Good morning. Good afternoon for those on webcast. My name is Bill Choi, and I'm the Head of Investor Relations at Zscaler. Thank you for your interest in Zscaler, and really appreciate you taking the time to learn more about us at our first Analyst Day event, held in conjunction with our Zscaler Zenith Live Cloud Summit. Here in Las Vegas, we just went through our vision, our technology platform that we've created, and some of the new innovations that'll be coming to the market shortly. For the benefit of those on webcast, we will be reviewing some of those, so bear with us for those who are here and listening to this. Hopefully, we could go into it perhaps a little bit deeper in detail.
I am going to announce upfront that three of the new products we talked about, CASB, B2B, and ZDX, will be in beta trials with select customers over the next several months. These products will be made generally available for purchase starting in calendar Q2 of 2020. Importantly, we have not included contributions from these new products into our guidance for fiscal 2020, which ends in July 31st. We provided all this guidance on our earnings call last week. As you can imagine, I just made a forward-looking statement. This presentation contains some of those additional forward-looking statements. All forward-looking statements in this presentation are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.
Moving on to discussing our agenda for today. We'll provide our view of the market landscape, discuss our technology differentiation and innovation, followed by a customer presentation. We'll take a short break, and return to discuss our go-to-market and introduce you to our new CRO, Dali Rajic, who unfortunately injured his back and is unable to join us in person today. We will dial him in, he will have a few comments, and then we'll also be available for Q&A. Some instructions for Q&A today. We will take one or two questions at the end of each section, but if you could hold your questions largely to the end when we have a dedicated time for that, around 2:30. Because we are webcasting, I'd ask you to wait until a mic is made out to you before asking that question.
Now, I'd like to introduce our Chairman and CEO, Jay Chaudhry, as well as Chief Strategy Officer, Dr. Manoj Apte.
I don't need it, just this. I'm not sure I want to get on the stage. I'll just talk here.
Yep.
Good morning.
Morning.
Morning.
Morning.
Well, after listening to the keynote, I'm not sure I need to say any more. I guess we got people remotely listening to the webcast. What Manoj and I are going to do is give you a higher level view of market positioning and essentially the opportunity we see out there. Okay. Some of it may be repetitive because you've probably seen some of the slides being covered, but audience that's remote, probably it's new for them. Let me start off with a couple of slides to set the stage, then Manoj will dig deeper into the technology, and I'll come back and wrap it up this first section. We talked about the fact that digital transformation is a business imperative. Everyone needs to do it to stay competitive or rather to survive.
This transformation is enabled by some key technologies, cloud being one of the big one that allows you the elasticity to being able to really build, run, manage applications easily. A lot of data being collected from various sources can be handled by some of the machine learning type of technologies in the cloud. Mobility is extremely important for us to be able to work anywhere at any time. Internet is becoming the network that connects various customers, suppliers, and partners, and the like. Connecting securely these various stakeholders with each other is an important part of access to applications and services. That's really the business we are in. We always focused from day one on fast and secure access. We added more on the reliable side of it as we are launching products like Zscaler Digital Exchange.
Experience.
Sorry, Experience. You can reliably access information no matter where it lives. Think of us as the policy engine that can connect any entity to any entity based on a business policy. With that, Manoj.
Yeah
take us through deeper?
Sure.
Yeah.
We've seen this transformation happen over the last few years, right? I was Juniper Networks for 10 years before last 12 years of Zscaler, and in Juniper, we were building these big, massive routers, firewalls, MPLS networks because all of our users, as an enterprise customer, all of your users were sitting in branches, factories, offices, and they all needed to access applications and data to do their regular work. The key was, how do I provide fast, secure access for employees to their applications? The best way to do that was to create a leased line network that connected you straight to the data center. The entire network, entire corporate network, was built to make sure that you had fast, quality of service-based, reliable, secure connectivity between any branch to the data center, because data center was the hub of everything.
As we all know, that didn't survive through the last 10 years. What has happened is everyone is using cloud. As you start using cloud, but your corporate network is the same, everyone is on the wrong path towards the cloud, first coming to the data center and then fanning out. It just visually represents to you what the problem is right there. You don't have to explain it. It's a huge choke point. You can call it four choke points if you're a bigger company, but it's still choke points. The whole notion for Zscaler was how do we provide all of the things that people were talking about, fast access, visibility, access controls, data loss prevention, sandboxing, DLP, all of these capabilities in this new world.
As we started thinking through what all, I rattled off a few, it was much more than that, right? It is, a employee is sitting in San Francisco and wants to go to salesforce.com. He types in login salesforce.com. Where is his DNS coming from? Am I just going to rely on Comcast to give me DNS, or do I go to Atlanta to get DNS to my HQ? If HQ gives me DNS, then I'm going to have to land on Akamai's frontend in Atlanta. When you build a platform like this, you have to go through that entire security stack or entire network access stack saying, "Yep, we got to provide DNS, and we have to provide firewall and IPS and sandboxing and SSL termination and proxy." There's a lot of flak about proxy or not. None of your companies don't have a proxy.
It's a big difference. When you're doing that stack, firewall provides network address translation and separates the external IP space from the internal IP space. A proxy isolates the two networks. Firewall doesn't isolate. Firewall passes through. You need a firewall as an access control mechanism, but you need proxy as the isolation mechanism for networks. As we started looking through it, that big stack needed to be figured out, not just on the outbound side, but also for connectivity to intranet applications, where people had load balancers, inbound firewalls. Patrick did a fantastic demonstration of what an attack surface looks like. Every time you have a firewall, it's listening for incoming connections, which means you have an attack surface.
You are relying on other controls to stop people from getting to it, the firewall basically is there to create a hole in your perfect world. That forces you to build denial-of-service, load balancers, segmentation, all of that. These are problems that we were looking to solve. One of the biggest challenges that we had as a company was, what do we call this, right? Because this is a undefined market space. It's not firewall as a service or proxy as a service or VPN as a service or DNS as a service. There's several companies that do all of that. What was needed in the market was one stack that provides everything, and there was no definition of it. What we saw people doing was doing the obvious next step, right?
Saying, "Okay, if you are not in data center and if I am in cloud, let's just take that stack and move it to cloud." Awesome, now I am doing great. Now I'm cloud-based. Guess what? It's still not going to solve the problem because, okay, you went to one cloud, but what if I need to go from Google to Microsoft or to Salesforce or to Workday? You're still going to a choke point to go elsewhere.
Manoj, you made situation worse. You extended your network over-
That too.
to public cloud. Your network is now all over out there in public clouds.
Exactly.
Exactly the opposite, maybe the other side of VPN. VPN stretches your network to thousands of places where your users are.
Exactly. Your attack surface internally becomes even larger because now you've incorporated a whole new asset into the attack surface that you had already created. What is really cool and we are really excited about, and I'm a geek to core, so I don't take analyst reports lightly, I go dig deep. Two reports came from Gartner about defining two whole new markets. One is called Secure Access Service Edge, actually, SASE, not network, sorry. Secure Access Service Edge. That is the market that Gartner is now defining as that consolidation of everything, right? When you are going into a mobile-first, cloud-first world, what is the product that you need to buy? How will you deliver security to your employees, to your partners, to your customers? They are defined that that work is going to be done with this new market called SASE. It's cute, S-A-S-E.
Secure Access Service Edge, I highly recommend I just posted a blog about it on LinkedIn, so if you guys want to click on it, we've got the Gartner subscription for or the reprint rights for it, so you can download it. It is a phenomenal treatise of 17 pages going really deep into what the architecture should be, what is the way that a service provider should provide that service. Let's say a vendor wants to be a SASE vendor, what are the key criterias that they must meet for it to qualify as a SASE? It is not looking at just saying, oh, MPLS replaced by SD-WAN or Zero Trust as the thing. It truly brings together all of it and says, when you have an enterprise to protect in this new world, this is the new architecture to use.
What is very interesting in that is that they make the point that compute power is at the edge. You need to move all your compute power as close to the edge as possible. You can't be on every endpoint, but move it as far as possible, right? That was the premise of Zscaler to begin with. That we said we need to have 150 data centers where we can process, not 12 regions where I bring traffic back. Actually compute at the edge. The second thing is they are very strongly suggesting that you have to go to a very light branch. The branch will be just a router and all your services. It's an SD-WAN router as the branch, and all your services that are security services will be a heavy cloud that is distributed at the edge.
The third thing is don't ignore encrypted traffic. That is, the world is encrypted. If you need inline network security, you have to be able to terminate SSL, which by the way, only a proxy can do. You have to have all of that capability. The main takeaway recommendation from Gartner is every enterprise needs to look at reducing the complexity of the network to a SASE vendor, which is one vendor that provides secure web gateway, CASB, DNS, Zero Trust Network Access, which is ZPA, and remote browser isolation in a single platform. This came out on August 30th. We see this as a true definition of the market that we've been trying to go after. It truly pulls everything together and provides you a view of where is the world going. Highly recommend taking a look at it.
Over time, what we have built is exactly that, right. That it's always on, all users, every location, easy-to-use service that imbibes all of those capabilities. Not all of them are completely done. We just announced CASB out of PAN, for instance. Half of it is here, half of it is coming now. Remote browser isolation, we just announced today. The platform wasn't all there, and there's a few other things that they are asking us to build into it. That kind of is why we are here. We are really thrilled about that development in the market, and we look at it as our guiding principle going forward.
If you look at Zscaler, what we have built basically is this massive platform that has the ability to provide compute at the edge for doing full inspection of traffic, provide inline inspection, peer with everyone on the planet to be able to be the fastest path between any user and any application. On that, we are building all the products that we are talking about. With that, let me give it back to Jay to talk about the products and then provide a view of what we are building next with Amit and Patrick.
Good. The offering. Some of you who listened to the keynotes probably already saw it, but essentially a couple of points to highlight here. The model of security and networking you've seen in the past 30 years is fundamentally being disrupted. There won't be the same market segments you see today, or you're seeing in the future, because some of this is going away because things aren't being done the same way. Obviously, some of the inspection technologies and all are still needed, but very differently. For example, when Gartner talks about Zero Trust Network Access, it's talking about the fact that you don't trust a person by putting them on the network and say, "Go wherever you need to go." That's if done right, the way we have done with Zscaler Private Access. You saw Patrick talk about kind of anti-DDoS, anti-firewall, anti-VPN.
What we're saying is that we aren't building VPN. We're building something that eliminates the need for VPN. With ZPA, when you access those services, since we don't allow any outside-in connection, we eliminate the need to have a firewall sitting in front of your applications in the cloud or Azure or AWS, whatever the case may be. If we aren't allow any outside-in connection, how are you going to DDoS someone? That's why we call it anti-DDoS, because we are eliminating a need by offering this ZPA type of services. That's why you think about it. That's why the mapping of one-to-one of older technologies to new technologies don't really make sense.
That's why when people like to say, "Network security has this," I like to challenge them and say, "What network security?" Your LAN obviously needs to be protected here, but the network we often talk about is the wide area network. That is the open internet. That's why we look at ourselves sitting in the middle as an intelligent switchboard or intelligent policy engine. In our world, there are users or things and applications you need to get to certain applications or services, and we are sitting as a platform in the middle. There's no such thing as inside the network, outside the network, off net, and on net in our world. You come, you talk to us, we look at the policy, authentication, and connect or don't connect based on various rules.
Just to summarize, you can take all applications and put them in two buckets, external applications that you do not have to manage. You simply use them. This is Internet, and this is SaaS. Internal, that you build, manage, or run within your own enterprise. This could be SAP running in your data center or in Azure or AWS. This may be a bunch of homegrown applications that every company has. We start the business providing access to Internet and SaaS because that's where a lot of threats come from. Internet is the Wild West. Even some of the storage services like Dropbox and Box become a wonderful tool to spread files that are infected around. That's where we started out with Zscaler Internet Access with simple goal, block the bad and protect the good from leaking out.
We do this not only for workforce, and the workforce means your employees and potentially your IT contractors and other consultants who are really working and accessing those applications from your premise, and things. Things, we're kind of calling it broadly. It's either IoT type of stuff. It could be devices, it could be servers and the like who need to communicate to either SaaS applications or internet. We end up being the Check Point to enforcing the policy. Most of our customers are in this area. That's the service we started day one with. Moving on, our customers started to say, "Hey, you're only doing part of it.
You allow my employees to go to Internet and SaaS, but you don't allow me to go to my internal applications sitting in my data center or public cloud. The technology is very different to be able to do that stuff. That's where a tool like firewall ends up being in or out, what is it? When you need to access applications sitting in SAP in a public cloud, the need is very different. Manoj showed you that on diagram. You're starting with essentially global load balancers and the like. When we built Zscaler Private Access, yes, it's using a number of common set of services, but we had to build something very specific from anti-DDoS to anti-firewall to anti-VPN and load balancing and the like that firewall guys will never talk about.
This is one of the fastest growing service for us, and Remo and Bill have talked about the growth and the numbers. They are part of the press release and the like. This solved the second part, and then as digital transformation is becoming more and more important, companies are creating a role called Chief Digital Officer, whose focus is not internal IT. CIO is typically focused on internal IT applications to be used by my employees. Right? CDO's primary role is focusing on digital transformation, where you are collecting data, telemetry, all those things that the business needs to be more competitive. That's where more and more B2 applications are being built. Far, before digital transformation, every company has some level of B2B application portals, but they never got full focus and attention.
Some companies where it's extremely critical to engage, they have pretty good presence of customers like Sanmina, Zscaler customer. For them, a lot of these manufacturing vendors who engage with them, and because they're part of the supply chain, they had to build B2B very early on. Those are the kind of customers who told us, "Huh, why don't you help me here? Because I am trying to build those applications, but I'm trying to really put them in my data center. Tomorrow, I need to build them in the cloud. How do you provide connectivity?" Based on that, we added one more circle at the bottom, our customers, your B2B customers being able to access B2B applications that may be sitting in your data center or sitting in a public cloud. There are certain technologies that are needed to make that thing happen.
The browser-based access was one thing. Supporting multiple identities was another thing. Supporting browser isolation for not just security, but for data exfiltration type of stuff were some of the key functionality that we need to support. That's the one we just announced today. Very excited about it. Last but very important, Zscaler Digital Experience. This is becoming a big issue for everyone. User experience. Where is my problem? What went wrong somewhere? Between your laptop sitting here and whatever service you're going on, whether you're going to access your email or you go to Salesforce or Workday or even a BBC News site, there are 10, 12, 15 hops you're going through. Where is the problem? That's a new area, new problem to be solved. I'm sure there'll be lots of companies will try to enter this space, right?
Anything gets hot, it is natural to have more entrants unless the barriers to entry are so high. We happen to be sitting in the optimal place to provide that service. We are sitting in the traffic path. We know what is happening on this end, we know what is happening on that end. Zscaler Digital Experience can provide you pretty good, very good user experience. Troubleshooting, monitoring is obviously the first step. Where is the problem? Being able to diagnose, then fix, and obviously, as you can expect, more and more learning can take us to auto-fixing, and the like. Very excited about this scope and size of offering. I do not think anyone comes close to this type of thinking. People do things based on the background they come from. Okay? They see things from those lenses.
People who are coming from a given appliance background, they look at things differently, and that's good for us because we are taking a totally different perspective than traditional security vendors. A lot of you have asked about customer benefits. You heard some of our customers today talk what's on the benefits. A number of them at SPAM actually quantified it. In fact, these numbers actually come from this book on cloud transformation that Richard Stiennon wrote. Richard is a former Gartner security analyst. That book is available. It's a very good book if you really want to understand how CIOs, CSOs, CTOs are going through this journey. The book is essentially a collection of interviews, without any special interpretation of it. You can firsthand read and see what these guys are thinking, without having to go through all the numbers, but the ROI is a no-brainer. Okay.
We covered some of these waves during our IPO roadshow last year. Right? In fact, early on when we started the company, the only driver at that time was internet and web traffic as number 1 and limited number of SaaS applications like Salesforce were there, NetSuite were there. The more traffic that needs to go out to the internet and SaaS, the bigger the need for a solution like ours because this means more traffic and also the more business happens on the internet, the more it attracts bad guys. You see all kind of stories out there. I don't need to make a case that there are security issues out there. The challenge is, how do you handle them? Office 365 became the biggest driver. Even though it's one more SaaS application, it's probably 10x the traffic of all other SaaS applications combined.
You saw Salesforce traffic sitting at 1%, Office 365 sitting at about 25%. They're hardly big applications. In fact, part of the challenge is a lot of other internet traffic is pretty big. It's rich media traffic, you have to process it, you have to handle it, you have to take it back. You can't just tell your employees, "You can't go to this site or that site." All that traffic is acting as a stage. People often ask me, "365, are you end of it? Where are you in that journey?" In fact, there's a lot of opportunity. Office 365 is widely sold, not as widely fully deployed. It's because it requires network and security transformation, that's where we come in to help in that area.
SD-WAN, actually one of the best catalysts that happened to us, the biggest one outside Office 365 is SD-WAN. You sometimes wonder every appliance vendor starting from Blue Coat six years ago will say, "We've got a cloud offering, we've got a cloud offering." They won't really go and talk in the market because most of these appliance vendors want to talk cloud to the press and investors, and when they go to customers, they would rather sell boxes, so they keep the cloud in the back, trying to much sell boxes. When the customer says, "Do you have a cloud offering?" They say, "Of course, I do." If they start really making noise about cloud, the market actually will move a lot faster and bigger. I think we'll benefit from that. Otherwise, we're the only one really talking to customers about it.
In the SD-WAN area, it's good to see a number of competitors. The SD-WAN awareness has gone out there significantly the past 18 months, we are natural partners for SD-WAN providers. As you saw, Gartner will talk about it. SD-WAN is wonderful because a cloud-managed, call it branch 2.0 box that integrates routing, switching, patch selection, all those good things, they can easily forward traffic to Zscaler. Application access to Azure and AWS. It's a matter of time when most of the applications move to the public cloud. Today, almost everyone who goes there, the traffic goes back to the data center at chokepoint and then goes out to public cloud because they can't afford to put security out there. There's no such thing as throw your virtual machine firewall out there.
I believe it's a matter of time when the cloud won't really have any firewall. You're going to see some sales of virtual firewalls out there for the next two, three years because people don't know any other way of doing it. The only way they know is put a firewall in front of it. In general, cloud is not really suitable for putting firewalls. Where do you put those firewalls? That's where I think the Zscaler, sorry, Zero Trust Network Access technology will take off. We're seeing a number of small startups coming to space, which is a good thing because it creates competition, and competition helps everyone, especially if you stay ahead of technology, which we know we can do very well. This partner ecosystem is important. I kind of talked often. This slide hasn't changed since we started the company. Okay.
It expanded a little bit from external traffic to internal traffic and the like, but sitting inline enforcing policy is the important thing. I've been asked a few times, "Well, are you kind of the single point of failure?" I said, "Well, do you want five points of failure?" Okay. All right. Lots of finger-pointing. Okay. Sitting inline is very hard to really figuring out security, not slowing you down and all the stuff. This is our core competency, opening up. You know why the market moved from proxy firewall to pass-through firewalls? In '90s, proxies were too slow. It's hard work. Intra-traffic took off. The markets said, "Hell with security. A good enough security is a good enough firewall, I'll move on." The market had to evolve.
Today, every aspect of business uses proxies, Akamai's the world and Cloudflare is the world when they need to really control traffic and connect with the right parties. It's all proxy architecture. The pass-through doesn't work. You see these five or six areas, right? Identity is important in the clouds, so we integrated all identity providers and vendors. Endpoint partnership, we today announced our partnership with CrowdStrike. Okay, natural partner for us on the security side of it. On the endpoint management, Microsoft and AirWatch, VMware have been good partners. Our goal is really, if we are competing, we'd rather work with most of them, but some of them that the customer is asking for and they want to work with us, obviously, we end up doing tighter integration and tighter go-to-market programs with them. On the branch side of it, again, SD-WAN technology, great partnership opportunities for us.
Security operations, being able to feed logs in real time to all these vendors from Splunk or some of the new offerings that are coming out from Microsoft, Google, and other players. CASB, out-of-band CASB, again, I think our approach is not to really force one kind of solution. Like many of the Microsoft Office customers have Microsoft CASB, we integrate with them. The customer also said, "Hey, many of them don't have it." They would rather use an interior offering from us, we already had inline, now we added out-of-band CASB. Pretty complete portfolio overall. Now, as we went for our roadshow last year, we shared with you, the TAM for ZIA, ZPA, based on data coming from IDC, Gartners of the world. Some of these new markets, I think figuring out the TAMs is fairly hard.
Think of it, the number of people who need to access B2B applications is actually far bigger. Many times bigger than number of employees in a given company, because all these companies need to work with each other. The numbers will be pretty significant. Zscaler Digital Experience, everyone needs something like that because user experience becomes the most important thing. We had lots of debates internally, how should we come with the size of the numbers? We obviously go to experts. Some of these areas, there are no experts out there. I was reading somewhere it said, when autos were invented, cars were invented, they tried to figure out the market demand for cars. The only source they could go to are horse buggies. Right? Think about how many horse buggies versus how many cars are needed. You just can't translate over.
We won't really venture to put any U.S. dollar up there right now. Okay. We'll let you figure out and imagine what it could be. Right? Needless to say, we think there's a big opportunity for us in that area. With that, Bill?
Yeah. We'll take a few questions. A quick instruction, again, for webcast purposes, if you could state your name and the firm you are with. We have two mics, one on the other side, one here. The first one I'll give to Alex Henderson here.
Thank you. Alex Henderson, Needham. Really two simple questions. Can you scale ZB2B relative to, say, ZPA? How do you think about pricing it on a per user basis, but also what the penetration might look like relative to it? Similarly, ditto for ZDX.
Right. First part, scaling Zscaler B2B, our digital experience. Scaling is our core competency. When you build something for the right scale, so we have no concerns about scaling the platform from that side of it.
Yeah, that's not what I was asking.
Okay.
I was asking, what do you think the scale of the opportunity is versus ZDX? If you were to size them.
Okay. I think it went to the question I tried to answer to say the opportunity we think is pretty big. At this stage, I'm not sure I can put any numbers around it. I think we'll be limited by the fact that how effectively we actually monetize and sell it. Okay. The technology is very good, it's highly differentiated. The pricing question, Zscaler B2B, you don't really have a typical user count base because one company user may go at 10 times a day, other company twice a month. It'll be traffic volume based pricing. Okay. We'll be learning from early customers. As we announced, we are working with a small subset of customers to learn and understand those things, and then we go from there. Did I answer both the questions or did I leave any?
No.
The first I couldn't, the second one I answered.
Hi, Jay. Jay over on this side of the room.
Yes.
Keith Bachman from BMO. Good to see you.
Thank you.
I actually had two questions. The first is, where do you draw the line? What I mean by that is you announced two new products, Z B2B and ZDX. If we take ZDX, it sounds like the value proposition is what other people do in APM or application performance management. Right? That's not to say there is an opportunity, but including if I look at what Datadog's doing and Dynatrace is doing and a little bit of New Relic, they're offering some of those same features. Secondarily within where do you draw the line is Z B2B, while you're partnering with some of the access management folks like Ping and Okta and those, it still sounds like the value proposition is similar in many ways and that you're trying to get limited access. That's the first question.
It's a good question. If you think about Zscaler Digital Experience, it's actually sitting in the traffic path knowing exactly what's going on, so end to end. Experience can be three pieces. One, what's happening on your laptop. It may have issues, it may be slow, it may have some memory, whatever. Two, the network part of it. Network starting from your PC, your local area network, Wi-Fi, whatever, all the way to the door of the application. That's the network. Number three is application. Is application slow or fast? We can see the entire end to end, but we are not competing with any of the application monitoring tools such as New Relic of the world, because they are actually inside the application figuring out if application is slow, why it's slow.
We actually, since we know everything, we can tell you that SAP is slow, but we don't know why. We would rather partner with those application vendors through APIs customers can figure out the holistic picture. We take you to the door of the application as a part of ZI and ZPA, we are in a natural place to troubleshoot exactly what's wrong along the entire network chain and the PC. I see this totally complementary opportunity, and we can do it better than anybody else out there because we're sitting in the path. If you're not sitting in the path, if you were to do something like ours, they'll be doing something called synthetic transactions. Let me try to run a fake transaction, try to simulate going to Salesforce and see what it looks like. We are actually dealing with real transaction.
That's one, that's the ZDX part. The second question was B2B, right? Think about it, people get confused sometimes. They say, "Jay, you talk about policy engine sit in the middle." I go to identity guys who say, "I'm the policy engine." The simple explanation is the following. When I leave the country, at the airport, they scan my passport, and the call gets made by the computer to a database of passport. Is Jay allowed to travel? Is any issues with this country and wherever? Is Jay allowed to leave the country or maybe he can go to certain countries. That's a lookup of database. That's what identity does. Think of it this way, identity is not sitting in the traffic path. If you don't have TSA to inspect in line, you can't do any of that stuff.
You must sit in line to say, "You can go, you can't go." That's how we complement identity providers in that space. Obviously, if someone were to do that, they'll have to get in the middle of the traffic, and figuring out who can get what you can get is very hard. People sometimes try to get selectively in the middle of a path. All these CASB only vendors you talk about, they're all out-of-band. They can say, "I'll give you CASB by getting the path of Salesforce and Salesforce only, or Office 365 only." To get in the traffic path of the entire company, it's a big undertaking, and that's why you aren't seeing very many entrants in that space.
Okay.
Okay.
Okay, thank you. We're going to move to our next section. I'll be introducing our CTO, Dr. Amit Sinha, and our CIO, Patrick Foxhoven.
Thanks, Jay. Thanks, Bill. Good afternoon.
Good afternoon.
It is afternoon universally across the working world, so it is good afternoon. All right. How many of you attended the Zenith Live keynotes? All right, good.
Fantastic.
Okay, good. I'm going to spend some time talking about how we think about the platform, but more importantly, I'm going to spend the bulk of my time talking about why virtual security appliances running in third-party infrastructure does not equal to a cloud service. Jay already covered our overall platform strategy, right? What we've built is across 150 data centers. These are compute destinations. We are a carrier-neutral service, which means we peer equally with Microsoft, with Akamai, with various service providers. When we say a Zscaler data center, that is a compute node. That isn't a front door, you'll see what that means in a minute. We've used that common platform infrastructure, everything from the control plane to the inline data processing plane, to the storage and analytics plane, universally across all these platforms that we've built.
When we launched zB2B or zDX, we were leveraging a lot of the core platform components that were already in place. Let's talk a little bit about ZIA and the evolution and innovations that have happened on that platform. That's our flagship product offering. If you see from an access control perspective, everything from next-gen firewall to URL filtering, to DNS resolution, to bandwidth control and traffic shaping have been in the product. On the data protection side, we had DLP, we had inline CASB, and last year, we launched Exact Data Match , the ability to go to a bank and say, you have 1 billion records that you want to make sure never leaks. We can ingest that, in a tokenized format and provide data loss prevention on your exact data.
Similarly, on the threat prevention side, everything from DNS controls to inline SSL, we'll talk quite a bit about SSL, to sandboxing, have been there for a while. Then, we also introduced IPS, cloud IPS protection as part of the platform. Today, you heard us talk about out-of-band CASB. All right? We've done the hard part, which is sitting in line doing SSL inspection, looking at content, giving you all the cloud application controls, the shadow IT reports. Now with out-of-band, we have the ability to go to your sanction apps and via APIs, deliver the same consistent data loss prevention and malware protection, without that traffic actually going through the Zscaler service. Patrick's going to talk a bit about browser isolation. Again, the clean way to look at it is ZIA, ZPA, today we allow you to access certain destinations.
We can block it, we can caution, but with browser isolation, you have more control. I can say, if a user wants to access a suspicious site, I'll allow it, but it will be rendered in an isolated browser in the cloud, therefore, the probability of the infection cycle is completely eliminated. There's nothing on the user's endpoint. Similarly, on the ZPA side, and Patrick's going to talk about that, maybe there is very sensitive information that you want users to access, and you don't want that information locally on the endpoint. Browser isolation can render it as an image, so you get additional security. We talked quite a bit about Zscaler Digital Experience. I think there were some good questions. I think as we have talked to all our customer advisory board members, the resonant theme that comes out is my workforce is out everywhere.
They are connecting using the internet and networks that I don't control. My applications are managed by third parties. I'm powerless. Give us more visibility and control, so that I can give proper user experience guarantees, and more importantly, even go back to my service providers, if they are violating service level agreements. If I'm using Microsoft Office 365 and I'm having SharePoint problems or Skype problems, I'd like to quantify that and then make sure that I'm getting the proper service levels from all of these cloud providers. I think the biggest differentiator for Zscaler in the ZDX space is the fact that, one, we are already present on the endpoints of all the users of a given organization. Right? We're not sampling. Many of the tools that someone mentioned, these are sampling-based tools. These are geeky network tools.
In the morning, I used the example of a professional SLR camera versus a phone that you carry, right? Every one of you has a phone. Every one of you can take a picture, right? Phones are getting better and better. What you want, similarly, in the world of digital experience is not to sample, right? If you have a geeky network tool, what ends up happening is you might deploy that tool in a branch office or in a headquarter facility. That user now goes home and has a completely different network, completely different user experience, and you just weren't there, right? We want to transform digital experience just like phones have transformed photography. Everyone has one, right? The advantage that we had was we are already present. Zscaler app is already present on the endpoint. We are sitting in the middle.
We have a unprecedented vantage point. We can see what's happening on the left side of the network, we can see what's happening on the right side of the network. We can poll your device and see what the health is, everything from CPU, memory, Wi-Fi, and we have access to front door of the applications. More importantly, the cloud effect comes in, right? We routinely see issues where a certain cloud service provider is having issues in a region, right? Maybe, as I showed in the morning, maybe Box is not working in Singapore. Why? Right? There's some peering problems going on there, we can provide that insights to customers, letting them know that it's not just you, this whole area is having a problem. This is kind of the problem statement that we shared at the keynote.
Today, the networks are so disparate, you don't control all aspects of it. A user can be in many different locations on many different devices. You could have problems with your Wi-Fi, you could have problems with your WAN, you could have problems with third-party peers. Sometimes you could have a problem with Zscaler, right? You could have problems with the actual service that the user is trying to access. That problem only gets compounded as you introduce mobility into the mix. When you're talking of a true 5G scenario, you have 100,000 employees all on their 5G networks. How do you know what is going on? Where will you run your packet capture tools? Where will you run your traceroute tools? Right? You need to be in line to be able to say, "This user is having a performance problem right now because of this reason." Right?
That is the advantage we have. The platform that we've built is already logging 70 billion transactions. When you can deal with that scale, adding some performance metrics is very easy, right? We're already there, so we are leveraging our position of strength. Most of the other network tools you'll see out there are what I would call a spectrum analyzer. I came from the Wi-Fi world. Back in the day, when there was a Wi-Fi problem, you rolled in these big, geeky tools to see if there was RF interference. Now, if you have Wi-Fi deployed in 1,000 locations, what are you going to do? Carry the spectrum analyzer everywhere? No. You have to start building intelligence into your infrastructure itself to be able to pinpoint those types of problems. All right.
With that, I'd like to hand over to Patrick to give you a quick highlights of some of the new stuff that has happened in ZPA and B2B.
Thanks, Amit. We launched ZPA a couple of years ago, and there was a lot that went into building the foundation of what ZPA does. This first line here, Zero Trust Network Access, is I think the term that's finally sticking. There's been some other terminology that has been applied to this kinds of concepts in the past. Software-defined perimeters was the most recent previous term. Google has been talking about this BeyondCorp term for five plus years now. I think ZTNA, this Gartner term, is going to finally stick. What it is, and Jay illustrated this well in his opening talk, is it's not another VPN. We don't even like calling it a VPN replacement. It's anti-VPN.
It's an alternative to rethinking how users should access applications in the future, especially accentuated by the fact that these apps often are moving out to the AWSs and Azures of the world. It's rethinking firewalls. If you have a inside out connectivity model where ZPA is basically doing this inside out traffic brokering, there's nothing that's allowed inbound on either side, so why do you need a firewall anymore? Manoj talked about that in terms of what firewalls are really good at, and if there's nothing inbound being permitted, the attack surface, like you would have seen in the keynote, is dark. It's invisible. There's nothing there. That's why ZPA can be very often thought of as anti-firewall. It also in the same way obsoletes the need for worrying about things like denial of service.
Again, if there's nothing inbound coming into the network, there's nothing to DDoS. We see those kinds of stacks of technology go away. Also in the same light, network segmentation. If you're very granular in ZPA policies, we design ZPA such that the way I like to describe it is surgical-like in your policies. You're permitting named users to named applications. If you do that right, you don't need to think about segmenting the network. Everyone has gone through the last 10 or 15 years of trying to think about doing mass segmentation, micro-segmentation of networks, and almost no one has ever done it end to end because it's too burdensome. It's too challenging. ZPA is something you can actually overlay.
It doesn't care what network it's running on. You basically are creating secure overlay networks on top of what's already there. We've seen that be very accepted in our customer base, where it's actually a project that gets deployed and achieves what network segmentation is trying to achieve. Naturally, to support those kinds of services to do it well, we had to have this concept of if we're brokering connections inside out dynamically for every user to every application, we have to figure out the optimal place to do that brokering. That's our global cloud footprint. We have 150 sites around the world. Our customers have their apps deployed in way more number of sites or regions than that, we have to choose the optimal place for the two sides to meet.
Part of the ZPA foundation was to be able to do load balancing and intelligent path selection, which also brings in health monitoring and, oh, by the way, every customer early on in ZPA that thought they had an understanding of how many internal apps they actually had in their network, they were all off by 10X or more. We realized we had to build in app discovery capability to make that easy for them to migrate to a world where it's a Zero Trust Network Access style. Highlighted down below under access, these are two of our most recent additions to ZPA. The first one was browser access.
When ZPA first launched, you had to have an app on your endpoint, which is good but not ideal in scenarios, especially like when you start talking about Zscaler B2B, because you may not be able to dictate to a third party, "Install this app." They may not even want to do that for a variety of reasons. We launched this last year, browser access in ZPA, so that allows a user to get to an application using the zero-trust style approach that ZPA brings, just with a web browser. You don't have to have an endpoint. Last but not least, and we'll have a slide on this, the most recent addition to ZPA is this concept. Manoj introduced the concepts of SASE, what Gartner's calling Secure Access Service Edge.
Well, that's a public form of SASE is what we do at the core, but we also are extending SASE down to a private model, and that's what we're calling Private Service Edge. That concept is, if you look at how ZPA works today, I'll build out this slide. You've got headquarters, data centers, you've got an enterprise network down below. When someone needs to talk through ZPA and do this zero-trust approach, those are the inside-out brokered connections coming from both sides. By design, if let's say a user in HQ is talking to something in the data center, you have to do this inside-out brokering, and that has to go over the internet to Zscaler.
That's good in some ways because that's what's giving you this new style of application access, but it's bad in terms of if, let's say, that user is talking to the data center locally, do you want all those connections to go out to the internet or not? You probably don't in on-premise local scenarios. What we're doing on ZPA is extending our cloud in the form of a VM and allowing that traffic brokering to happen on-premise. Now, it's still the cloud doing the control plane and the logging, and it's still a SaaS offering, but the actual traffic flows can happen on-premise without these traffic having to go, in essence, hairpin out to the internet and back. We've seen that be as once we introduce browser access, the next most demanded feature was let me do traffic brokering locally.
We're calling that our ZPA Private Service Edge, and you'll see aligning with that terminology, our ZIA customers have been doing private, now called service edge, but what we called before private ZENs or private or virtual ZENs that would run on-prem to allow inspection to happen. We're doing the same thing now in ZPA. Last but not least, B2B. The foundation that I just highlighted on ZPA, inside-out broker connectivity, browser-based access, that is what B2B is. If you didn't have a chance to see the keynote, the best illustration shows all of this in action is in there. I'd suggest you go back and re-watch that if you'd like to see it in action.
B2B is all about the same thing that you're trying to do for rethinking users to applications, eliminating the attack surface, doing the Zero Trust Network Access style connectivity approach. That is very relevant. I would argue sometimes it could be even more relevant when it is I'm a company, and I'm giving a supplier access to my extranet or my ERP portal, or what I showed on stage was a web development tool that we use internally that we have third parties come in and collaborate with. It's core to how we develop our products. Very sensitive applications that you're giving to third parties. Think about what the attack surface is if you can bring those behind a ZTNA style access. You obsolete the need for all the kinds of technologies that usually sit in front of those applications, and you're dramatically improving your security posture with B2B.
The pillars of B2B are similar to what I just showed with ZPA, but there's some new ones. Browser access is key because third parties, you're not going to often be able to dictate install my app to access my business app. We also had to build in the ability to do multiple identities, which is a kind of a new concept where it's not just a company or a tenant in a cloud that's consuming identity from their Azure AD or their Ping or Okta or whoever they have. We want customers to be able to federate identity to the third parties, because if I'm a company and I'm allowing another company into my network, I don't want to create accounts for that other company in my directory. It would be way better if you can just federate identity to them directly.
We built the ability in ZPA to consume identity from, it's not limited, from however many third-party suppliers, customers that they have, we'll federate that identity. The other piece that we had to build as a part of B2B is browser isolation. You really need to be careful about the data when you're, especially in a B2B context, the data that reaches the endpoint, because it's a third party, you're not necessarily responsible for securing that endpoint. Browser isolation gives us the ability, and this was in the demo as well, to allow the access to occur, but restrain or restrict what data can actually leave. We're doing that by just It looks like it's a web application, but it's actually just sending pixels to the device. There's nothing that's in the cache.
The demo that you would have seen, if you try to copy and paste content, you can't because it's just pixels. You can't even download files, and you can put policies around manipulating that. To Jay's earlier point, the only way you can do that style of control or security is to be in line to the traffic flows. No identity provider that's in line just during authorization and then out of line when they're going to the application. No identity provider is going to be able to do that. You have to be in line all the time, which is obviously core to what we do very well. Hopefully that gives you a little bit of a peek on B2B and ZPA. With that, I'll hand it back to Amit.
Thanks, Patrick.
Thanks.
All right. I thought it'd be useful to spend some time on core technology differentiation. There's a fair amount of FUD in the market, so I thought it's a good opportunity to set the record straight. I'm going to talk about what it takes to be a true cloud service for security, and we're going to have a discussion on four key tenets that we believe are absolutely critical when you're trying to deliver a security cloud service like Zscaler. We're going to talk about what it means to be born and bred in the cloud. We're going to talk about a service edge architecture. What does that mean, and where are some of the differences between what you hear in the market versus reality? I'm going to spend a lot of time on SSL inspection.
If there's one thing I want all of you to go away with is, without proper SSL inspection, you cannot do security today. Finally, we'll wrap it up with Zero Trust Network Access. Let's start with being born in the cloud. What's common to Workday, to Salesforce, to even Dropbox and Zscaler? All of these SaaS companies have built their own multi-tenant cloud platforms. Why is that? How many of you have read that article that talks about how Dropbox migrated from AWS to their own cloud infrastructure, right? Good. I think the reasons are very simple and obvious. One, it gives you strong economics, right? Our gross margins are 81% because we've built a very efficient platform. We're not using someone else's infrastructure. We're not using third-party load balancers. We're not using storage from Oracle or some other vendor, right?
It's all based on a true multi-tenant platform that we've built. It gives you elastic scale, we'll see that in action. Obviously, user experience, right? If you're able to operate this at scale, your end users get a wonderful experience. Let's contrast that to single-tenant architectures. How many of you love to watch movies on Netflix or Amazon Prime these days? Good. How many of you still watch movies on your DVD player? One brave soul. Maybe you invested quite a bit in your home theater system. It's kind of like investing in a data center, right? You're stuck to it. You have to get value out of it for some time. Imagine if your DVD manufacturer came to you and said, "You love this player, right? It plays awesome 1080p or 4K movies.
I'm going to take this and shove it into AWS, and I'm going to start streaming movies." Do you think that would be a worthwhile cloud service like Netflix? It won't. I mean, look at it from an operator perspective. I'll have to have thousands and thousands of these DVD players. I'd have mechanical Turks loading all these discs. If the same movie is being streamed on a Friday night to a million people, I don't know how to do it, right? Imagine the experience from an end user perspective. Today, when I get on a flight, I download some movies, I watch it on a plane. When I get home, I can start watching where I left off.
All of those are intrinsic services that Netflix has built, which would be impossible if you just had that mindset that I have these beautiful DVD players, and I can shove it into AWS and Azure and start competing with a Netflix type service, right? Poor economics for the operator, scaling challenges for the operator, right, and very crappy user experience. What are security vendors, your legacy single-tenant firewall and proxy security vendors trying to do? Well, kind of that. It's a shot from a movie where they look at each other and say, "Hey, we got to take this firewall." We have this cloud, and we got to deliver a service, right, using only what we have in this room here," right? I think fundamentally it's very difficult to take single-tenant offerings.
Anytime you hear a security vendor tell you, "We have an awesome proxy or an awesome firewall," think about the Blu-ray player and what Netflix and Amazon Prime are doing, okay? Let's take a look at a user experience a little more closely. What you're seeing here is a traffic pattern for a Fortune 100 company. You're seeing the transactions that were happening every hour, and all of a sudden, you see that they were doing about a million transactions an hour, and then there was a worldwide spike where you had three times the amount of traffic. We never saw this. Our customer didn't know about it. In a quarterly business review, this popped up, and then we started looking, and they said, "Wow. Yeah, that was when our CEO did his global YouTube webcast, and we had to do nothing," right?
The cloud was elastic enough. It absorbed all of that. They never had to do any network configuration changes, right? Imagine if you came home and your kid said, "Let's watch a movie," and you said, "Hold on, I got to reconfigure my router. I got to up the bandwidth so that I can see that movie." That would suck, right? That's what most vendors push you to do. This is actually how you configure next-gen firewalls in the cloud. You choose the amount of bandwidth, you provision compute capacity in accordance, and guess what happens when you have to change that bandwidth? You get a pop-up message which says, "A bandwidth change will require you to redeploy. Your service IP might change. Your IPsec VPN tunnel will get reconfigured, and it might result in 10-15 minutes of downtime." By the way, that's for one virtual firewall.
Imagine if you had 100 of these everywhere. Imagine the headache that is required to manage it. At the end of the day, you either run a service or you don't. It's important to keep that in mind. All right. Let's talk about the second pillar, which is the service edge architecture. This is where I think there's a lot of confusion, and I think it's very important for all of you to understand this very basic concept. If you look at the internet today and how our customers access services, they fall into three layers. First, you have your users and destinations. Your users and devices across locations. This is your organization across many different countries, many different users trying to access services through many different devices. You have compute destinations.
Compute destinations are where your servers are actually giving you the processing capabilities. If you look at infrastructure as a service, AWS, GCP, Azure, all of them, they make awesome compute destinations. Those infrastructures are primarily designed to run a destination application. For example, it is great when you access Gmail over Google's network. In order to make that happen, what folks do is they have a few concentrated compute destinations. For example, GCP has 20 regions, 20 compute destinations in the world. Think of them as football field-sized data centers where they have invested in economies of scale, and that's where all the compute resides. It kind of makes sense. Why would I want to build football field-sized data centers in 100 locations across the world? They've concentrated that, and then they provide what they call front door services.
In Google's case, there are 6.7 front doors. Let's round that to seven front doors for every compute destination that is available. 20 data centers that give you compute, about 140 front doors. A front door is kind of like a router. You come to the front door, and then over Google's network, they ship you back to the compute destination. That is the same for Azure, that is the same for AWS. That's how they've built out their core infrastructure. Let's take a look at this model and what happens when you try to access an application. Fundamentally, Zscaler or any security provider is providing an edge service. You're inspecting content in an attempt to not slow it down and provide security, and you ship it out. Whatever comes in, goes out. It's very symmetric.
It's not destination as in it's not a server where you come, and you get all your data there. It's an edge compute service. When you try to access, let's say, when a Zscaler customer or any customer tries to access Office 365, in this case, through this architecture, they hit the nearest Zscaler data center, and this is very important. All 150 Zscaler data centers have full compute capabilities. We do not run front doors. Every Zscaler data center runs the same hardware, same software, is fully able to process everything locally. You get local processing at that edge. We peer with Microsoft, with Akamai, with Google, with Apple, with all of these service providers, because we have built these data centers where the bulk of the internet is already pulsing through.
You hit the nearest Zscaler data center, your entire security stack and all processing happens there. A millisecond hop away is Microsoft's front door, and boom, you are on Office 365. Let's see what happens when you try to run a next-gen firewall in a cloud, in an infrastructure, and take a look at the path. First, you can only run that virtual firewall in compute destinations. You cannot run it on the front door. There isn't processing capability available there. What's going to happen is you're going to hit the nearest Google front door, then Google is going to send all that traffic to the nearest compute region where you will run the virtual firewall, you'll hairpin back, you'll come back, enter Microsoft's front door, and then go back to the actual destination that you wanted to.
This is the core problem when you try to run an edge service in a third-party infrastructure. You have to have compute available at the edge. Does that make sense? I know it's a difficult concept, but it's important to understand, otherwise, DVD players and shoving it in the cloud and everything is awesome. Okay. Gartner has released this paper, Secure Access Service Edge. Manoj talked about it, Jay mentioned it. It's a great paper. I urge all of you to read it. By the way, this is by the same Gartner analysts that launched the CASB space and the firewall space, so they are all kind of understanding what it means to be an access edge. I'm going to read a couple of quotes verbatim from this paper.
First, "Legacy inline network and enterprise firewall vendors lack the expertise to build distributed inline proxies at scale, risking higher costs and/or poor performance for SASE adopters." Next, "SASE offerings that use only the internet backbone capacity of infrastructure as a service, but without local POPs and edge capabilities," what we just talked about, "risk latency, performance issues, and resultant end-user dissatisfaction." Third, "Legacy vendors don't have cloud-native mindset. Hardware-centric vendors and network security vendors will have difficulty adjusting to cloud-native and cloud-based services delivery." It goes on and on. There's a lot of good material there. I want all of you to have a copy of this, and read it for yourself. Okay. The other myth is that Zscaler breaks Office 365. It's just bizarre and wrong on so many levels. Let me start off with a graph that we showed at the keynote.
Office 365 is the number one application that Zscaler delivers for all our customers. 25% of all the bytes that we ship through our platform is intended for Office 365. In fact, it has grown 5x since 2016. This is over and above the organic growth rate of our cloud, right? You can see YouTube used to be the number one application, now Office 365 is the number one application. The reason for that is very simple: Zscaler delivers an awesome Office 365 user experience without compromising any security. That's the reason you have Satya Nadella talking about how Zscaler and Microsoft deliver fast and direct access for Office 365 for some of our most demanding customers like GE and Siemens. Okay, you talked about user experience for critical applications like Office 365. Let's talk about what it means for the administrator to configure.
In the case of Zscaler, you could be an organization with 100,000 employees. To make Office 365 work, you have to click on that checkbox in the UI, and that's it. Across all 150 data centers, all your users, everything is taken care of. This is how typically you manage Office 365 configuration on a next-gen firewall. You install a Linux server, you download a third-party application like MineMeld, you configure the miner to go to Office 365, get changing domains and IP addresses. You configure your firewall to dynamically ingest these rules, enable SSL bypasses, and then you hope and pray, right? Imagine you have 700 locations, 700 different firewalls. Today, this was a Skype IP, tomorrow, this is a Yammer IP. You're just playing Whac-A-Mole, trying to make sure everything just works.
Many of our customers have talked about how that's been a hugely problematic experience, and we are an application proxy. We understand applications. Once we know this is Office 365, we have our APIs with Microsoft, and we can take care of all of that complexity for you very easily. Microsoft recommended. Yes. By the way, that is all Microsoft recommended policies, right? Let's talk a bit about SSL inspection. Very important. If you follow the news, Google has released this. These are well-established facts. Mozilla has similar facts. Well over 90% of all content on the internet is SSL encrypted, right? What does that mean? That means that unless you are inspecting SSL, you are blind to most of the threats. If you're not inspecting SSL, you cannot detect and block some of the most sophisticated threats.
Majority of the threats that Zscaler sees today, the more serious ones, are all delivered inside encrypted connections. If you don't inspect SSL, you cannot do DLP, data loss prevention on the network. Someone attaches a file to their Gmail and sends it. All of that is being delivered using SSL encryption. If I'm not breaking the connection, looking at the email, extracting the attachment, converting that to a PDF file, and then doing a pattern match on it, there is no way for me to know that this is a violation. You have to inspect. Here's the dirty secret. The only way to properly inspect SSL content is with a proxy architecture. You have to terminate the connection. You have to assemble different packets. You have to assemble the content, then you have to scan it.
Next-gen firewalls are typically layer 3, layer 4, attempting to give you some app IDs. They are not inspecting content. They just aren't. That's a huge lie if someone says that a next-gen firewall can inspect SSL content. The important fact here is, unless you're inspecting content, you cannot do proper data loss prevention, you certainly cannot do effective security. What's the burning question? How do next-gen firewall vendors inspect SSL? Anyone wants to take a stab at it? They don't. They don't, but if they say they do, what do they do? They have a proxy. They bolt on a proxy, right? They won't tell you that, but they'll bolt on a proxy. Well, what happens when you bolt on a proxy to a firewall that hasn't really been designed for performance? Don't take my word for it.
Go to the latest NSS Labs report on all next-gen firewalls, Check what happens when you run full SSL content scanning. By the way, that's a high-end firewall. I won't name the firewall vendor, You can take a guess at who it is. The HTTP, no SSL performance is around 8.5 gigabits per second. The moment you enable SSL scan, it drops by a factor of 15X, right. That is the performance hit you take to basically run, right. Zscaler has always been a proxy. We were never a firewall. For us, becoming a firewall was easy. It's very hard to be a proxy. We've been an inline proxy. All our 150 data centers have SSL acceleration built in. We run on bare metal. Guess what AWS, Azure, or GCP do not provide as part of their infrastructure? SSL acceleration.
You just get virtual machines that you can run server loads on, right? This is a huge problem, and this is where economics and other things come in as well when you start thinking about a service. Net net, there's rerouting overhead. You saw that, the service edge problem, right? You lose about two to three X there. You lose an order of magnitude when you try to do SSL processing. We decided to do a simple test, and we chose a user in Texas because my friend Alex there is from Texas, we chose a neutral portion of the U.S. right in the center. We said, let's do a simple test, a one gigabyte file hosted on Microsoft OneDrive, with SSL scan enabled with the users in the center of the U.S., good networks, east and west. What's the performance?
This is the Zscaler performance. We got about 264 Mbps in the download with full SSL scanning. The entire file downloaded in 22 seconds. What's a one gig file, anyone? It's a one-hour Netflix movie, right? 22 seconds to download a one-hour episode. What did the next-gen firewall on GCP take? The effective throughput was about 10 Mbps. The entire file took 720 seconds to download, 25x slower, right? Not surprising because SSL processing is hard. Number 2, when you're going rerouting and hairpinning in and out, you will incur all those latency challenges. Does that make sense? Okay. This is a slide I stole from Alex. Alex is here. Maybe I shouldn't have named Alex, I'm sorry.
At the end of the day, speeds, feeds, you block this, you didn't block this, you hear about it and your eyes gloss over. Finally, what matters is how effective is your overall security, right? I haven't seen a better way to quantify security at an overall organization level than this slide. This is a Fortune 100 company. What you're seeing is the number of machines that were getting infected with the security technologies that were in place. You can see on an average every month, 100-200 different machines were getting infected. The company deployed Zscaler. They also enabled application whitelisting, and you can see that virtually all infections were completely eliminated. You heard Hyatt CISO, Ben, talk about the effectiveness of security with SSL scanning, with caution, with making sure that right policies are set.
As an inline proxy, you break those connections, you make sure nothing bad is coming in. If something is infected, they can't communicate with their C2 host. It is better security than sitting as a firewall and just inspecting session flows. Finally, Zero Trust. Patrick talked about it. I think it's important to reiterate that concept and think of it from a firewall vendor's perspective, and then think of it from a Zscaler perspective. Back in the day, you had your data centers. You had one data center, maybe two data centers. You put a lot of firewalls in it. Your attack surface was well contained, right? You said, "Hey, these three locations, as long as I lock down these three locations, life is good." Your mobile users started popping up, and they wanted access, so suddenly your attack surface started increasing.
Your branches started popping out, and you wanted local internet access. You need firewalls there as well. As you start moving applications to the cloud with AWS and Azure, that attack surface is just becoming bigger and bigger. If you're a firewall vendor and you have VPN, you only see a flat network and all of these individual appliances that need to be configured properly, right? Fundamentally, firewalls are strong, but managing and configuring them is what gets to you. If you look at it from Zscaler's perspective, you are truly running a dark network. There is no inbound connectivity. Everyone talks to Zscaler. You're behind Zscaler IPs. If you try to discover an organization, you're not going to find anything there, right?
These are all four important concepts, and I want you to think about it as you analyze a Zscaler service with DVD players in the cloud. Okay, thank you.
Thank you, Amit. Okay, we'll take a few questions here. A lot of hands. I'll start here.
Fatima Boolani, UBS.
Hey, Fatima.
Thanks for doing the session. A question for you regarding ZPA and ZB2B. They're solving the same functional pain point. I'm wondering if you can dive into a little bit more detail as to why ZB2B has been carved out as a separate SKU, because in theory, nothing would stop me as a customer to deploy ZPA for a B2B use case. If you can flesh that out a little bit, that would be really helpful.
Yeah. I'll share my comments and Patrick can chime in as well. At the end of the day, they are fundamentally different buying centers and different customers that you're trying to address, right? If I'm an organization, I have my IT organization providing access to internal applications for my workforce, right? I have a whole partner ecosystem. There are new economic buyers like the chief digital officer now, and their job is to transform the overall business. You have ZPA is more targeted towards the workforce. Zscaler B2B is more targeted towards your partner ecosystem, right? The economic buyers are different, the sales motions are different. From a technology perspective, very important for us to develop multiple identity provider support, right? If you're just dealing with one organization, it can be Okta or Azure AD, and you're good to go.
If you're dealing with a partner ecosystem, you could have 300 different partners with 300 different identity sources. There are some fundamental technology differences, right? At the end of the day, they are zero trust based, but different economic buyer, different sort of end users. One is a workforce, one is a partner ecosystem, and therefore we feel it's prudent to look at it in two different buckets.
Just a quick follow-up on the browser isolation capabilities. I noticed that's only part of the Z B2B SKU. Is there an aspiration or a thought process to bake in some of the browser isolation capabilities in core ZPA?
So-
I didn't see the browser isolation bubble in-.
It is there in both, right? Just to kind of summarize, if you look at ZIA, ZPA, ZIA is for internet-based destinations, ZPA is for private apps. The way we look at browser isolation is it serves both those use cases, right? In the internet access case, maybe you want a more permissive policy, where you want users to be able to go to, say, miscellaneous and unknown destinations, but without the risk for infection. All of that content gets rendered in a safe, isolated browser. On the private access case, the use case could be for more sensitive documents. You might want to provide visibility, but not the ability to download and have a local copy.
We see browser isolation as helping both across the entire spectrum, where you have things that you don't care about but they are risky, and things that you care about deeply, and you want to protect.
Just to add to what Amit said in terms of B2B, this is Manoj for the webcast. The reason it is a completely separate product from ZPA is because of the way it gets deployed to. Actually, Sanmina is doing a probably overlapping talk right now about their deployment of B2B. It took them a total of 30 minutes from start to finish to deploy B2B, because what did they do? They changed their DNS name to point to Zscaler, they deployed a connector, they loaded a certificate, they were done. That's it. Traffic starts flowing, you have nothing to do. It's pointing to an identity provider of their customer. There's nothing to do. It's a very different deployment model from what we do for ZPA for employees for remote access, right? Technology is similar, not quite the same.
The other part for B2B also is having a portal, a landing portal. There is no such thing for ZPA. It's your own applications. When you log in for B2B applications, based on your entitlement, what you have subscribed to as services, when you log in, when you go through ZPA B2B, you are going to land on a user portal that shows you, hey, these are the applications that you're allowed to, that when you click on, we'll call outbound and connect to you, right? The actual people who deploy it are actually building it into the application. It is with the application, built with the application. As they orchestrate it out, the ZPA connector is orchestrated out and just connects out, right? That is also very different from a form factor of how we do remote access or ZPA for third parties.
This is customer facing. Lastly, I think somebody asked the question about how we will price and go to market. It's not user-based. I can't. There's too many users. It has to be based on how many applications, what is the volume, what type of application. It may be a IoT application just occasionally showing up. It could be a massive continuous data stream application, in which case the amount is huge. It's a different billing model altogether, different buying centers. A lot of things that are very different about B2B, and that's why it's a separate product. Isolation has a very key element there as well, more from a WAF standpoint, in this case.
Yeah, given my starting comment at the beginning of the Analyst Day, give us time to give you more information as these products become generally available. We'll give you more insight into that.
Thanks
We'll take one more and then [Dr. McGuirt].
Great. Thanks so much. Brad Zelnick with Credit Suisse. Thanks so much for a great day. Amit, in particular, thank you so much for helping to dispel a lot of the myths that are out there. I want to hit you with another one that I commonly hear from those that see the firewall as the center, as the sun within their universe around which all the other planets orbit, which is that, even if I take the performance hit of hairpinning through the front door of a destination cloud, and even if I also turn on proxy capabilities in order to handle or decrypt SSL traffic to perform better security and everything else, that perhaps there's still a benefit if I'm able to have a single vendor synchronized policy across a hybrid architecture in a state that I still have a lot of data centers perhaps, and firewalls.
What if I can marry this all together with one vendor? Maybe it does make sense to put my eggs in their basket and take that hit. What would you say to that?
First, if you look at this whole hybrid model that you just described, where I have a virtual firewall appliance in GCP, AWS, and then I have a physical firewall appliance on-premises. This notion that there's a magic single console that manages everything is not true, right? The logging that you get from that service is different from the logging that you get here. Some capabilities work here but don't work there. Right? You've got to go back to that simple DVD example. Right? Can I stream a movie with a box from an infrastructure? Yes, you'll quickly start losing many of the capabilities. For example, you're going to lose the ability to play a movie here and start off where you left off.
If you look at that from a firewall vendor perspective, even basic things like logging, when I buy a Zscaler service, I buy it for X users, and I get six months of standard logging. I don't have to worry about storage and right-sizing my S3 buckets or any of those types of things. The fact is, when you do these types of hybrid models, it's a shared ownership model. You're responsible for procuring the right amount of infrastructure in AWS and Azure. You are responsible for right-sizing your storage buckets. There's all these documents around, if I wanted to get X months of logs, what kind of storage do I have to buy? You are procuring all of these different components and trying to basically Band-Aid them together into a service. At the end of the day, users want a simple service that just works, right?
You pay a per-user subscription. I don't want to manage different infrastructure. You start getting into things like SLA. You look at the SLA for that type of service, you read through the fine print, and it turns out that the basic SLA is 99.9%. Why? Because that's the basic SLA that AWS or GCP provides. If you want to build four nines or five nines, you're responsible for spinning up multiple redundant virtual firewall machines and then try to deal with that. Right? At the end of the day, you can hand wave your way, but if you're a DVD manufacturer, you will probably sell boxes. That is your center of gravity. When someone says, "But what about my mobile work case?" "Yeah, we'll figure it out. We'll give you something." That's not truly their core strength.
Over time, you have to believe that that's the predominant use case that dominates.
Actually, Amit, just to add to that. Sorry. Can you hear me? Is this on? Hello?
It should be.
Oh, it is on. It was off. Sorry about that. Sorry. To add to that, we hear about a single console use case all the time. I have a different acquisition of a CSPM vendor. I have a different acquisition of an endpoint vendor. I have a different acquisition. It's not really a single pane of glass ever when you acquire companies and try to put it together. The second point to make, actually, to add to Amit's Netflix DVD example, is you all remember Blockbuster also had started a cloud service, but it would stream only in standard definition. If you wanted high def, you had to get DVDs. That is because you have to conserve your business model. When you go to cloud, you get a different performance. When you go to Box, you get a different performance. You need high performance, great.
Let's get hybrid and put boxes in your data center because you need high performance. When did Netflix tell you that? Netflix streams 4K to your home from the cloud because they can. Blockbuster would have never done that. It would be shooting themselves in the foot. This notion of hybrid is a protectionist notion for an appliance vendor that needs to keep its old stuff running. If you can do it really well in the cloud, why would a customer ever say, "No, give me an appliance to maintain, in addition to taking on your SLAs"? It just doesn't make sense for a customer. When you talk to a customer, customers never want hybrid. They get forced into hybrid. They want one solution that fits everywhere. You just heard Mars in the previous conversation, 600 locations.
He wants one consistent policy across the board, same speed, same outcomes, no matter how many acquisitions he does. You have to do it pure cloud. The last point on that is, we hear about East, West, North, South, or what about on-prem stuff? Well, those rules have nothing to do with each other. When you are talking about an employee going out to applications in the cloud versus a server talking to another server, you never use the same firewall nor the same firewall rules. Even if it is physically on one firewall, you have a completely different zone policy that looks like a completely different firewall, and that has nothing to do with A and B. It's cute to say, "Oh, you got one console," but the teams are not the same, so they are completely isolated from each other in terms of configuring the policy.
The policies are kept separately, and the buying centers are different. It doesn't really jive.
Okay, good.
All right. Thank you. Next, we have pleased to present a customer of ours, Alex Philips, the CIO of NOV. We'll also have some time for Q&A at the end of his presentation, but after that, we'll take a short 10-minute break. Okay? Thanks to Alex.
Thank you.
That's fine.
I got a green light.
All right. Can you hear me now? Okay, perfect. Well, thank you so much for this opportunity. Has anybody heard my story before? Okay, a few of you. All right. I'm going to summarize some of that. We'll talk about what's happened in the last year for us and what we're looking at going forward. We began our security journey a long time ago, and we had to do it with boxes, right? Lots of vendors. Oil was a nice high price. We picked best of breed for each area of protection that we needed. We had applications all over the world. We've got about 635 facilities in 66 countries, and we've got about 27,000 users today. We used to be 65,000 users, actually employees, about 41,000 users.
What was interesting is, in 2014, there was this little thing that happened that greatly impacted us, the price of oil plummeted from $100 and something a barrel down into the 30s. It was a horrible experience. I would have given plasma to survive. Right? It is bad. When you're in the oilfield, you know that it's cyclical in nature. Well, we had all these wonderful appliances, and they were all getting old. They were five, six years old. Anybody that's familiar with appliance vendors, you know that there's a life cycle to appliances. They last five or six years. Our appliances were on their last legs. We're going to have to replace them all. We also do a ton of acquisitions. We've done a lot of growth via acquisitions.
I've been involved in about 250 to 300 acquisitions over my 22-year career. We are like the Borg. Resistance is futile. You will be assimilated. So we're always merging people in. With appliances, you learn the hard way that they're never the right size when you're doing acquisitions. So you're cranking along with 100MB box, and all of a sudden, you need a 250MB box. What do you do? You have to buy a new box. Well, now what do you do with the old box? So we're running through this constant problem. Oil crashes. We've got to replace all of our boxes. We now have 10 gig boxes in multiple places around the world. Due to security problems, we had consolidated everything down to about 12 to 15 egress points around the world because we needed visibility.
What's interesting, though, is we couldn't afford redundancy. All those boxes are really, really expensive. I had one box. If something went wrong with that box, I just had to bypass the box, the protection was no longer there. I couldn't afford SSL decryption. At the time that we began this journey in 2016, about 50% of our traffic was SSL encrypted. Today, that number is 86%. Back in 2016, we were only looking at 50% of our traffic for protection. We knew that the world was changing. We knew that our applications were changing. We knew that we had no choice but to do something different, to change our ways, because our old ways were just too expensive. We began down the journey of trying to figure out, what do we do next?
We had MPLS circuits everywhere, and those are expensive, and we knew that we needed to move more towards internet-based circuits. We began the journey with Zscaler. We were able to convert about 95% of our users in 30 days. That was a drastic change. We were able to get the remaining 5% in the next 60 days. We began the journey on turning SSL decryption on, and that was probably one of the greatest eye-opening events of my career. The amount of evil that is in SSL traffic is truly stunning. When we started looking at, okay, what are we protecting? What are we finding? We found a lot of phishing. We found a lot of ransomware.
When we started diving into that, trying to understand where is all this coming from, it turned out that it was our users' personal email. Most of us, I'm sure most of you, check your personal email at work. Well, that puts your machine at jeopardy if there's malicious content in your personal email. We were protecting our users from their personal email threats. What's another interesting part is, being in 66 countries, there's a lot of privacy concerns. There's work councils you have to deal with. With my old solutions, we were never able to get permission to decrypt SSL because we would have access to that data. When we did it with Zscaler, I don't have access to that data. I know because I asked, and they wouldn't give it to me. That's another interesting differentiator.
They're decrypting the SSL traffic, inspecting it, protecting my users, and as a company, I don't have access to that data, which is important for an employee. It's important for me. I check my personal email at work, and I don't want my company looking at my personal email. I found that to be very valuable. We're going along the journey. Things are working well. We're actually blocking a lot of threats, and we started on the journey of Office 365 and moving a lot of applications to the internet. We started noticing that our users were struggling, trying to figure out, when do I turn the VPN on, and when do I not need the VPN? What's interesting about this is we'll take an application that a lot of our users use, and that's SharePoint. We're in a hybrid SharePoint mode.
It takes a long time to migrate your on-prem SharePoint environments up to the cloud. While you're in this hybrid mode, you've got some up in the cloud, some of them are inside your data centers. If your users are inside your network, both work fine. They don't even notice it. If they're outside your network, and they go to SharePoint Online, and they're accessing, everything's great, but as soon as they click a link that takes them to an internal SharePoint farm, it just fails, and the users don't know why. You tell the user, "Well, you got to launch your VPN." We started understanding pretty quickly that only IT knew where the apps were, because some of them were being migrated, and that wasn't even true. Sometimes we don't know. Is that on-prem, or have we already moved that?
We decided we needed to take the approach where it doesn't matter where the app's at, the user has access to it. We went down the Zscaler Private Access route. Today, all of our users use that as their sole VPN to access anything inside of our company. We deprecated our old VPNs, and those are no longer in use. Some other interesting things. I recently discovered that my IT career has been to the detriment of performance for my users. I've been in IT 22 years, and 22 years ago, every single facility that we had a server. On that server were files that the users used in that facility. It was a print server, it was their email server, it was their identity server. Everything they needed was at their local facility.
Well, being in IT, and we have to make things better, we decided that was too much administrative burden. We're going to move all these servers back to data centers. You guys have heard this story before, right? Data center consolidation. It works really great for IT. It sucks for the users. Because now the users have to access all their data across slow links. I did that, made the world worse for my colleagues. Then security problems hit, and so you've got to really get a grip on what's moving over your networks, what's happening on your users' endpoints, right? Which computers are you using? You decide you need to hub and spoke everything instead of having a mesh network. That makes the user experience worse.
You decide, hey, now we need to really harden your machine and protect your machine, and we're going to do application whitelisting, so we can stop files that you accidentally download from infecting your system. Certain apps that they need to use don't work. My entire career, unfortunately, has been about making the user experience worse. I had an executive come to me and say, "Alex, you realize that in 1995 with a dial-up modem, my experience was better than it is today." That was a slap in the face. I really started thinking about that. I have a mission to deliver secure, anytime information technology, anywhere, anytime on any device. Almost any device. We don't support BlackBerrys anymore. It's one of those things that wakes you up.
When we started down the Zscaler journey, we didn't think about it, but we were actually figuring out how we're going to do both: offer great security and great user convenience. That process has led us down the road to where now we're thinking about, hmm, how do we look at user experience? There's lots of tools out there. Most of them, you install an agent on a server. You're looking at them from that point of view. Well, what's interesting is when I think about my users, they already have an agent. It's their private access agent on their endpoint. All their data goes through Zscaler in the cloud. Zscaler's data centers are the closest thing I have to my SaaS applications, to the destinations on the internet. Who's going to be able to give me more insight than anyone else?
Zscaler, on where the problems are. They have an agent on all my machines, and they're at the furthest point closest to the destination. As we look forward, we look forward to looking at how do we explore that, and how do we figure out how to improve the user experience. That's my shortened story. I have lots of slides. I could bore you to death, but I'm sure there's questions.
Yeah. We'll take some questions for Alex. Okay, mic's coming your way.
Sorry.
Simple question.
Sure.
What can Zscaler be doing better?
I have a big, long list.
Top three, top five.
I think that they can do better in a couple of different ways that we've had to put workarounds in place. We're big on security automation and orchestration, and one of those areas that we struggled with in the past was around some of our dense countries, where they're real close together, like EU, will get the wrong language when they go to a website. How do we solve for that? Also, some websites are not categorized, and so you've got that miscellaneous categorization. Zscaler makes sure that there's no threats on it, but it's just a miscellaneous category, and so I'd like to see that done a little better. Those are the top two, but I do have a big, long list. We shared that with engineering a few months ago. We've been very, very pleased with how they've helped us transform how we think about things.
Can you also just talk a little bit about how your spend with Zscaler has trended from the beginning of the journey to where you are today in relative terms or whatever you're comfortable with, and maybe even relative to your other spend on traditional network security? Thanks.
On the original journey, what we found was that there was no CapEx, right? Moving to Zscaler eliminated $2 million of CapEx spend for me, because I was going to have to replace all these old appliances. OpEx, Zscaler displaced three vendors for me, Zscaler's cost OpEx was cheaper than the OpEx I was paying of those three vendors combined. To me, it was a cost optimization move, which I had to do. Adding ZPA, the private access, was not a cost savings move, it was a security move, it was an employee experience move. That was an add. We just recently re-signed for another three years. We just finished our three-year commitment, we signed up for another three years.
Awesome. Hey, Alex.
Yes.
Saket Kalia at Barclays. Thanks for coming. I think, to your point, I think some of us have heard from you before. The last time we spoke, I think one of the things you were thinking about, and you may have touched on this with the $2 million CapEx, but maybe taking a closer look at your firewall footprint in your branch offices, right? Specifically getting rid of them, right?
I guess, assuming that that's been done so far, what did you replace those with? Has it just been Zscaler, or was there any sort of other hardware to come into those branch offices? That's the first question. The second question is, ever since then, has your security posture changed? Is there anything that you've learned from that or anything that you regret, or do you wish you would've done it sooner? Does it all make sense?
It does. My goal is every single facility has an internet site. I want the stupidest box I can put at a facility to route the traffic to the cloud where it can be protected. In three years' time, I have not had to worry about patching. I have not had to worry about, oh, this appliance is the wrong size. I have not had to worry about, oh my goodness, this firmware is blocking something or not working right. Zscaler's done multiple upgrades, and it's just worked seamlessly. When I look at my branches, we're on that journey to giving internet to them. We're seeing about a 4x savings versus MPLS. We're going with a cheap white box solution, and we're putting an SD-WAN piece of software on there. I would love to eliminate that at some point.
I would love to just say, "Hey, Zscaler, here's all my traffic. Route it where it needs to go.
Great. Thank you.
Okay. Thanks for that. We'll take a 10-minute break, and we'll be back.
That's perfectly normal.
I think this is maybe going flat.
Oh, yeah, it is. Just batteries. Okay. Because it was green.
Yeah. That's what I was like. I don't know what it was because I did not change anything. It just cut for a second, and then I guess it might be a bad connection on the wire possibly.
Yeah, I wiggled it.
Oh, okay. Maybe that might've been it.
Thank you.
That was really odd. How long is the break for? Five minutes? 10 minutes?
Okay. Is Dali online?
Dali is online.
Okay.
Yep, I'm on. Can you hear me, Jay?
Yeah. Good, Dali. Thank you. Yeah.
No, forget it. Nope. Can't do that. No. Nope. It's yours. What did I miss? After the one gentleman that was up.
Mr. Customer.
Oh.
He's presenting next door now. It's the same customer.
Which customer?
These guys?
No.
Okay. That's who's presenting next door.
Yeah. I'm just sort of running it out.
Okay, we're back. Thanks for joining us again. We'll proceed with our next session. We're talking about our go-to-market. Jay Chaudhry, CEO and Chairman, will be presenting. We also have our new CRO, Dali Rajic, on to also make some comments towards the end, and both of them will be available for some questions at the end. Jay?
Excellent. Thank you, Bill. You are driving transformation, your sales need to be different as well. Over the past years, early on, when we tried to sell like a typical security product, we soon learned that it doesn't really work. We adapted, we learned, and we moved on to what we call top-down strategic selling for transformation. It became a visionary sale. Okay. I'm going to walk you through exactly what we do, how we do, and I'm very excited that Dali is joining us to take to the next level. A few slides on where we sell, how we sell. As I mentioned during my keynote, that early on, some of the large customers like GE and Nestlé, they fell in love with Zscaler, bought it, and we kind of said, "Wow, that's wonderful." We started focusing on large enterprises.
If you look at the four market segment we're showing on this slide, major is an important part of sales process as we evolved our sales teams. It used to be a field sales team first, then we added some inside sales team. Field sales team naturally gets more granular, doing better segmentations. We eventually have broken into three areas. You have people who have major account managers. They deal with major accounts. These are some of the largest companies in the world. The next level, we have what we call large enterprises, and these companies are typically with over 10,000 employees. We have below, if you get to the next level, about 3K to 10K, and that's what we call enterprise. Next level. Below 3K, what we call general business, is driven by inside sales. Okay.
If we are doing top-down strategic selling, we really are identifying some of the key decision makers who can drive transformation. It's a pretty high touch sale. On the top part, I'm showing it's more of a strategic sale. On the lower end, many times we do get what we call transactional sale. Transactional will be typically a customer looking and saying, "I am out of support from this proxy box," or whatever the box may be, "and I'd like to move to the cloud." We never say no to taking a PO. Right? Customers need it. That becomes a beachhead for us. On the other side, if a CIO is starting a project and says, "I am embracing the cloud. I'm moving my application. Office 365 needs to be rolled out," it starts very differently.
You have head of applications coming together, head of networking comes together, and security gets in the loop to say, "If you are doing network transformation, if you're doing local breakouts, I may need to make sure security is done right." That's what we are indicating a strategic sale. The sale can start from either side, but most of the cases, these are strategic, top-down net sale. When you're doing something new and different, you have to end up creating awareness and demand and the like. When the market becomes commoditized, then you end up selling more and more channel led. Early on, we end up doing a fair amount of heavy lifting and selling ourselves. It's a pretty high touch sale. A lot of business coming from the top, there's a significant opportunity to come down the triangle.
That's an opportunity for us. In fact, if you look at most SaaS companies, they start at the low end, actually. They get a lot of business because low and small businesses actually need SaaS. They have fewer resources. That's equally true for security as well. The difference is large companies actually need security, their resources. We started from top-down, and one of the reason to do that was, in my view, companies that start at the low end generally struggle to go high up. Their products generally are designed for smaller companies. They can't handle the richness of functionality that's needed. It's easier to come down. Our product, if it can satisfy the needs of the Siemens and Shell and DHLs of the world, it can easily meet the needs of small companies. We just dumb down user interface.
You don't have to worry about a small box and large box and the like. Okay. If you look at the channel I try to map up there, on the higher end, the transformation, SP and SI kind of partners get involved. We are driving the sale. As you start moving down, we are getting more and more help from SP, SIs, and we're jointly working on those. When it comes to low end, it's really the inside sales working the VARs. That's a broad directional thing. It's not that exactly every situation is like that. There are some good boutique born-in-the-cloud VARs who actually are doing some good business in the cloud because they don't have a lot of legacy box business to worry about. A number of you saw this slide.
We're very proud of the progress we're making on the high end, 400+ of the largest global 2,000 companies. As I mentioned, it's across all verticals. We are a horizontal product offering. It's true that some areas where they are more distributed, more spread out, like manufacturing of the world, embraced us earlier. On the financial services side, as you probably know, the banks have been slow in embracing the cloud, but somehow insurance companies have picked our cloud a lot faster. In fact, a lot of large insurance companies are Zscaler customers. A number of banks have become our customers as well. We are seeing more adoption coming from the large banks now. Office 365 is finally actually getting accepted in some of the largest banks, and they're all planning to roll it out.
They just needed to get full comfort and assurance from Microsoft about data privacy. We think it's there. Banks are telling us. Microsoft is telling us, "Get ready for some of those large banks." Very pleased. I think whether it's 3 of 3 or 5 of 5 or 7 of 11, all these companies, with probably exception of few because of timing and all, almost all internet and SaaS-borne traffic that goes through us. That's something we're very proud of. Large enterprises, why? A number of factors play into it. First of all, we built a rich product with the functionality that large enterprises need. That's number 1. Number 2, it may be founder's bias.
I come from enterprise sales background during my days at IBM and other companies, I had natural affinity to go and talk to CIOs and CTO type of people in large banks. When you look at the functionality you need, the larger the company, the more security savvy they are, the bigger security teams. They need security. They actually analyze security, proper evaluations get done. When you have rich functionality, you win. When we are in a real situation, even though generally it's not even a breakout, there's a lot of architectural discussions about this and that. The kind of proxy thing you just heard here, that's just the tip of the iceberg. There are lots of people out there who don't understand the new way of doing it. Large teams, good teams, we end up winning in that thing always.
Bigger the company, bigger the network complexity, bigger the pain. There's desire to solve that, to simplify that. Then you combine the network complexity with cloud adoption, it actually further start accelerating. That's where things like Office 365 and other applications come in. Appliance overload. Everyone really is worried about those, and then they want to get rid of it. They want to simplify it. They want to save costs. The WAN costs, the bigger the company, the bigger the network, the bigger the MPLS cost, the more pain to bring it down. Data privacy. Large companies are into data privacy, small companies are not. When you put all these factors together, all these large companies become better target for us than smaller companies. Okay. That's why we have kind of focused on large companies, and we've done very well there.
This is a chart we just recently put together. I think probably most of you are seeing it for the first time. This was our analysis of top 25 largest Zscaler customers. We looked at various modules to see what kind of adoption are we having, based on various modules. Rather than I tried to do it by bundles are so coarse, just two bundles. They don't really give the deeper insight this chart gives us. The green basically saying what the initial purchase was by the customer. The colored reddish, whatever color you call it, is the upsell. Now, most of the column you're seeing out here, we have done full breakout of Zscaler Internet Access. ZPA, right now is shown only as one column. It's an early stage. Over time, as we do more modular stuff, we'll share more with you.
In the case of ZIA, as we said, essentially almost all cases, when they buy something, it's for all users. ZPA starts the other way around. In most cases, ZPA, they say, "I want to solve this problem." You can see pretty good penetration across all areas. First column, secure web gateway. That essentially is that typical business that you would have competing with Blue Coat and Websense of the world. You're looking at advanced threat protection with SSL inspection. Application control to bandwidth control. Bandwidth control is becoming very popular to make sure important applications get a high priority to our cloud firewall, to sandboxing, to DLP. We put DLP in two columns, DLP and DLP exact data match. We can charge a lot more money for exact data match because that's a heavy-duty functionality when customers want it, they need it.
IoT server protection, we carved out that product probably, what, 12 to 18 months ago. We started to see that there was so much traffic leaving the enterprise that was not user traffic. We found there's lots of IoT traffic, lots of traffic coming from servers. GE started using us early on when they would have the traffic moving from servers in the data center to servers sitting in AWS, and they wanted to go through some security check post, and they couldn't think of what. They said, "Oh, Zscaler. It's a proxy. Start logging and telling me what's going on." They accept, "Oh, logging is good, but I can do a policy. I can say these servers can only talk to those servers." That's the kind of value we're adding, so that became a SKU by itself because it's a valuable thing
Our pricing is essentially value-based. Guest Wi-Fi security. Typically, every enterprise has guest Wi-Fi. You go to the company, there's a guest Wi-Fi sitting. Being able to charge for that kind of stuff. Pleased with the penetration. Moving on. Some of you have seen this chart. Buckets, where from channel point of view the revenue is coming from. As seen this chart, SISPs are essentially a little more than 50%, VARs about 45-some%, direct is five. Most people get confused with it. They think that, direct versus indirect. I would say, as a strategy, all business goes through channel. The reason you're seeing direct is because some customers have traditionally insisted that they want to really give directly the order through us. You don't expect this number to grow.
The key thing we are trying to work on is getting more and more leverage from the channel. Okay. Even if we do all the work, we actually end up doing fulfillment through channel. On one extreme, channel does fulfillment. On the other extreme, channel does everything, the PO shows up in the inbox. I would love to be in the second place. We have a fair amount of work to do to get there. Today, especially with transformational new stuff, we are evangelizing, we are creating a visionary sale, we end up doing a fair amount of heavy lifting. What we're seeing is, as the market is moving, our channel is actually doing more heavy lifting every year than they did before. There used to be where we had to go and tell the customer.
With SD-WAN type of stuff happening, more and more RFPs are happening, where customers say, "I need to do WAN transformation," Zscaler gets listed, becomes part of it, because without a proper security cloud, you can't do your local breakout type of stuff. In the case of value-added resellers, there's a range. There's some who are focused, who want to pivot from the old world, they're doing pretty well with us. Their number is still small. While there are others, like box vendors, are hoping that the cloud will never happen. That's why you see probably limited business from VAR channel, it's an important channel for us. That's our overall channel strategy. This chart tries to show you how and where sales are different from Zscaler versus others. I've been part of three box companies.
My first startup, SecureIT, and we sold tons of Check Point firewalls, a bunch of other appliances. AirDefense and CipherTrust, the other two security startups I did, is all the boxes I used. I would have 400 to 600 channel partners and teams really going and working with them. Most of the time, security sales are done to techies by VAR channel. Here's my really fast, shiny box. Okay. We soon realized early on that technical team is not driving transformation. Transformation is driven from the top. That's where we start to put more and more focus on figuring out how to engage a CIO, CTO, and CISO. Those are actually primary drivers, and along with them, the next level, they bring their architects along.
They buy the Zscaler story, they love it, and they say, "I like it, but let me have my architects poke holes into it." We end up typically doing three to six-hour workshop. In large accounts, they end up being multiple workshops. That's what we are talking about, strategic and architectural sales. The second part, in terms of channel, when network transformation happens, customers typically say, "I would like to have my SP partner, service provider partner, get engaged because they are managing the networks. Quite often, they get engaged with us. We have been working with SP providers for quite a while. They used to be one of those things and say it's a little bit conflict, but they all have woken up to the fact that MPLS is going away.
They would rather proactively manage in it, otherwise someone else will come and do it for them. On the application migration side, where Zscaler Private Access plays, we are building strong relations with systems integrators. As you know, ZP is a new product, relatively, a couple of years old. Our focus on SI started a couple of years ago. It's building, it's growing, and it's a very good fit for selling ZPA. I already talked about the personas we deal with and on rep side, right? Typically, you have rep and SE. I think that works in a mature market. In our market, a couple of roles, the architects are extremely important role, okay? They end up driving the change. How does your network change? How does security change? CTOs and CISOs are actually very helpful.
You saw that Dan Shelton, in fact, he wanted to join and evangelize that type of stuff. He has been doing a great job. Larry Biagini, who retired from GE years ago, and he wanted to kind of get back and evangelize this thing he loves. Those type of things are good for us, and we are investing in those resources. We think what we have developed here is a fairly differentiated go-to market, which is very different than what typical security box vendors do. This is some of the examples of some of the SIs and SP partners. If you looked at top 10 or even 15 service providers, everyone has done some amount of business with us or a decent amount of business with us.
Some more than others, but they all are engaged, that's partly because as we ventured early, we evangelized Zscaler, and customer has asked and told SI, "I would like you to provide Zscaler for me." With that, the opportunity grows. On the SI side, here are some of the example partners. Folks like Avanade, you may not have seen it, these guys are big system integrators for IBM. They're actually partly owned by Accenture, a little bit piece owned by Microsoft. They're focused on Microsoft consulting Office 365 deployments. Since we are so closely engaged with Office 365, they are good partners. You see a number of what we call I6, India's top 6 SIs, and Deloitte for the world. Good opportunity. This is kind of still early stage since we got moving in it in the recent couple of years, a good opportunity.
With that, I'm going to get Dali on stage. He wanted to be here. He couldn't get here, but Dali is going to share with you some of his thoughts. As you know, he just joined us last week. He's actually officially was supposed to be on vacation. He said, lots happening. He'll give some of his thoughts, and he and I both will take Q&A at the end. Dali?
Thanks, Jay. Can you hear me?
Yes, pretty clear.
Hi, everybody. To Jay's point, I'm neither on vacation nor am I there. My overeagerness during interval training, I think, afforded me a pinched muscle in my back, so, we'll get through it. In the meantime, though, I thought what I would do is take this opportunity to introduce myself a little bit, as far as my background. I thought I would share why I joined Zscaler, I also thought, given I don't have any specifics or details to share yet on plans and strategy, I would at least fill you into some of the philosophies and principles that I believe in and that, quite frankly, I've executed against throughout my career. Just jumping into this briefly, heritage is Croatian.
I grew up in Hamburg, Germany, came to the U.S. at the age of 16, and to the surprise of my parents, after my foreign exchange student year, decided to stay, and been here since. Lived out on the East Coast, West Coast, in Chicago today with my family. Chicago's always been a great middle point for travel, which I firmly believe in. I'm a fan of being in front of customers and with teams, and I'm going to continue practicing that. Why Zscaler? It's an interesting question because when I decided it was time to move on, I looked at some of the top companies in the Forbes Cloud 100 list and decided on Z for quite a few reasons that just stood out as very unique to me.
Number one, if you look at the leadership team, it is experienced, it has serially successful executives on it, and I think as everybody's noticed, they're quite humble. Humble in their approach, yet not humble in their goals and aspirations to really drive a paradigm shift in the cloud. That was very similar to what I experienced at AppDynamics, and it was a tremendous journey and one which I was hoping to repeat and maybe take to even greater heights. The market, the team's talked about it. It's a huge TAM. It has huge adjacent TAMs, it's a transformative and disruptive situation across every vertical. Quite frankly, that's unique to find, especially because the market is ready to be shaped, and that's, I think, what a big goal is for Zscaler.
The product, I've rarely come across a product of such quality at the enterprise level, and Jay spoke to it. Usually, everybody starts small and tries to grow into big. We solved the enterprise layer and the complexity first, and that means the rest is really going to be easier to go after, which also is very similar to what I experienced at AppDynamics. Being customer-driven and being really customer-focused is a tagline a lot of companies use, but Zscaler practices it, and that was also a point that was really appealing. Most importantly, all the great go-to-market elements that drive true quantifiable customer impact are already in place. That is a really great foundation to build off of. To Jay's point, I've not officially started, but I've had the chance to have a lot of great conversations with a few folks.
I thought I would share a few of my philosophies that we'll be exploring within the next few months as well. Most of these philosophies really have been shaped throughout my experience at Verint, BMC, and then most recently, the adventurous journey I had at AppDynamics. Quite frankly, I almost feel like I'm experiencing deja vu a little bit. Similar inflection points, similar market forces, similar competitive forces as to what we went through at AppDynamics about two years or so ago. To start with, I'm a believer in a high-velocity land-and-expand model as what Jay laid out earlier. The only time you can really practice that is if you have great products. Otherwise, you're trying to back up the truck, sell as much as you can, and get out of town.
That's just not the model here, where we're partnering with customers and trying to really shape the direction of their business. In order to do that, we are really going to probably explore, as I have in the past, creating a closely knit life cycle approach across the entire customer engagement. What that means is close linkage between lead creation, first contact throughout the sales process, deployment, customer success, and then renew or expand. When a close-knit life cycle is created, a seamless process if you will, value realization for a customer happens, maximum velocity and yield for our activity happens, and stickiness of customers happens. The entire organization is really working against the same playbook of metrics.
When you start talking about multidimensional go-to-market models, as Jay alluded to earlier, that's even more important because you have other elements, outside elements, that even though they're partnering and helping you, it's always your brand that's impacted. Having close partnership and that being part of the life cycle is going to be critical. I'm a firm believer that in order to maintain and increase velocity, you have to have a qualification framework that you religiously follow, and that's been MEDDIC for me. It's a model that's been out there for quite some time. I've used it across three companies. What a qualification model means that is executed across every step of the sales process is you minimize any wasted activities, you drive maximum relevance in customer meetings, and most importantly, you dictate pace and direction of customer-facing and sales campaigns.
Another point that is really the main one in everything that I've done in the past is creating any metric-based model around rep productivity. That to me is the stat number one because everything else flows off of it. That's time to productivity, size of productivity across geos, various cohorts, and then quite frankly, understanding all the ecosystem variables from channel SI, marketing, customer support, engineering, understanding the impact of all those variables to productivity and creating a model that automates that so that we're tracking relevant metrics. When we talk about relevant metrics, it means introducing a little bit more science so that we can help reps help the field across all activities, understanding progression, conversions, influencing factors on size of deal, on time to deal.
When we can automate that and understand it, and understand it not just in a lagging way, meaning forecast and pipeline, but start looking at leading indicators which are more activity-based that we know have a probability for success at certain dimensions. When we start looking at leading indicators in an automated fashion, that's really when you start unlocking the power of productivity. We'll be exploring what that could potentially look like here. One of the other things, Jay's alluded to it quite a bit, he speaks of transformational selling a lot.
During times like this when market dynamics are dictating that customers have to look for different ways to solve problems, you have to decide whether or not you're going to deploy a visionary sales approach that's not feature function focused, but rather focused on outcomes and where you can take a customer with uniquely differentiated features and functions. It sounds nuanced, but it's very different as to what conversations you're having, the partnerships you're shaping, and how you're guiding CXOs during these turbulent times.
A value-based, outcome-based sales model is what I think a maximum velocity generator, and is something that we're going to look to fine-tune even more from where it is already today. One of the things that impressed me that Jay and team have built out is the strong team of former CXOs and strategic resources, practitioners available that we can leverage in campaigns, that we can leverage in painting a vision, painting a path for our customers to understand. Taking that and understanding how to scale it into business outcome models that every rep, every systems engineer can use is a massive unlock to the quality and level of conversations everybody across the org can have. We're going to take a look at how to potentially build that out, same way as I've done it in the last few engagements that I've had across multiple companies.
The other thing that this does also is there's so much FUD out there from competitors, and it's going to continue due to the velocity we're having. It's great to be the fastest kid on the block, but everybody's coming after you. When you have a value-based, outcome-based sales approach, it's kind of hard to argue with quantifiable results that you can take somebody to when your only focus is feature and function. One other thing that I've been a religious believer in is not waiting for market to dictate velocity, but rather drive velocity to the market. What does that mean? I'm a fan of maniacal and continuous pipeline generation programs. What that means is we are going to have steady days where we drive pipeline. All we're doing, we're preparing for meetings with customers. We're reaching out to customers.
What that also means is it has to be in a very focused way. It has to be in a way where we educate the channel as well to help us with that pipeline generation. That's FSI service providers as well as the VARs. That focused approach, in my past, has produced great results because you can act as a partner to companies versus just chasing deals. You're building a business plan in how to help your customers become better. Maniacal pipeline generation focused on accounts that we cover, focused on enabling our partners to help us with that pipeline generation, enabling them are going to be key programs. Two last elements that I just want to mention that kind of wrap around everything that I just mentioned.
Two key elements that have to be in play in order for everything that I just philosophically and conceptually mentioned to actually be maximized and realized are the following. Number one is we're going to continue to focus on recruiting only the best talent and with the highest expectations of that talent. The quest for excellence is going to be our mantra. What that means is when we're recruiting people, we're going to focus on intelligence, coachability, character, and experience. The first three really being the most important. The reason being, the market is evolving so dynamically that we need to have people who enjoy being uncomfortable, enjoy learning, enjoy growing, and enjoy becoming really the best version of themselves. We're going to give them a platform to do it by executing on the second element.
We're going to build a world-class enablement team that's going to not just enable the sales teams, but also sales, pre-sales, sales leadership, the channels. That means everybody will be in a consistent way, in a scalable way pursuing value creation for our customers and in return getting maximum yield for our efforts. I think it's known we've hired a new vice president for enablement, Rick Kickert. I'm going to be partnering very closely with him in building out these models and these frameworks so we can take advantage of everything that I believe is in front of us. The enablement portion is so critical because it actually accelerates people's ability to execute, eliminates waste, increases transparency and complete accountability across the team because everybody's educated and everybody understands what their charter is.
Quite frankly, when all comes together beautifully as it did for us at AppDynamics, that's when you hit escape velocity. My goal is to help hit escape velocity through the $1 billion mark in ARR. A little snapshot. I hope it gave you some insights into what's floating around in my mind. I'm going to look to have this not just float around in my mind, but rather be built into a program within probably 30-60 days, as I want to spend a lot of time in those first couple of months sitting down with people, sitting down with customers, and analyzing data. Jay, that's kind of who I am, what I'm about, and what I'm looking forward to.
Excellent. Dali, thank you. Bill?
Okay, we'll take a couple of questions here before we move on to our final section.
Yep.
Hi. Hamza Fodderwala from Morgan Stanley. One of the key debates coming out of the most recent earnings was the longer sales cycles that you noted. It seemed like it wasn't entirely clear whether that was macro or competitive related at all. I know it's been, I think maybe one or two weeks since, but can you share with us any additional insight or color you might have on that from a go-to-market standpoint?
First of all, I'll clarify what we said. We said towards the end of the quarter, we saw some deals taking longer than expected, which really means a number of deals we're working on, they closed, but probably more than normal we expect did not close. Okay. We thought it one or two kind of highlighted as being transparent, but that's one data point. As I say, one dot is a data point, two is a line, and three is a trend. At this stage, it's a data point. We aren't seeing a trend yet. Just wanted to highlight.
Jay, if I may add to it as well?
Yes.
Again, this is why I said I had deja vu just having some of the conversations within Z. When you hit a certain scale and a certain velocity, and you start adding more and more heads, it becomes critical to have a broad sales enablement model with templates and frameworks so that everybody can learn. It's not just best practices over here and less best practices over there, but it has to be consciously built out. When that is built out consciously, then you'll see consistent effort as opposed to some of the lag in how long it takes to close deals in certain regions. To me, when I looked at the information, again, outside looking in, a robust sales enablement program, right. This is not a couple of people and a few trick ducks.
This is a legitimate program, and an offering that is going to continue to evolve. That is what will help eliminate some of those challenges, and I've seen it before across multiple organizations.
Thank you. Any other questions? Next we'll go with the financial section with Remo Canessa, our CFO.
Great.
All right. Thank you, Jay. Thank you, Dali. Appreciate you being on the call. There's no change or update to our guidance that we gave. The only comment is that our free cash flow will have a negative impact of about $15 million-$20 million for Symantec litigation expenses. We're moving our headquarters, so there'll be a cost related to TIs for that, as well as we'll have duplicate rent. Those expenses aren't picked up in our pro forma, but they'll be picked up in our cash flow. We expect our cash flow to be 1% or 2% lower than or one, two points lower than our non-GAAP operating margins. We've gone through this before. Really strong and powerful financial model with Zscaler. The comments I've made, I've never seen a model like this ever in my career, with the opportunity that we have.
50% growth, mostly subscription, 81% gross margin, which talks about the strength of our platform. The multidimensional go-to-market, which Jay just went through. Net retention rate, 118%, which is outstanding, especially when you consider that more and more customers are going straight to transformation. Also the infrastructure. Our cloud infrastructure that we have with the ability to increase our cloud and increase our capabilities is very unique with the type of traffic that we see, and again, at these types of margins. From an operating expense structure, very leveraged operating expense structure. Over a third of our employees are in India. We have two locations, one in Chandigarh and one in Bangalore. Our intention is to continue to build that capability in India. A third of our employees are here in San Jose, and a third the rest of the world.
Very distributed type operating structure, very leveraged. If you compare us to other companies, the cost per employee, I'm sure it's one of the lowest, if not the lowest on the market. As Jay mentioned, the two pillars that we've had is ZIA and ZPA, with the Zscaler B2B as well as the ZDX, the digital experience. It's a big market opportunity. Even at $20 billion for ZIA and ZPA, a very large market opportunity. When you add the other capabilities that we have, along with CASB, the market opportunity just starts getting really big. That was one of the beauties for me, or one of the things that really took me when I talked to Jay for the first time, and I took a look at the platform that's been created.
Coming both from a security and networking background, not a technical person, but with companies like NetScreen, which got sold to Juniper, also Infoblox. I took a look at the platform which was created for tomorrow. That's what Zscaler built. When I take a look at legacy companies who've built appliances, it is awfully hard, as we've talked about, retrofitting those appliances into a cloud. That's what these companies are trying to do. They have no choice. Zscaler, clean slate, 10 years ago, built the platform to go forward. As you can see, we have additional capabilities that we've put on that platform. As we go forward, you'll see additional capabilities.
The advantages of Zscaler also is that our engineering organization, which is absolutely outstanding, the speed that they develop these type of applications, when you're doing it on a purpose-built clean slate, is a lot faster than what you can do as an appliance company trying to cobble things together and hope that they work. Going back, related to how we sell, professional bundle, I won't go over this in detail, is 1x, 1.5 for business and 3x, but I think most of you have seen this. The transformation bundle includes firewall, cloud sandbox. ZPA basically doubles that. The new product platform, we expect to significantly increase that. Secured transformations gone from 35% last year at the time of public offering was above 20%, and this year it's at 43%. That's when companies decide to go local breakout.
That's when companies basically are going all in with Zscaler. That's what makes our product very sticky. We are a large enterprise-driven company. Over 200 of the G2K in fiscal 2017, over 300 in fiscal 2018, and over 400 currently in fiscal 2019. What's impressive is the average ARR has gone up about 50%, from fiscal 2017. It's gone from $306,000 ARR per customer up to $467,000 per customer. Customers are buying more, reflection of our ARR. With the additional capabilities we're putting on our platform, gives us the ability to increase that. I would expect that to continue to increase. If you take a look at the penetration of transformation at 43%, we'd expect more companies to go full transformation. You look at ZPA being 14% of our new and upsell business in fiscal 2019, up from 10%, large opportunity for customers to buy the ZPA.
With our CASB capabilities in the future, as well as the digital experience in B2B, those should increase our average ARR fairly substantially as we go forward and provide those applications and capabilities to our customers. Revenue's gone up significantly every year, 50%, average over 50%, on an annual basis and quarterly basis. We're a subscription model, which basically, it's ratable, so it's an easy thing to basically predict. Annual billings up over 50% to $390 million. Comment we made, first half full year billings, we only have four years, but over the last five years, and this is also within the 43%-44%. With Dali coming on board, we've said that expect 42%-43% in billings in the first half and a little bit more than normal in the back half.
One of the things that I've talked about also is that, coming to Zscaler, and I've mentioned this many times, I'm not concerned about our operating profitability or free cash flow. If you take a look at the state the company is in, or the size the company's in, to have these type of results is outstanding. We have a huge market opportunity. When we gave guidance, we gave guidance lower operating profitability in fiscal 2019 versus fiscal 2018, primarily related to so that we can make the investments in the company to exploit this market. There is no company in the world with the platform that we have or the ability to capture this market like Zscaler. What it's going to come down to is our execution. One of the missing links that we had was Dali.
In working, talking to Dali over the last few weeks, I am excited having Dali on board and the capabilities that he can bring and continue to execute. Our execution in the past has been 50% growth year-over-year. Having Dali on board, I'm excited to see how things work out. Operating profitability 8%, in fiscal 2019, free cash flow 10%. When Jay set up the company, as I talked about, he did all the right things. With the India operation, we take a look at the R&D people in India, our R&D employees. I asked one of our key engineers, I said, "How would you compare the India employees versus the U.S. employees?" He said, "One for one." That's the type of capability and strength we have in India. You're not going to hear that from many companies.
The reason for that is because that's the way the company was founded from the very beginning, with a significant India influence, with strong employees in India, driving the culture and the success of the company. From a revenue perspective, pretty much 50/50, right across the board. You don't see this very often, if ever at all. Most companies start out 80/20 U.S., 20% international. You get to maybe 60/40 over time, 55/45. We're at 50/50 currently. From a long-range model perspective, you can see, for our guidance, we didn't come out and say 80%, but that's pretty much we target internally. If we stay in that 80% range, we're happy. Non-GAAP operating profitability, 3%-5% down from the 8%. You can expect sales and marketing to be up a couple of points. Again, we're an innovation company. You saw all the products that we're coming out with.
I would expect R&D to be up a couple points also. G&A in the same range, maybe a little bit lower. I mentioned, the non-GAAP free cash flow, couple points below the non-GAAP because of the things I had mentioned, Symantec and the new building and the duplicate facilities. Long-range model, no change. From the time of our public offering. When we went public, just to remind people, I said we'd get to sustained operating profitability, positive free cash flow sometime in fiscal 2020. We basically got there right out of the chute. I also indicated that we'd get to this model when we got to $800 million to $1 billion. The reason that we put out that guidance is because we wanted to give ourselves all the room in the world to exploit this market and make the investments that we want.
In fiscal 2020, with the development that we have in R&D, with Dali coming on board, we're going to step on the gas. With that, what I'd like to do is get the team up, then we can take questions all together.
Yeah, we can get the team up, but maybe take a couple specific questions for Remo before we open it up for the other execs as well. Okay, I'll take one here.
Fatima Boolani from UBS. Thank you for taking the questions. Remo, around the time of the IPO, you talked a lot about contribution margin, and I wanted to understand with the product portfolio having expanded, with your sales reps landing customers with both ZIA and ZPA at an increasing incidence, I'm wondering if you can just refresh us on how those contribution margins have trended over the last 18 months since the IPO. As Dali's thinking about accelerating the velocity of land and expand, what sort of impact should we expect that to have on contribution margins going forward?
Yeah, good question. Things have really not changed with the contribution margin. The first year, basically, it's high expense related to landing customers. You look at years two and three, the contribution margin's in the 60+% range. I really don't see that changing. When Dali gets on board, we'll see how it all plays through. I wouldn't expect a whole lot of change with that.
Dan.
Yeah, Dan from Wedbush. My question is, with Global 2000 customers, ARR right now trending about half a million, is there any reason that shouldn't hit seven figures in the next few years, especially with Dali on board? Thanks.
A leading question. I can't really go there. I don't have a crystal ball. We are a large enterprise-focused company. I think that the number one thing with Zscaler is basically our execution. We've got the platform, the delivery mechanism at high gross margins. We got reliability, scalability. We got the infrastructure in place to grow the company. We just need to execute. I think that from my perspective, when I take a look at the landscape for companies, it's really complicated. What Zscaler does, it basically simplifies it at a low cost. I would hope that we'll continue to see increases, and we should see increases in that Global 2K.
Alex Henderson over at Needham. I was hoping we would go back to the delays and the deals that were pushed out. There seems to be several possible variables that you've highlighted, but one of the ones you didn't talk about a whole lot is the bias that you're having to much larger, much more complex deals, which ultimately means there's more boxes to check, more process that has to happen within the customer. That could just as easily be an excuse for why that occurred. Can you talk about the size of the deals that were pushed out? Were they biased to very large deals that inherently take longer and hence may it be a function of you just getting bigger and the deal sizes you're chasing?
Yeah. That's a good question. When I take a look at our deal sizes below $500,000 new ACV, our growth rate year-over-year was substantial. When you take a look at our growth rate over $500,000 in new ACV, that's where we saw some slowing down of the deal sizes. Again, from my perspective, as you get bigger, as Dali said, things change. I also think that basically, putting a sales enablement process into place, knowing when to go after deals, when to pull out, selling value, I think that's what we're going to do going forward. I would expect things to be strong for us.
Hi, it's Tazeem Essap from Guggenheim. Remo, you've spoken about your durations ranging from one year to three year for your deals. Can you talk about the trend in that duration over the last couple of years? If you look at the blended duration across all the deals, how has that trended since IPO, even before IPO to now? Has it gone up a lot, or has it remained pretty much the same?
I would say it's been pretty close to the same. We made a push before I got at the company that we'd push three-year deals. Since I've been here, when you take a look at three-year deals, over a four-quarter period, it really hasn't changed. It's been about 70% of our new business have been three-year deals. On a renewal basis, they're lower. Again, once a customer goes annual, and you're trying to get into three year, it's a little bit more difficult. For new business since I've been at Zscaler, pretty consistent, right around three years. 70% has been three years.
The blended duration would be around two years if you look at the new deals?
Higher.
70% three years.
It's higher, yeah.
It's higher.
Yeah. I would say it's above 2.5 years.
For new deals.
For new deals.
Thank you.
Yeah.
Okay, now we're going to get all the execs up and have them available for any questions that you might have saved since the beginning of the Analyst Day.
We're going to stand.
Okay.
Thank you for taking my question. This is Yifu Li with Oppenheimer. I think Dali talked about earlier that usually corporations go from smaller customers to larger customer, and obviously Zscaler did the other way around, the harder route, going target larger customers. Going to Hamza's earlier question about the sales cycle was a little bit longer for some of the larger deal. Are there any plans to go be more focused on the SMB customers so as to lessen the volatility on the larger elephant deals?
All right, I'll answer that question. As I said during my section, we started from the top. We are going down. As Remo indicated, in some recent quarters, our growth actually in that enterprise space has been fast higher the growth rate than on the high end. We are making inroads in there. Going all the way down to SMB fundamentally changes the lead gen, all the stuff. Look at typically in the enterprise, there's one mix of sales and marketing. In the low end, it's a different mix of sales and marketing. We have an inside sales team that generates a small part of a business. It's an opportunity for us, but I think it's an incremental opportunity. Obviously, when Dali comes on board, we're going to take a look at it to see where all we expand.
To me, it seemed like naturally going down the triangle is a natural approach for us.
Just to add to that, I spoke about it just briefly. I'm a big fan of multidimensional go-to-market models and then unlocking which of the different tiers is going to be covered, either direct or with what type of partners. Because even you can parse the channel community into tactical VARs, which will engage with anybody, and more strategic VARs that do transformation for their customers. Identifying the multidimensional model, the elements of it, and what velocity accelerants are, is absolutely going to be something we look at. I'll tell you the last two and a half years, it's what's helped AppDynamics explode its business, by taking advantage of everything without diluting the productivity per head across the cohorts in each category.
We will be looking at it because the velocity and the opportunity is there, but we're not going to do it at the expense of top-line productivity trend.
Good.
Hi, everybody. It's Michael Turits from Raymond James. Thanks very much for having us to the user conference and for the day. Amit, you laid out this framework for how you're positioned implicitly relative to next-gen firewall vendors, born in the cloud, service edge, SSL inspection, and ZTNA. If you use that same framework, how would you position yourselves against the CDNs who are doing more in security and certainly were actually born before the cloud, and certainly still do edge, and Akamai in particular, is already doing something that you could call ZTNA.
Right. If you look at the Zscaler platform and what we have built, it is three things that have come together. One is this high-performance architecture that allows us to inspect without slowing down traffic. That's engineering. The second is physics. We have built these data centers across 150 locations where compute is present right there. There's an engineering challenge that we have solved. There's a physics challenge that I talked about, where we are not rerouting traffic and hairpinning and tromboning and incurring latency. The third aspect, which was implicit, is the domain expertise, the security domain expertise. All of these three things come together to deliver what we call the Zscaler service. If you look at CDNs like Akamai, they are very good at building data center footprint. Do they have some of the high-performance engineering? Yes.
Do they have all the security domain expertise? No. When you look at CDNs, they are front-ending servers. They are fanning a single server, like a wellsfargo.com or a Bank of America. They're sitting in front and sending content out so that multiple users can access it. Zscaler service fundamentally is sitting in front of users. We allow a user to go to any destination. While there may be a few areas on those three pillars that I talked about where, yes, the edge footprint might be there, but it's the coming together of all of those three things. Fundamentally the service, you have to look at one as front-ending servers and the other as front-ending users from a policy-based connectivity perspective, one user to every possible destination that you can go to, where CDNs are one application fanning out to multiple different users.
If I may add a couple of comments to that. It's important to understand user-facing versus server-facing that Amit said. Otherwise, security starts looking confusing. Take united.com, United Airlines. All traffic, all United employees goes through Zscaler for their protection. united.com website is not protected by us. It's probably redirecting when you type united.com, it's probably get redirected to Akamai or somebody for two things. One is caching, and second is probably DDoS protection kind of stuff. Their core competency is sitting in front of servers, and actually CDN is the biggest core competency. The DDoS of the stuff was natural for them to add because they're sitting in front of servers, though it's a new acquisition for them. Us sitting in line taking all traffic from all over the world is very different and very complementary than what they've done.
Now, your second question, is everyone trying to move into a different space? Yes. From SASE point of view, what Gartner said, CDN vendors don't really play in that game. The second part is the ZTNA. Being able to access applications, with Zero Trust, everyone's trying to figure out. We got a much bigger lead over others. Yes, some of the CDN vendors have tried to either buy technology or do something out there. If you look at the core space, where the vendors are trying to get to, we think we are actually in the midst of that core space, core competency, while others are trying to come from different strengths.
I can add on just one more piece. Don't discount the combination of Zscaler Internet Access with the Zero Trust Zscaler Private Access together. Companies, to do that well, you have to deploy an agent. That's a very hard proposition than a CDN saying, "I'm going to do Zero Trust access for websites," and that's it. The combination of the two are very powerful.
Hi. I don't know if this mic works.
Turn it on.
Turn it on.
Turning on the mic. Hello? Hello?
Number 6.
Number 6. Oh, excellent. Thank you. Brad Zelnick again, Credit Suisse. Remo, if we take a look at your guidance, and appreciate all the color commentary you've given us around it and the increased investment this year, just given the massive opportunity. Specific to Dali coming on board and the playbook that he's going to run, can you give us a sense of how much is represented by the things that he needs to invest in terms of sales enablement, et cetera? He hasn't even arrived yet. Is there any chance that you didn't properly account for everything that he's going to need once he gets here and assesses what it takes to run his plays and implement his program?
Good question. I'll talk around it, but make some specific comments to it. Our growth rate in RSM last year was about 40%. Our growth rate that we're planning for internally for this year is 60%. Also, related to sales enablement and things that Dali's going to bring, we put some things aside for that also. We went into this planning period basically knowing that we had an opportunity to really capture this market. We knew that Dali was close coming on board, and basically, we wanted to make sure that we gave him the runway and the resources, basically to do the things he needs to do. In addition, one of the things I want to talk about, which is separate, is that the 42%, 43%, that is to give Dali the runway, let's say.
As Bill mentioned, the new products, don't expect any revenue this year. We're not planning for any revenue for the new products. The Appsulate acquisition, it's going to increase expenses $7 million-$9 million. I think we made that comment a couple of calls ago. We're looking at this year as a year of investment. I am not concerned at all about our operating profitability or free cash flow. Zero. I am concerned, making sure we make the proper investments to really exploit this market and take the FUD out of this market so that our customers can realize the benefits of Zscaler, which is really the next generation networking security company, and I think the best one in the world.
Thanks, Remo. Is Dali still on? Can I ask him a question?
Of course.
Awesome.
Yeah, I'm still on.
Thanks, Dali. Dali, can you maybe just share with us any prior examples from your career where upon arriving somewhere in a situation such as this, the amount of time that you think it takes just to appraise what the state of the state is and what the work is that's cut out ahead of you?
Yeah. I'm not going to comment on time just because it would be speculation at this point, but why don't I give you some conceptual viewpoints, and then hopefully it gives you the data you're looking for. If you look at AppDynamics, my last spot, it was really a single digit, seven-figure to quite the large growth ratio. We built it, and we built it in layers. It's a little bit different than here, but the concept of building things in layers still applies. Doing it in a very systematic way is not disruptive. Doing it in a way where it's accompanied by templates and enablement allows people to learn, right?
If you look at my prior experience at BMC, for example, where I witnessed and participated in and learned from what it meant to really take a business that was sleepy and completely turn it around within six months. Same thing with the right sales culture, with the right talent, with the right enablement framework, with the right metrics being measured and impacted and coached to. That was a major overhaul project that was completed within six to nine months. Then you look at Z, to Remo's point, you can't disregard the growth that this engine is already producing. Clearly, there's some great elements in place already, right?
The goal really is going to be to take 30 to 60 days to evaluate all data, build models where none exist, and evaluate talent, hire top talent, and speak to as many people as possible, and speak to as many customers as possible to get a complete picture, right? All the while making incremental progress. I'm not a fan of standing still, and I'm a fan of iterative progress and sometimes even pulling back if it wasn't the right step and doing it quickly.
I can't speak to the time, but I can speak to the sense of urgency, and I can speak to the fact that there are already great elements in place, so we're not having to build from scratch or redo or undo things. That obviously is always a positive. I did dig into this, and I'm going to answer a prior question a little bit, too. One of the points that I did discuss in great detail with both Remo and Jay, was the types of investments that would be required in order for us not just to scale this for now, but to build a scalable engine so that we never talk about worrying about scale again. What that would take this year and in the years out.
I can say with complete alignment, all of us left the meeting on what's required and what we're committed to and what we think is going to be the winning formula. I don't see any surprises, and I see a solid plan being laid out, which is part of the reason why I'm obviously very excited.
Cool. Thanks.
Great. Thank you. Andrew Nowinski with Piper Jaffray. I just want to start with a clarification. Palo Alto says they now have over 100 onboarding locations, which substantially improved their performance. Are the onboarding locations they're referring to the equivalent to what you call the front doors, where there's no compute capabilities and therefore their performance didn't actually improve?
Hey, Amit, before you answer the question, they said 100 onboarding locations, and how many data centers did they say?
They didn't say data centers. I think.
That tells you something, right?
You can look up Google Cloud GCP. GCP, when I last looked up, reports 20 compute centers, right? 20 regions, and on an average, about 6.7 front doors or onboarding locations for each of them. As I described in my presentation, if you are Google and Microsoft, you're building these giant football field-sized data centers, it makes sense to aggregate them in certain locations. It's wonderful if that's your ultimate destination, but if you're trying to run an edge service where you need to come in, get inspected, and go out, it's a physics limitation, right? The short answer to your question is yes, it's 100 onboarding location. Think of it as just as a router. It accepts traffic, and then over a private circuit, it ships that to one of the compute regions.
That's where you can physically run a virtual firewall, and then you come back and then go to where you have to. If the whole world was located inside Google, perhaps that would work, but that's not the case. A user needs to go to many different destinations. Fundamentally, what Zscaler has done is in every one of 150 of those pops, our compute is sitting right there. On top of that, we do app neutral and carrier neutral peering with not just one provider. We peer with Google, we peer with Microsoft, we peer with Akamai, we peer with Apple. A user gets to the compute as soon as possible, the entire security stack, all their policies show up, and then a millisecond or two hop away is the front door of whatever service or destination that they go to.
We have invested heavily in carrier neutral colo facilities where the bulk of the internet is pulsing through. We're right there. That's really what you need to do to deliver this high-performance service where you get all your security without any user experience compromise. That's FUD when you hear front door equals compute. That's absolutely not the case.
Okay. Then I just wanted to go back to an example you provided on downloading a file that only took you 22 seconds with SSL scanning enabled.
Right.
I guess in the debate of proxies versus firewalls, you pointed to SSL decryption as one of the key differentiators.
I believe you're both using commodity hardware chips to do that. Why is your performance so much better, and why can't the firewall vendors achieve that same performance level with SSL decryption to that?
Great question, right? I touched upon this in the presentation, but let me reiterate. First things first, to do SSL inspection, you need to have a lot of compute resources, right? That's a fact. If you try to run a virtual firewall in AWS or GCP, none of these infrastructure vendors give you hardware accelerators on their platform to begin with, right?
Amit,
Specialized hardware
Chips et, right?
For example, we run all our infrastructure on bare metal. These are Intel servers. We use Cavium Nitrox cards to do SSL acceleration. That's one bit of it. Over the last 10 years, we have refined our TCP/IP stack, our SSL drivers, to squeeze every ounce of performance. We started as a proxy architecture, we had no choice. We assume that the world is going to be 100% encrypted. As a proxy, you have to intercept, you have to look at content. That's what we designed for. Firewalls were designed as a layer 3 device looking at source IPs, destination IPs, throwing a bunch of DPI to detect app IDs and things of that nature.
At the end of the day, if you have to do any meaningful DLP or any meaningful security these days, you have to decrypt, you have to look at content, and then you need to fire all those engines. The reason why, you saw the NSS Labs report. All of these firewalls, when they bolt on a proxy, they suffer an order of magnitude performance degradation, right? Because the drivers are not tuned, and when you move that over to a virtual setup like AWS and Azure, you don't even have hardware accelerators that you could derive some extra performance from. Those are all undisputed facts, right? People will try to muddy the water saying, "Yes, this all works," but those are undisputed facts.
The other comment I could make is there are architectures you design for. You don't change architecture overnight. You can add a feature or function to it.
Designing your inspection check device for proxy architecture or a passthrough are fundamental decisions. Once you make the decision, unless you go and rewrite your stuff, you can't change it. That's where this thing happens.
If I could add one more emphasis on the fact that, to Jay's architectural comments, we're multi-tenant from the beginning. There is not a marriage of a customer to a VM in our architecture. That gives us crazy economies of scale.
Right
that only true multi-tenancy will do, meaning we have a pool of resource available to do SSL. SSL is expensive no matter what, at the end of the day. That pool is shared among all of our customers, not a VM that we deployed that was still a single-tenant VM in a particular compute region for that one customer. We have scale across all customers sharing a common pool. That gives us a crazy advantage.
Another way to look at it is from an infrastructure load perspective, for Zscaler, there isn't any difference between one organization with 100,000 users or 10 different organizations with 10,000 users each. If you had a single-tenant architecture, you remember the Netflix DVD example I gave, you will have to spin up 10X more virtualized infrastructure because they were single tenant to begin with, right? You do not get to use that pool of capacity that is available. That pool of capacity is limited given the fact that AWS and GCP do not give you that bare metal performance that you need for SSL interception.
Hi, it's Howard from Jefferies. I have a follow-up on Palo Alto Networks. In the last couple of weeks, there's been some noise in the market following Palo Alto Networks' analyst day in which they mentioned some competitive wins, including a top 50 customer from Zscaler. Do you dispute that commentary? Could you provide some additional color? Thank you.
Yeah. I thought I was pretty explicit in my earnings call. Did you listen to it? Did you?
I did read the transcript afterwards. Thank you.
Okay, what more clarity do you want? This is what I said. I said, "I personally know every customer where there were 1 million users." Okay. Do you think that customer go get displaced and we don't know about it? We haven't seen any change in that. The second comment was they displaced the Fortune 50 retailer. I personally and my team, every Fortune 500 customer that Zscaler has, they're all happy and working with us. I don't know where the numbers came from. It's silly. That's all I can say.
I appreciate you hitting the point home.
Thanks.
Hi, Alex Henderson, Needham again. I wanted to ask a question about the data lake that you described building. Clearly, the architecture that you've described is an edge architecture with edge compute, but a data lake generally is a centralized architecture. How do you put those two together and how are you designing that lake? Can you talk a little bit about whether you're going to do a CrowdStrike-like threat graph, or what are you doing with that information and how do we think about that performance? It hasn't really been fleshed out at all.
Right. Designing a proper logging architecture was a day zero design consideration for Zscaler. What we did when we started building this platform was to separate the control plane, which is where policies reside, from the enforcement plane, which is the high-speed inspection, from the data analytics and storage plane, right? Some of our fundamental patents around Nanolog are around the ability to live stream logs from any one of these data inspection points to log aggregation clusters. The reason we don't do one for one is because it helps with things like GDPR. Maybe I'm a European customer and I want to ensure that I get the best performance for all my users anywhere in the world, but I want my logs to be written and stored in Geneva, right? We have the ability to live stream that.
This is one of the strengths of the platform. Any user log on any 150 of our data centers will show up within a second or two on the administrative console because of the fundamental architecture that we have built for logging. Once you look at the volume, 70 billion transactions a day, each log line itself is about two to three kilobytes of data, right? It's a staggering amount of information. A lot of the engineering that we did around was how do we compress that 50 to 1 and still be able to provide live streaming analytics. The reporting capabilities of the platform is one of our strengths. Now contrast that to what happens when you do a hybrid architecture. In a hybrid architecture, here's the reality, you should go and ask all the appliance vendors. Here's my firewall.
That firewall is dumping logs locally on that box. There is some cron job somewhere that is trying to pull these logs from different sources, trying to put it together into a data lake. If you have portion of your service sitting in AWS or GCP, well, that logging might be different from what is happening here. The amount of storage there dictates how many days of logs you can do. Think of it from a privacy perspective. I'm a Fortune 100 company. Now I have my logs spread across hundreds of these boxes. If a user comes and says, "I have the right to forget. Eliminate my logs from everywhere," there is no way you can guarantee that. The Zscaler architecture was designed so that the data enforcement plane never writes anything to disk anywhere.
Everything is sitting in RAM. Then we use these high-speed streaming services to send the logs to the designated log cluster. If you are the CIO and you say, "For my Fortune 100 account, I want my logs written to a disk underneath my desk," we can guarantee it by design, and it won't be written anywhere else in the world. Right? Those are some fundamental engineering problems that we have solved, and the reason why you see us launch ZDX and Zscaler B2B is that core platform is providing all of those services, then we can just easily re-leverage. When we talked about ZDX this morning, what is the biggest challenge for other troubleshooting vendors? If I have 100,000 end users, how do I log everything from every one of those devices every five minutes? It's a staggering logging problem, right? We've already solved it.
We are doing that for every transaction. For us to add that incremental telemetry data is something very simple and trivial. That's the power of the platform that we will continue to re-leverage as we launch newer and newer initiatives.
If I could ask a second piece to that. In regards to the CDNs, they all get some benefit from sitting inside the service providers in terms of improving the performance of the service provider. They get free bandwidth or free location, reduction in cost. Can you talk about your positioning against that functionality? Are you also seen as one of those edge providers that in fact improves the performance enough for the service provider or partner enough with the service provider to give you that value that you get that reduction in cost associated with those relationships?
Right. I can add a comment.
Yeah.
First thing I'd mention, I think this question was similar to CDNs versus Zscaler, right? Again, fundamentally look at that problem in those three buckets. There's an engineering problem. We've talked quite a bit about what it means for high-speed inspection, what it means for logging, all of that stuff, right? There's a physics problem, which is your compute needs to be right next to the users and destinations. We've solved that. The third aspect that I want to double-click on is the domain expertise. We're running a security platform. Our security platform is getting 120,000, 130,000 unique threat indicators every day, right? How do you ingest that? We get feeds from 40 different security vendors. We get feeds from VirusTotal, from Google Safe Browsing. We are part of Microsoft MAPP program. All of these things are coming in real time. How do you ingest all of that information?
How do you update every minute so you don't disrupt the user experience, right? All of that is a lot of security domain expertise and engineering coming together. While CDNs, yes, they have some edge footprint, right, and they have front-ended servers. I think to deliver a Zscaler service, all those three things have to come together.
Yeah.
High-speed engineering, your edge architecture, and a lot of the security domain expertise that we have refined over the last 10 plus years to be able to do that in line.
Amit, there's a second part of the question. I think what you said is sitting there, the bandwidth benefits you're getting. A few years ago, internet peering at exchanges was not very common.
Right.
In fact, three, four years ago, every service provider was talking to Microsoft and said, "Hey, I'll sell you special exchange. You come to me, and I'll take you to Office 365, ServiceNow, and wherever pretty quickly." They're very excited about it. What has happened in the past three, four years is internet exchanges. There are something on internet exchange, as the word exchange means, for a very nominal fee, any provider of content can become participant in it. A typical exchange in Chicago or New York may have 300, 400 providers there. Who are these guys? Either they are bandwidth providers, like service, or actually majority of them are content provider, Google, Salesforce, Apple, Zscaler, all these people are there. Once you get there, for a nominal fee, you're part of the exchange. Now you're one hop away.
The advantage of being sitting next to the telco exactly hasn't become good. In fact, we debated should Zscaler data center be sitting with AT&T, Verizon, or BT? The answer came back in their data center, answer was no, because we needed carrier neutral data centers, Equinix or Telecity or Global Crossing, because in those places, generally all carriers try to come. Because of peering, when your volume is large, we actually get a lot of benefit of bandwidth savings.
Right.
Which is a good thing. We are taking full advantage of it. We are extremely well-peered.
Right.
That's a big plus.
You can, for example, if you go to PeeringDB, right, you can see Zscaler listed. Our AS numbers are listed in various internet exchanges, because we are a true cloud service. You should do the same checks for some of the appliance vendors and see if they are present there, and the answer would be no, right? In some of the internet exchanges, we are right up there with some of the biggest cloud service providers. You'd see Verizon, Netflix, Zscaler in the same kind of screen on the PeeringDB website. That's a very important point. Being carrier neutral, being app neutral, being able to connect a user on the fastest path with the application they care about is the most important criteria for us.
I want to thank the team. I'd like to thank the analysts and investors who have made themselves available with your investment of time to learn more about Zscaler. Hopefully, we gave you a lot to think about what the next world looks like for cloud and mobile. We'll be here to take additional questions in the room. I will conclude our program here. Thank you.
Thank you.
Thank you.