopting AI. This by itself, almost everybody that I talk to, and I deal with our large customers on a day-to-day basis, almost everybody is kind of thinking about AI security, and they're looking at different technologies that typically have pieces of what this does. When we show them the breadth of the offering, they're really excited. When, of course, we remind them that we have both sides of the coin. It's really hard to secure data now without AI, but as the agent gets past the tool or the MCP server, you can't secure just the AI. You have to secure the data, too.
By having both together, it's a very powerful story. The third leg of the pillar is email security. We started at the data layer. This is where we first had visibility, and the analogy we use is just like your credit card company uses the credit card transactions to detect credit card fraud. We've been using the data transactions for years to detect insider threats, to detect ransomware, to detect other things that access files in a way that they shouldn't. In fact, we had an alert when we first started. I called it our early resignation detection system. It was very basic. It looked at your daily average. If you exceeded your daily average by more than three times your standard deviation, then we alerted.
It was a very rudimentary alert, but it worked. It's because we were looking at the data. We've since added a lot of machine learning-based models that look at the data layer as well as the identity layer, and in fact, 7 out of 10 attacks that we detect are at the identity layer, 2 out of 10 are at the data layer, and 1 out of 10 at the network. As I mentioned before, because we've had a front row seat to so many breaches for so long, said, "How can we keep the attackers further from the data?" We noticed that so many were getting in through phishing. We looked for, okay, what's the best way to stop these phishing attacks, all these account compromises? We found a product that was so head and shoulders above the others that we bought it.
It was called SlashNext. We've rebranded that to Interceptor. I can go into why it's so much better in terms of efficacy. It doesn't really matter. What the truth is it takes 15 minutes to install, and we can look back at three months of email and find all the things that whatever you're using has missed, and then you can make a decision. Worst case, right, it's just an audit. Okay, our email security is doing great. I haven't seen that to be the case, though. We almost always find something that the other solutions missed. It makes sense to couple that with your data security because that's what all these attackers are after.
With our Managed Data Detection and Response service, which is part of our Data Security Platform, where we're the ones responsible for managing the alerts, tuning them, and escalating them to you when we think there's something that you need to know, this is a really easy fit. Why is this all really important now? AI depends on data. AI, I think the first big use case that has been a huge win with AI is coding, and it's kind of natural when you think about it. You've got the whole open-source world, right? That AI can train on all that open-source code. It's made those models really good at coding. In order for AI to do more things and more things that are relevant for a business, you have to train it on your data.
It has to have access to that in order to be more relevant. AI is driving data security requirements. This means that AI security is a critical market, data security, and then email security as well. Again, we're the only vendor that has all of these combined. In fact, even the data and the AI security is unique to us as well. Thanks very much. I guess we'll pause for some questions.
Okay. You can sit down. All right. I'm asking all of my companies this question, which is, frame the case for why you're an AI winner. I think you kind of just did. Maybe talk a little bit more about the competitive landscape, like who you're going to be competing against for this. You said Varonis has the potential to own this market, like what it is about where Varonis sits that allows you to do that?
I think what I've seen as I've been talking to customers, and by the way, the activity on this has been wonderful, right? I think I've done more demos of Atlas than any other single product in a two, three-month span in my history of Varonis, so that people are really interested in hearing about this. Most of the ones I talk to have seen a couple of products. The breadth of the offering on that wheel that I mentioned, just going through all the pieces of functionality, most other products just have one piece or so, maybe two, and we see that having them connected makes sense. I'll give you an example. We can see the vulnerabilities in your system. Maybe you've got a model that's vulnerable to jailbreaking. We find that maybe through automated pen testing.
You're going to want to put something called a guardrail in place, so you can kind of intercept what's happening and make sure you can block any attempt to jailbreak. You probably want to test before and after that guardrail's implemented, and having these systems integrated allows you to do that with a couple of button presses, or automatically even. There are a few things I think on its own that are really special about this product and the breadth of the offering. I think that the biggest thing, though, is because AI, the chain, like when you think of how you interact with a prompt or an agent, eventually it gets to a data store. Where the AI stack ends and the data begins is the core of Varonis' solution.
Having these two solutions together and integrated is a really powerful thing that people, when they see it and they start to get it's really compelling. I think that that's going to be the case for a long time.
Got it. Okay. Maybe one for you, Guy. I think about the company's evolution. Obviously, the SaaS model shift has been a big part of the evolution. Maybe you could talk a little bit about that and what it's meant for the business. How does the expansion of the portfolio into some of these areas that David was talking about, especially AI and Interceptor, how has that changed, I don't know, the complexity of the company and the operations and the go-to-market, or maybe it's a lot less complex than it meets the eye?
I think we've done the challenging part of the transition, and we are really at the very late innings, if you're a baseball fan, or if you're a soccer fan, in stoppage time. That's where we are in terms of the transition, being just under where roughly 90% of our ARR is coming from SaaS. We're going to be fully SaaS at the end of this year. We talked about our end-of-life announcement, and we can spend some time about that on the on-prem subscription side being completely done with the on-prem subscription at the end of this year, December 31st, 2026. We went through all the hardships there, and there's a ton of benefits of being fully SaaS. There's a lot of leverage in the model
I think if you look at where we are from a profitability perspective and from a free cash flow perspective, during the early parts of the transition, we were actually doing better than what we initially expected. If you look at the numbers, we were able to improve nicely, where usually most of the companies that have gone through a transition, those are the years that they were struggling the most. I think it's a clear indication of how the software was built in terms of its efficiency and the leverage that we can generate even further as we move on.
When you look at the conversion side, and I know you touched on that in the first part of your question, the right framework to think about the conversions as we go through this year, we gave a bull case scenario and a bear case scenario starting this year, and it was $50 million-$75 million. We talked about the fact that this metric, this guidance on the conversion side, is very different than all the other guidances that we have provided that are done in the same philosophy. This one has a bull case and a bear case, and we expect to be somewhere in between. This is not a number that we started with and expect to improve as we go on throughout the year.
The two points, just from thinking about the trends of the conversions that are important to note, I would say the first one is that there's a lot of movement between the quarters, which is why we gave an annual guidance. We're not guiding on a quarterly basis for those conversions. We talked about the fact that the expectation is that many of those conversions will actually happen in Q4. They will happen in Q4 for two reasons. One is Q4 has been historically the largest quarter for us of the year, which means that the largest portion of the conversions should happen that quarter. The other thing that we have seen in Q1, we are also seeing in Q2, is that some of the customers do want to convert.
They don't have the bandwidth from a time perspective or a focus perspective to do the conversion in Q1 or Q2. They ask for an extension and say, "We're going to move. It's going to happen in Q4. Let's just get the extension for a couple of months, and then we'll deal with that." We're fine with that. We're working with the customers, but it just puts additional weight on the conversions that will happen in Q4, and that's really why we guided on an annual basis. Not that we're not expecting for conversions in Q2, but if you look at the guidance, there isn't any guidance on the conversions from a Q2 perspective. The other thing to keep in mind is that we talked about the single-threaded type customers that will not move, many of them on the federal side.
Q3 has been historically the largest quarter of federal, so the expectation is that in Q3, we will see some churn on those conversions. Within the guidance that we've provided, we feel good with those numbers as we look at them today. I think that what is the most critical part of all of my rambling that I just gave about conversions is that it's done by the end of the year. This is not the main focus of the business. This is not where the emphasis should be from a numbers perspective. We provided SaaS ARR excluding conversions starting in Q4 of last year because we wanted to make sure that investors and analysts understand what is the right growth rate for the business. When you eliminate the noise of the conversions, you can actually see where the business is headed.
Finishing at 29% SaaS ARR growth excluding conversions in Q1 is a number we are really happy with. I think it was a very good start for the year. It allowed us to increase our full-year SaaS ARR excluding conversion guidance and start with a two handle. We guided to 20% on the low end and 21% on the high end. We know what we need to do in order to improve that throughout the year. Obviously, from an execution perspective, we feel that that setting is a good one. When we look at the evolution throughout the year, Q1 was very strong from a new customer perspective, which ties very nicely with our thought process that reps don't have to focus on the conversions as much as they did last year.
It opens them up to focusing on what they know how to do best, which is new business and upsell. New business was very strong in Q1, and with the additional platforms that we have acquired and the pipeline that David was talking about, the expectation is that those would kick in later in the year, and then it can become really interesting.
How happy are you going to be not have to talk about this next year?
I hope I won't get any more questions in 2027 about conversions, but I'm not holding my breath.
Okay. Got you. About the question I had on the operational go-to-market complexity or if there is any with having these kind of new multiple product areas now.
One of the things that we have done throughout the years of the transition is try to simplify the conversation. We took advantage with the move to SaaS in kind of baking in many SKUs into one SKU. That has worked really well with our sales force. The conversation is not about the functionality of our protection from a cybersecurity perspective, but rather on what platforms are we protecting. That worked really well. We've doubled down on that when we came out with the MDDR in 2024, lumped it in as part of the offering, and combined incentives for simplification. The focus going forward would be to continue on that path. We want to make sure that it's clear for the customers, it's clear for the sales force. There's a ton of value within the platform.
We just need to make sure that the reps can actually communicate it in the most simplistic way. I think we've definitely moved in that direction already, and we'll continue to focus on the simplification going forward.
Yeah. Is there going to be a metric that you provide in terms of multi-product adoption or, I mean, adoption of Atlas and Interceptor so we kind of get some way to track your progress?
Obviously, Atlas was the acquisition closed in February. We didn't have much of an impact in Q1. Definitely generated a ton of conversations and emails and discussions, and we're seeing it now. When we start seeing that this has major contribution, we'll call it out in whatever way we would find as the most beneficial. We haven't seen that yet, but the expectation is that we would move in that direction and see more of that happening. The benefits of the Atlas acquisition, you can see them on multiple fronts. It's not just the actual dollar value that they generate, it's the value that they provide customers that allow us to upsell additional platforms because customer satisfaction goes up. You can see that in some of the renewals, and the expectation is that it can make the product stickier.
Just like Interceptor can have that same value in making it stickier and having a very strong renewal rate on the SaaS side, even stronger. I think it could be measured on multiple fronts, and we'll make sure that we call it out the right way.
Okay, great. Is there a solution for a federal customer or a regulated industry customer that, for whatever reason, can't move to a SaaS control plane? Is there a way to create a dedicated cloud offering for those types of customers?
The one thing you want to make sure is that whatever offering you have, it scales and is profitable. There are, in this process, customers that have been with us for a long time, historical customers that bought us for a very specific use case that isn't necessarily where we are today. If they bought us for an auditing tool, or they bought us, those are kind of more that single-threaded customers that we talked a lot about. You want to make sure that the customers go through the journey that you have gone as a company with the evolution of the company and the technology.
If they're kind of behind in what they acquired, and they're viewing us as a single-threaded type customer, and they're not moving with the technological advantages that we have now, then that's part of that $30 million-$50 million churn that we called out at the beginning of the year. We feel very good with where we are in terms of the technological capabilities and the upsell opportunity. We're focused on that.
Okay, great. I think that will do it on the time here. We're going to go upstairs for a breakout. Thanks everybody for joining, and thank you guys very much for being here.