Zscaler, Inc. (ZS)
NASDAQ: ZS · Real-Time Price · USD
212.25
+10.45 (5.18%)
At close: Oct 6, 2026, 4:00 PM EDT
215.12
+2.87 (1.35%)
Pre-market: Oct 7, 2026, 5:13 AM EDT
← View all transcripts

Investor Day 2026

Oct 6, 2026

Summary

The strategy pairs an expanded Zero Trust platform with AI-led demand and four go-to-market levers. Three growth engines grew ARR 60% in FY26; the base outlook targets over $8B ARR by FY31, with a faster-AI scenario pointing to $10B.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Hello, everyone. It's my pleasure to welcome you to Zscaler's 2026 Investor Day. Whether you're here with us in New York or you're watching on the webcast, we really appreciate you taking the time to be with us today. It has been five years since we hosted an Investor Day. During that time, we've grown into a broad and integrated platform built on our Zero Trust Exchange. We have a great lineup today to tell you more about our evolution and to help you come away with a better understanding of our strategy, our product differentiation, and our growth drivers. Jay will kick us off and take us through Zscaler's vision and strategy, including how our solutions fit into the changing cybersecurity landscape.

Next, Adam will take us back to basics and introduce the Zscaler platform, followed by Dhawal, who will talk us through AI security and data security. That's an area I know many of you would like to know more about, so listen up. Then Dhawal will host a panel with three customers that we're very grateful to have with us today. They'll be sharing their security challenges and their journey with Zscaler. They'll also be available to take your questions, so start thinking about what you might want to ask them. After a short break, our new CRO, Ross Tackett, will introduce himself to all of you and share our go-to-market strategy. Then Kevin will finish us up with some financial perspectives. Then we'll welcome all the speakers back on stage and take all of your questions.

For those of you here with us in New York City, after that, we'll invite you to join us for lunch and a reception, and we also have some demos of the products that we'll be sharing today. So make sure you hang around for that. Now the part that everyone loves, the forward-looking statements. Before we begin, I'd like to remind everyone that today's presentation contains forward-looking statements within the meaning of the safe harbor provisions of the federal securities laws, including statements regarding our future financial performance, business strategy, and market opportunities. These statements are subject to risks and uncertainties that could cause actual results to differ materially from those projected, and we undertake no obligation to update them.

For a more complete discussion of the factors that could affect our results, please refer to the risk factors described in our most recent filings with the SEC, including our annual report on Form 10-K and quarterly reports on Form 10-Q. With that, it's my pleasure to introduce Zscaler's CEO, Chairman, and Founder, Jay Chaudhry. Jay?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Good morning, everyone.

Great. Thank you all for joining us this Zscaler's 2026 Investor Day. As you heard from Kim, we have a great lineup planned for you this morning, and I am excited to hear from leaders across our business. Overall, we expect you will leave today with three key takeaways. Number one, Zscaler is the cybersecurity platform for the AI era, and AI is the most powerful tailwind of driving our business. Number two, we are capitalizing on this opportunity by expanding our platform and strengthening our go-to-market muscle. Finally, we are multiple growth engines that we expect to drive our re-acceleration in the years ahead. All right. Let us get started. Zscaler takes me back to 2008 when I started the company, when we pioneered Zero Trust security. The term Zero Trust was not well-known, but what we came up with the idea was trust no one.

Making the internet and advanced technology safer to do business was our primary focus. We are not focused on building the next generation firewall. With this, our vision was ushering in a world where people, devices, and AI agents can communicate and innovate securely. Security should not be holding them back. We achieved a lot in the past some 18 years or so. Look at the numbers. Over 50% of Fortune 500 companies. 750 billion daily inline transactions we inspect and enforce policy. Over 200,000 locations. These are public, globally distributed, and there are many more private ones. Over 1,000 patents issued and granted. Lots of cool technology. We are essentially about innovation. The new approach to security we took was driven by the fact that in my background, where I spent over a dozen years before starting Zscaler, doing security.

I have seen more and more security products coming and more and more breaches happening. I was convinced that the traditional way of doing security, by building these moats with firewalls, was not going to work. The new approach was, entity A should be able to talk to entity B through our exchange, our switchboard. Literally like a phone switchboard in the old days. You know, in the old days when you called, you said, I want to talk to John. You got connected to John and John only. Then you said, I want to talk to the President of the U.S. they said, sorry, go away. You are not allowed to. Simple concept Party A can only talk to party B as opposed to the old concept. Everyone is in. Now let me try to put the guards that are on firewall here, firewall.

That was the simple concept, the simple idea. The goal was fundamentally twofold. One was stopping threats no matter where they come from. Two was protecting data. Two basic things. While we started with users, that architecture designed to handle any entity. Today, we handle devices sitting in plants and factories. We handle all kind of AI agents. The most exciting part, we have taken it to cloud workloads and third parties and like. They should be able to access the right data sources. They could be AI models, could be applications, SaaS applications, agents, and whatever tools. It is very exciting platform, and it is probably far more needed today than it was ever before. Now, I want to talk about why Zscaler is winning the business and why we have a durable growth opportunity at Zscaler. Four simple areas. Architecture matters, and you cannot fix it overnight.

A unified, integrated platform takes time to build. You cannot buy a bunch of companies and call it a platform. Removing cost and complexity, and lastly, our go-to-market engine. Let me walk you through each of the four areas. The first is our architecture. Many times people get confused between architecture and features. Architecture is the foundation. Features, you can add on. You do not build foundation every day. Now, our story starts with building disruptive solution, disruptive technology. I have always liked not to build me too, but a different, better way of doing it. Mobility played an important role in Zscaler's success. That is a big mega wave. Cloud was the second mega wave that helped us because in the world of mobility and cloud, the old security based on firewalls and VPNs made no sense.

We leveraged those two mega waves, and now we see the AI era. I call it a giga wave because it is going to change things. It is already changing things, and AI is the largest tailwind we have ever witnessed. We are already seeing early signs of it, and we think there is a lot more to be coming. Now, AI. There is hardly a meeting that goes by where AI is not part of the discussion. I do lots and lots of customer meetings. Last week, I was in Dallas meeting 80 CISOs of large enterprises. Every discussion starts with, my CEO, my board is asking me to really roll out AI solutions at a faster and faster pace, because CEOs are convinced, and rightfully so, that it can accelerate the top-line growth, and it can also drive efficiencies.

But they are all worried about some of the challenges, especially the cyber issues they have to deal with. I want to talk about how we deal with, how we help our customers with cyber risks to manage them so they can effectively start rolling out solutions. There is cost and complexity of the current infrastructure they need to deal with. On top of which, rolling out AI becomes very, very hard. So the tailwinds for Zscaler platform can be put in two buckets. One is frontier AI attacks. These models are powerful, these models are dangerous, and we will talk about how we empower our customers while mitigating the risk. The second part is AI agents. Agents we deploy or agents other deploy, agents going rogue. How do you use agents effectively? Let us start with the risks posed by frontier AI.

For that, one needs to understand how most of the world has worked in the past. The way technology's done is I'm going to build my application portal, my mobile portal, and put a VPN firewall, load balancers in front of it, and it's all open to the internet, so people can come over the internet and connect with them. That is good. But the more things exposed to the internet, the bigger the attack surface. We had some amount of attack surface before AI. Now, AI is further increasing the attack surface. You're adding AI chatbots. You got MCP servers, you got AI agents. The attack surface is getting bigger. We call it attack surface because anyone from the internet can scan you and find you. That was there before, but now, once they can find you, with AI models, they can find all kind of security vulnerabilities.

It's unbelievable how many vulnerabilities can be found. Once they find them, they compromise it, and then the game gets over. That's a lot of these breaches are happening. So the risk of frontier model is exploiting these vulnerabilities and the gap between discovery to exploitation, which used to be months, is now becoming minutes or seconds. That needs to be handled, and you can't fix it by putting on more DDoS protection, more firewalls, more VPNs. Here's a real-life example of a customer. It's an energy company. Rather than reading all the stats, I'm going to highlight three things. Internet-facing assets. These are exposed infrastructure. Your application, your firewalls, your VPN, your load balancers, and all those things. About 6,614. It's not an unusual number. That's what we see in large enterprise. For that enterprise, 1,049 software vulnerabilities. One thing worth highlighting, VPN appliances, 40 of them.

It's easy to find every other week, you see some VPN got compromised. This is the landscape you're dealing with. Models, these frontier models can exploit them very easily. How do you fix them? Not by more of those things, but simply using a different architecture. The Zscaler world, all applications that require authentication are hidden behind the Zscaler, and attackers can't breach if they can't reach. Very simple, elegant architecture. That's what our customers get very proud of, because simpler but great solutions. The second area is the lateral movement of threats. Once they compromise a firewall or VPN application portal, the malware moves laterally. How does that work? I tried to explain that concept. Generally, it get confusing between networks and all. So I came with a new idea. Let's use the highway metaphor.

Just like highway connects different cities, that corporate network, that private network connects your data centers, your SaaS application, public cloud, your neo clouds, and all the branches and everything. The goal is once you get on the corporate network, you move left, you move right. That's a part, job of the network. That's wonderful. But now we got, first of all, more applications on top of what we had. We got AI applications, we got agents and all that stuff happening. What can bad guys do? They can get on your corporate network, they can move laterally, they can reach targets and cause breaches. It used to be hackers before. Now you're going to see more and more AI agents acting autonomously, being able to do this job. That's a big risk that needs to be dealt with. Let me give you an example of real life.

We have been reading about Hugging Face and OpenAI agent. How did it happen? Well, OpenAI had this agent in a sandbox. It got out of sandbox. It got on the network. It moved laterally. Then it got to found a way to the internet, and then scanned. It found Hugging Face website. Then it discovered vulnerabilities in the website, and then it breached it. Simple concept, but this is a great example of how breaches happen. I wonder why people are surprised about it. This has to change. Architecture has to change. That architecture is going to help us. Now, one other point. Today, we worry about users being the weakest link. Tomorrow, agents will be the weakest link, and far more dangerous than people because they can move at machine speed. They need no coffee break, no weekend, no evenings, no vacation.

The numbers keep on growing. That's the big risk. How do you fix it? By taking and adopting a different approach. That's where Zero Trust comes in. Remember I said in Zero Trust architecture, entity A talks to entity B through a switchboard, to an exchange. That's a simple policy engine. The difference the old approach was, you put everyone on the network. Now you try to kind of control who goes where. This is the difference. That's why you can't build it on top of traditional security. You can't bolt on Zero Trust on firewalls and VPNs. Let's move on to the second area, and this is our comprehensive and unified platform. We started Zscaler with securing users. First of all, internet. Second, for private applications that you knew ZIA, ZPA.

In 2018, when we went public, we had just one product, ZIA, and investor used to ask, would you really be able to go beyond ZIA? Look at the journey we've come along. We built full Zero Trust for users with intra access, private access, and user experience. Then we added a branch because branch and devices must be Zero Trust. The big risk out there is these networks that are like a mesh network, everything connects to everything. Whether you have MPLS or SD-WAN, you have risk of lateral movement. We brought the solution where each branch is simply like an internet cafe. It's an island of its own. Each device in a factory or plant is isolated. It can't infect each other. Very powerful technology. I told you years ago that MPLS had to go away because with Zscaler architecture, everything will go direct over the internet.

People kind of thought that was a crazy idea. I can tell you it's a matter of time. You'll find that SD-WAN used to be something. Today, when people talk about Zscaler's competition, they compare us to SD-WANs the world out there. Really, we'll show you how our customers are embracing Zero Trust Branch, and you hear from one of our customers about this story where they've done a large scale transformation from the old world. Zero Trust Cloud. More and more workloads and applications are being built in the cloud. How is security done in the cloud? Still the old way. Just like people used to do application lift and shift, and they realized that lift and shift wasn't a good thing, now they build cloud native applications. But they're still lifting and shifting security. You know how? Firewall boxes for east, west in the data center.

Now it's virtual firewall in the cloud. Firewall is an IP device. It's a network device that deals with IP addresses. This source IP can only talk to this destination IP. That is hard enough to deal in the data center. Think about dealing with lots of moving IPs when the workloads are ephemeral. How do you deal with that? Impossible. The best solution would be zero trust. You can say workloads in VPC A can only talk to workload VPC B. Powerful concept. Workloads with tag A can only talk to workloads with tag B. Those are the innovations we bring to the table. That's why our customers are so excited about working with us. The most exciting area of expansion of zero trust journey is AI agents. Dhawal is going to talk about how we really built.

We had the underlying core, most of the technologies in place. We had to build a number of things. We had to build MCP gateways, A2A gateways. How do you extract and analyze prompts? How do you figure out intent? Those are the type of things we built. But we're already sitting in the traffic path. We already distributed infrastructure. So we believe that we are in the best position to really provide the solution for controlled, managed use of AI engines. So this brings together to the overall platform that's integrated and comprehensive. Zero Trust SASE Everywhere. Users to branches, to cloud, to AI agents. On top of that, data security is fundamental, extremely important. Our customers want data security that's integrated one policy rather than five different data security products. In this area, we have very strong advantage. We have over $410 million ARR.

Probably if this was an independent company, it would probably be the largest data security company. We are the natural party to do data security because almost all data leaks the internet. We are sitting in the traffic path for that. Security for AI is the next big opportunity. If you're deploying AI, how do you secure it? Dhawal will get you deeper into that. The other new area we recently added is Agentic SecOps. SecOps is ready for disruption. Adam will take you deeper into it. But one comment I'll make is we have better, more meaningful data for SecOps than anyone else out there. Anyone who started building SecOps before a couple of years ago built it the old way. They may be using AI, but they were using AI to supplement something built for humans.

We actually built SecOps for AI agents for the native use. So what is our unique advantage for architecture and platform? Our scale. Scale matters. Scale will become bigger and bigger with AI. Cyber better protection because of architecture that gives us minimal attack surface and prevents lateral movement. A platform that covers everything for Zero Trust everywhere is number three. Number four are securing AI and data everywhere. It's hard to find someone who really can provide this security everywhere. Lastly, unmatched proprietary data. AI models are getting commoditized. There'll be special models and open weight, all this stuff, but private data will matter, and that's the unique and lasting advantage we have. Let's move on to the next topic, cost and complexity. If you look at a typical enterprise, this is what their infrastructure looks like. Everything connected to everything because they want to reach everything.

And trying to secure a firewall here, router here, switch here, all that stuff is very complex. It is hard to find a CIO and head of infra that says, my infrastructure is simple. Then they keep on adding more and more products on top of that. It is really a mess. What does it result in? Well, you got high cost, CapEx and OpEx both. Scaling challenge is a problem. Complexity. Complexity is the enemy of resilience, and complexity is the enemy of security. Those things need to be fixed. That is why you could not fix it by bolting on more and more features on an architecture that is 30 years old. You had to do it the new way, and this is where our Zero Trust architecture comes in. One other clarification. The word platform has lost meaning out there. Every company claims to do a platform.

Platform actually uses a common set of services for policies, some of the other stuff. That is a real platform. I see many customers talk about and said they got sold a platform. When they looked underneath, they found there is eight policy engines, eight product. That is a real quote from large retail in the U.S. who I met with about two years ago. We are very mindful of building a right platform. That is why even when we do an acquisition, it is generally a smaller tuck-in company, so we could integrate the solution and make it a part of our platform. If we do it right, we bring a lot of cost down.

In this simple example, the various areas, even if you exclude legacy sunk cost because that is already paid for and the customer want to say, let us deal with that in phase two, we are able to bring the cost down significantly. Typically, 30%-40% range is not unusual to take out. That is because we do not worry about the cannibalization of firewalls and VPNs and load balancers and those ExpressRoutes and the [inaudible] . All those things go away with Zscaler. Firewall companies have to protect the install base because if that goes out, their business hurts. That is why we can take a lot of this stuff out that others won't do. Let us move on to the fourth topic of why we win. It is our GTM engine. Our TAM. You have seen the numbers that started with Zero Trust for Users at about $62 billion.

It is moved up at $220 billion because all these platform offerings were added. These are very logical and systematic plans. We do not just go and randomly buy a product here, buy a product here. These are very synergistic areas, very well thought through. We are not trying to be everything for everyone. Okay. I will highlight that in the previous chart I showed our AI Security TAM of $24 billion. That is about 1% of the total TAM of AI spend that Gartner is predicting. Most of the conversations I have with CIOs, they tell me that they are factoring mid-single digits of the total AI spend for AI security. If I look at that 4% or 7% range, that will be in the $100 billion-$200 billion range. So we kind of left it outside, but just to give you a data point where the numbers come from.

How is AI helping you? Let me be more specific. First of all, these tailwinds are coming from first two areas, large attack surface and increased lateral threats. Those two things are bound to bring more breaches. We are already beginning early signs of that, which really means customers are appreciating more and more need for Zero Trust architecture. This will give us opportunity to sell new logos as well as upsell. Second area, we are beginning to see there is more traffic, there are more entities, there are billions of agents. Communication, when we secure communication, we are dealing with more traffic. That means exponential traffic growth, which will drive security consumption, which will drive upsell opportunities for us. Let me give you some real data points. Since Mythos preview program, we have done over 400 assessments with a large Global 2000 customers. What are we finding?

Well, as I talked earlier, large install base that needs to be minimized. Internet exposure need to be minimized, and that drives need for Zscaler Private Access. Lateral attack movement, which typical networking brings. We need to eliminate trusted network. Network should merely be the transport and plumbing. It should never be trusted. Zero Trust SASE, there is a solution for that. Attackers are scanning the targets once they get on the internet or once they get on your data center. Maybe in the data center, they get on the network, maybe in the data center, maybe in the cloud. We have honeypot technology deception to handle that. We are seeing meaningful increase in that demand for it. If breaches happen, then they take to data loss. So there is a bigger demand for data security. Lastly, AI is showing up, shadow IT agents showing up.

There is a lot of demand we are seeing at a pretty rapid pace with short sales cycles in this area. So these are tangible examples of the AI risks that are leading into growth opportunities. The four levers of GTM that Ross is going to expand upon. Platform, you heard the expansion story. New logo engines with the platform expanded with many, many areas to land on. We do not need to go through just one traditional way of Zero Trust for Users. You can start from AI side, you can start from data security side and others. Partner leverage, you spend a lot of time building a partnership. Global system integrators are especially useful because they actually help drive the transformation. Customer obsession. Our customers are very proud of what we do or what they do using Zscaler. You will hear from a few of them today.

Here is the stat I am very proud of. This is based on some data we analyzed. This is about nine or 12-month-old data. 285 CXOs, this is large companies. They bought Zscaler in two companies, went from company A to company B, called us. 84 of them in three companies and 45 of them in four companies. Very, very wonderful to see that. Our financials. Strong financials, you know the numbers, $3.8 billion ARR. That is about 25% year-over-year growth. Revenue growth in the same range. Net new ARR, which is indicator of near term how things are happening. We are seeing some very good results. Look, we started at 7% in fiscal 2025, took it to 14%. Our first half of fiscal 2026 was 10%, Q4 was 17%. It is moving the right direction.

We are going to keep it moving in the right direction, and there's enough opportunities to do that. We also manage our bottom line very well. Kevin will give you more about that. Here's what I'm excited about, the big opportunity for us with all that stuff. We think we can get to $8 billion-$10 billion by fiscal 2031. There's a lot of opportunities, the reasons I already stated, to be able to drive 17% CAGR on the base level and 22% CAGR is very much achievable. That's a potential upside for us. Very excited to build a business to take to those levels. Why invest in Zscaler? If I boil it down to four simple reasons, I stated enough about the architectural advantages. Others can't just copy architecture. It's the foundation, you have to do it right, and you have to worry about cannibalizations.

That's why you aren't seeing firewall companies building on Zero Trust. They may claim Zero Trust once in a while, but it's not there. The demand tailwind I talked about untapped go-to-market. There's a lot of opportunities in the customer base, as well as new logos for us to do, and very strong financials. So what are we going to hear today? For the rest of the presentations, our team will give you a deeper view of it. Platform expansion, Adam and Dhawal will share more detail about the platform and the recent innovation we have done. You'll have a chance to directly hear from some of our customers about this area. Ross will take you through our go-to-market engine and the steps we are taking to drive growth moving forward.

Finally, Kevin will share some financials and should give you more confidence in our path to $10 billion ARR, and provide a fresh look at a long-term financial model. Let's get started. I'm thrilled to welcome Adam Geller to stage. Adam.

Adam Geller
Chief Product Officer, Zscaler

All right. Thank you, Jay. Welcome everyone here in New York, everyone on the webcast with us. I'm excited to spend my time talking to you about all the new innovations we have in our platform, and I want to connect those to how we're enabling new growth opportunities for the Zscaler business. So we've been relentlessly innovating on our platform for the past 17 years to solve some of our customers' biggest cybersecurity challenges. This is leading to our key Zero Trust solutions, and we're delivering them for some of the world's largest organizations. We started with Zero Trust for Users well before SASE existed as a market category, and from there, we extended the principles of Zero Trust to branches, to OT, to IoT, and now we deliver Zero Trust SASE Everywhere. It's this foundational platform that's also enabled us to deliver new adjacent solutions over time.

So for example, we launched data security, and we started with our in-line Data Loss Prevention or DLP. We have since expanded that over the years to cover all of the important channels for DLP. So that is endpoint, that is data at rest, data in motion, data in the cloud, data in SaaS applications, even data on premises as well. Next, we delivered Security for AI, and this is a space where we have innovated very rapidly over the past several years. Dhawal is going to dive deeper into this right after my presentation. Most recently for us is Agentic SecOps. We just launched the latest update to our Agentic SecOps offering last month, and to do that, we have brought together our strong Agentic SOC product capabilities with our expert-led services around managed detection and response and managed threat hunting.

Jay mentioned this, the rise of AI-driven threats and the massive increase in vulnerabilities discovered by frontier AI models like Mythos. It has created a huge uptick in demand for Zero Trust solutions. What that means is Zero Trust is no longer just a strategic security transformation for an enterprise. It has changed. It is now become an urgent board-level mandate to help organizations protect themselves against AI-powered attacks, but also to help them safely enable the adoption of AI for the organization itself. The fundamental truth that existed, and this existed by the way, pre-AI, it is now more true than ever. If you are reachable, you are breachable, and this continues to be true for users and applications, and now it is also true for AI and for agents. The reality is, Zscaler as a company and as a product, excuse me, it was built for this moment.

It turns out the unique architecture, Zero Trust architecture from Zscaler that our customers have used so effectively to secure their users, it is also the best way to secure AI agents and to protect against AI-driven threats. We continue to expand our platform on the foundation of Zero Trust Exchange to solve the broadest set of cybersecurity challenges for our customers. We are going to share more details about our expanded set of capabilities beyond Zero Trust for Users and how this has enabled us to address even larger total addressable markets. But first, I want to come back to this point that Jay mentioned again, which is why does the architecture really, really matter? You may think of Zscaler as a network security company. We have a fundamentally different point of view on that.

Networks, whether it is a LAN, WAN, SD-WAN, VPN, whatever technology you are talking about, their whole goal is to connect things together. Zero Trust is not about connecting things together. Earlier, Jay touched on our approach to securing the agentic enterprise, and it is based around this premise and this principle here that secures any-to-any communication using business policies and not networks. Let us dive a little bit deeper into that. Our fundamental approach to security lies on abstracting away the network completely. That is the primary job of our Zero Trust Exchange. To us, that network, it is simply plumbing, and we never trust them. That means you never put the user, the device, or the agents directly onto the network. Instead, that is where we use the Zero Trust framework to connect entities only to the resources that they should be allowed to have access to.

So let's take that one step further. How do we do this? When an entity tries to connect to a resource, our Zero Trust Exchange is going to quickly run through a process in real-time to do the following things. First, we're going to verify the user or the entity. Second, we're going to establish what should they be allowed to do. Then we're going to bring together first and third-party signals, context signals, because we want to understand the user, the entity, the device, as well as the potential risk in whatever interaction is about to happen. Then finally, because we're in line, we're able to enforce a policy decision on what actions to allow and what actions to block or to deny. The net result of this is a dramatically more secure environment that can protect against the four stages of an attack.

The first step is, number one, we'll minimize that attack surface. This is by hiding applications behind our Zero Trust Exchange. This way, attackers can't even discover them. Second, if an attacker does somehow manage to get in, we prevent systems from being breached with our in-line cyber protection capabilities. Then third, we're going to prevent attackers from moving laterally across the environment where they're looking for those high-value assets. With a zero-trust model in place, everyone's untrusted, every device is isolated. That's how Zscaler customers operate their branches, their factories, and their cloud environments. Then fourth, we're going to use our in-line protection capabilities, data protection capabilities, across all channels to make sure that we can stop sensitive data from either being accidentally or intentionally exfiltrated out of the organization. So why does this architecture matter?

Not only do we connect users and agents only to what they need, unlike competitive solutions where the users and agents land on the network, but we also sit inside every traffic flow, where most other solutions observe that traffic from the outside. We are a single unified platform where others stitch together different point products. In an AI world where exposed applications can easily be exploited, this difference absolutely matters. As I said earlier, if it's reachable, it's breachable, and we stop attackers from even being able to reach the applications in the first place, which does wonders for preventing the possibility of a breach. So while we continue to drive innovation and growth across our platform, a big focus in our product development over the last 12- 18 months has been building new product beachheads.

This is an opportunity to land new customers and to expand to our existing customers as well. And we see this in three main areas: users, branch, and cloud. So let me walk you through what we're doing in each of these areas, and I'm going to start with Zero Trust for Users. Zscaler Internet Access, Zscaler Private Access, so ZIA and ZPA, they've been the foundation of our platform for the longest time. This is how we secure users accessing the internet, SaaS applications, private applications, whether they're hosted in customers' data centers or they're hosted in the cloud. We've been very successful helping customers understand how to implement Zero Trust for Users to transform their overall security architecture. This is a strong part of our business and it's growing in the double digits.

These transformation projects, when they complete, they take Zscaler, and they put us in place as mission-critical service for our customers. The scale of this is unmatched. Zscaler now protects nearly 7 million business applications for our customers and safely enables more than 55 million users every single day. Zero Trust transformation for users with ZIA and ZPA, that is typically how customers have started their journey with Zscaler, and we have continued to drive industry innovation, specifically in this space. Now, in particular, let us look at ZPA for a minute. It has seen a sharp increase in attention from customers in 2026 from the tailwinds created by AI. Mythos-like frontier AI models and AI-powered attacks are finding vulnerabilities, they are chaining them together to evade legacy perimeter security solutions. With ZPA, we are known for hiding that attack surface area and preventing lateral movement.

We also now protect applications at runtime with our new Autonomous App Shield virtual patching.

This solution uses frontier AI models to continuously scan these applications that we are protecting. It is going to find vulnerabilities, create virtual patches for them, and we will be able to protect these applications before a customer even has a chance to patch them. Just yesterday, we announced our partnership with IBM and Red Hat, to deliver virtual patches for vulnerabilities even more quickly, often before they are publicly disclosed. ZPA represents a meaningful expansion to our install base alone, as approximately 30% of ZIA user licenses today do not also have ZPA. It also drives new logo opportunities as prospective customers are urgently looking for new solutions to protect themselves against AI threats. Earlier, Jay showed a slide, and he talked about the frontier AI model assessments that we did with over 400 organizations.

The number one ask that comes out of those assessments is: What do I do next? This is exactly what we tell them to do. A Global 2000 financial services customer was looking to reduce their exposure to vulnerabilities found by Mythos-like AI models. They expanded their ZPA footprint to cover all 120,000 of their users. This increased that customer's ARR to Zscaler by nearly 50%. Now we are going to move over, and we are going to talk about browser security. The browser is where modern work gets done, but web content can be risky. Also providing third-party contractors access with BYODs, or bring your own device, it has historically been hard and complicated. You think about it, a dangerous website, it can serve malware down and compromise an end user's machine.

Also, limited controls can allow sensitive intellectual property that is in that application you are trying to protect to be extracted out. At Zscaler, we pioneered one of the most effective solutions for this problem. It is called cloud browser isolation. With this approach, a user accessing an application or a potentially risky website, they only see a streaming image of what they are browsing. This means that they are protected against malicious content because no content is coming down, and the organization that is controlling this can easily decide what sensitive data even gets delivered to the user, what can they see, and what can they do with it. While full cloud browser isolation is arguably the most secure approach out there are some cases, like with third-party contractors, where a simplified user experience through a local browser might be preferred.

And so over the past 18 months, we've expanded our browser capabilities to include a browser extension that lets a customer work securely in any browser that they want, as well as building and releasing a dedicated enterprise browser. So with this, Zscaler now has the most comprehensive browser security offering in the market, and we think it can satisfy customers across any use case and beat any of the point product competitors. The result of this for Zscaler is a net new land opportunity where browser security starts as a potential first step in a customer Zero Trust journey. We saw this play out with a Fortune 500 retailer where we won a competitive deal against other browser-only security vendors. The customer who bought Zero Trust Browser for 350,000 of their users, they had no previous Zscaler deployment, no ZIA, no ZPA.

This was the land for it. Then they plan to expand to more parts of our portfolio in the coming quarters. So that's just some of the incredible innovation we're driving in Zero Trust for Users. Now let's talk about branch. Legacy branch solutions like SD-WAN, VPN, MPLS, they're typically quite expensive, they can be complex to manage, and they drastically expand the overall attack surface for a customer. Remember, all of these are networking technologies, so they were built for a purpose, and that was to connect things together, not to provide security. We introduced our Branch Connector several years ago, and that was our initial solution to this problem. Over the past 12 months, we thoughtfully unified our Branch Connector and our microsegmentation capabilities into a line of purpose-built appliances that provide a true, secure, Zero Trust alternative to SD-WAN.

The unified appliance that we built, it seamlessly connects the branch location to our Zero Trust Exchange, and then leverages local microsegmentation to eliminate lateral movement within that branch location or factory. So just by way of definition, microsegmentation, it's that ability to place every single device, even small footprint IoT/OT devices, into isolated segments. So this is where they can't communicate with any other device unless we explicitly, or the customer's policy explicitly allows it. Remember that these devices, for a lot of customers, especially in factories, they're in places where they can't install additional software or software agents onto it. So it's critical that they're able to easily segment out their infrastructure to prevent lateral movement in these environments. The result again with branch security is a new land and expand opportunity for Zscaler.

Highlighting this is a recent deal we won with a Global 2000 manufacturer who's deploying Zero Trust Branch to secure their OT environment. Again, this customer had no previous Zscaler deployment. Their incumbent network provider had a shot at winning the deal to secure this environment, but the customer chose Zscaler to secure all of their critical production sites because of the way we approached this in a Zero Trust fashion. Now, 40% of Zero Trust Branch customers are new logos to Zscaler. So this is a great opportunity for us to accelerate our new logo growth, and again, it also provides an expansion opportunity to the rest of our customers once they are on the platform and are going down the Zero Trust journey with us. So now on to cloud.

In the cloud area, enterprises have been struggling to secure cloud applications running in hyperscalers like AWS, Google, Azure, OCI. The traditional approach is to bring that which you know, so bring legacy firewall appliances and move them into the cloud. It can be costly, complex to manage, and not often able to really stop the lateral movement that we would want them to protect against. When we started in cloud security space, we started with a cloud connector. This made it easy to secure cloud workloads running in public cloud. Customers liked that simplicity, they liked that flexibility, and they really decided they wanted this to be extended more and to be able to replace all the different use cases that they would want where they would typically need to deploy a virtual firewall.

This is why we introduced our Zero Trust Gateway in late 2025. This is a managed solution designed to deliver Zero Trust for cloud workloads. It includes micro-segmentation, and overall, we will run this service on behalf of our customers, so there is no need to deploy and manage virtual firewall infrastructure. If you remember, just before, I talked about this idea of micro-segmentation in the branch, and the goal of that is to stop lateral movement. We apply that same principle natively for cloud workloads. This time it is an agent-based approach, and that is what allows us to do full all directions, north, south, east, west traffic flows in cloud environments in a true Zero Trust fashion. This too creates new land and expand opportunities for Zscaler. We saw this at a global manufacturer. They deployed Zero Trust Cloud in a seven-figure deal to implement micro-segmentation.

The goal was to eliminate virtual firewalls, and they did this following a major cybersecurity incident which brought their physical production environments down for over six weeks. This customer was able to get our Zero Trust Cloud solution up and running in less than 10 minutes during their proof of value process, and that demonstrated the simplicity of our powerful cloud solution. So Zero Trust, as we have described, this is a journey, right? As I have described today, customers are starting that journey wherever it makes the most sense for them. Could be users, could be branch, could be cloud, and increasingly it is going to be AI agents, which Dhawal is going to talk about in just a moment. Any of these are starting points for customers to adopt Zero Trust SASE Everywhere.

With our relentless innovation, our proven success in the market, we are really proud that Zscaler has been recognized as a leader in the 2026 Gartner MQ, Magic Quadrant, for SASE platforms. If you dig a little deeper into that, Gartner says 50% of new SASE deployments are going to be based on single-vendor SASE platforms by 2028, and that is up from 30% last year in 2025. With what I described to you, with Zscaler's Zero Trust SASE Everywhere, we think we are super well-positioned in this space to win with a comprehensive single-vendor platform in the SASE space. We continue to expand our Zero Trust SASE Everywhere cloud presence too, to support more and more customers across more and more locations. What is increasingly important in many parts of the world now is cloud sovereignty, right?

Our leadership in sovereign cloud, this is a structural advantage for Zscaler. The nature of our architecture, it provides us with the ability to maintain separate traffic processing, management, and log storage, and we can do this in isolated regions around the world. As digital nationalism rises globally, Zscaler is the only cloud-native platform that delivers global performance while we are meeting strict local data residency and unique regional requirements. For example, our partnerships with providers like Schwarz Digits, who combine our Zscaler Zero Trust Exchange with their European sovereign cloud, STACKIT, they continue to support customers with sovereign cloud requirements, or together we do, in ways that our competitors cannot easily serve. You are going to see us make further sovereign cloud announcements in additional regions over the coming year.

In my last few minutes, I want to talk to you a little bit about agentic security operations or Agentic SecOps. Along with availability, reliability, performance, our customers benefit from our unrivaled telemetry across identity, network, endpoint, cloud, and they get this when they leverage our inline Zero Trust Exchange. It is important to note, without accurate and relevant data, the value of applying AI models, especially in the cyber world, it is greatly diminished. But with this unique foothold we have on the endpoint, as well as with this global cloud presence, we can see and stop threats that others are going to miss. We believe one of the most important ways to leverage these powerful vantage points and this telemetry is to apply it towards detecting and responding to cyber attacks. This is why we launched our agentic security operations solution a few weeks ago.

Let me introduce you to our Agentic SecOps offering. Legacy SOCs, security operations centers, they were typically built to chase endpoint alerts and to search SIEM logs and do this after the fact, and most typically with humans in that process to try to figure out what happened after a threat was detected. That model itself, it struggled in the past, and now it is completely broken with AI-driven threats that are operating at machine speed. With Zscaler's Agentic SecOps, we started with an agent-first approach. We have over 50 agents that are trained on our global telemetry, and they are tuned by 10+ years of human security experience that comes from our Zscaler ThreatLabz team, as well as our Red Canary managed detection and response team. In our Agentic SecOps platform, we also brought together exposure management and threat management into one place.

What does this mean? This means that a customer can proactively work to reduce their vulnerabilities, their exposures, and their risks, and then they can use that information to quickly contextualize and automatically respond when a security incident is happening. That information is super valuable to go through an investigation. Time and time again, our telemetry has proven to be very valuable to our customers, in helping them investigate security incidents, and now we are operationalizing that value for customers with our Agentic SecOps solution. SecOps, too, does provide yet another land-and-expand opportunity for Zscaler. We had a Global 2000 manufacturing company engage us to help quantify and manage exposure and risk across 700,000 assets. That was before Mythos. When Mythos came through, this customer realized that sampling their estate, it just was not going to be enough.

They adopted our Agentic SecOps solution and expanded their coverage to more than 20 million assets to make sure that they could cover their entire organizational footprint. We are in the early innings of reimagining security operations, but we are really excited about our unique opportunity in this space. To summarize, the Zscaler Zero Trust Exchange, it is the platform for the AI era. We think it is the best way to secure AI agents and to protect against AI-powered attacks. We have continued to drive innovation across our platform to expand our TAM. Not only does Zero Trust for Users remain a powerful growth engine for us, but we have also unlocked new and upsell opportunities across users, branches, and cloud.

In addition, we are excited to disrupt the SecOps market and transform how organizations detect and respond to threats, which we believe will open up a large adjacent growth opportunity for Zscaler. With that, I would like to thank you for your time today. Now I would like to welcome Dhawal Sharma to the stage, and he is going to dive deeper into what we are doing in AI and data security. Thank you.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Welcome, and thank you everyone for joining us here. In this section, we are going to talk about two broad areas of our platform, Security for AI and data security, which unlocks a significant TAM for us, as Jay showed, which is about $48 billion. We have a sizable book of business already where we are securing data for our customers over the last many years. Earlier this year, we also introduced our AI security portfolio. As we have been selling this in the market, what we are seeing is there is a strong synergy between the two. Persona of Chief Data Officers is overlapping and emerging with the Chief AI Strategy Officers, and CISOs are getting deeply engaged in securing AI everywhere. Also, when you think about the traffic patterns, 80% of unauthorized AI traffic caused a data security violation.

As AI creates more data, organizations are leaning to build safeguards against it with Zero Trust. These are strong statements that have come from Gartner recently, and we do strongly validate that in our customer conversations as well. As we think about AI security, we are seeing AI actually creating strong tailwinds for data security as well. We are seeing that AI adoption is growing in organizations. We have a strong book of business of more than $400 million in data security today, growing with a CAGR of 31%, as well as in the last three years, we have seen strong growth of 126% in this area. What is even more exciting, however, is that AI security creates a new entry point of Zscaler for customer acquisition.

What I am very excited about is the fact that 70% of Security for AI deals in our fiscal Q4 actually had data security with it. As we think about these two problem statements, they are actually converging and are becoming very symbiotic in nature. To understand how these two areas are coming together, let us look at the underlying problem statement. In today's world, every app that we have built over the years, every SaaS application, is becoming agentic and is creating more data. Fundamentally, it is becoming harder to understand who has access to data, what they are doing with it, and what is the risk of their access to the data. Moreover, AI models are not just consuming your enterprise PII data and transforming that data, they are also creating more data.

This creates more data attack surface for the organizations, and also AI agents can work autonomously with no human in the loop, exfiltrating enterprise data to risky destination. In my observation, this is a new frontier that enterprises have not tackled before. Zscaler has been working in the area of AI security for many years. Let us talk about our Security for AI solution for a second. We have been building this for more than four years. When you think about the moment when ChatGPT came out, right? Since then, there has been explosion of generative AI and agentic AI application. There are thousands of them that have popped up since then. We introduced our GenAI security product that provides visibility into shadow AI and also secures thousands of GenAI applications.

Then we introduced AI Guard, one of the industry's first intent-based policy framework to secure what happens inside the prompts of these applications. in last one year, we are seeing that AI adoption, especially within the hyperscalers and neo clouds, has accelerated significantly, which means people are building more AI infrastructure in the cloud. We introduced our AI asset management solution then. To bring visibility into AI everywhere, and then secure the posture and configuration of these AI applications as well. Then we also introduced ability to do offensive red teaming through our acquisition of SPLX on AI applications that organizations are building to determine the risk of AI apps. 2026 is the year when agents are going mainstream, whether embedded inside SaaS applications, whether they are built independently for the organizations.

To understand the relationship of AI agents, data that they have been using, and the identities that they are using, whether they are human identities or non-human identities. We introduced the AI Access Graph through our acquisition of Symmetry Systems. We also introduced Endpoint AI Security that is built using our acquisition of SquareX. Finally, we introduced our AI Gateway that sits between every AI interaction within an enterprise and secures them with. We will talk more about it soon. When we think about Security for AI and data security, there are three big pillars in this area as we bring these together. The thing that really stands out for our customer is that when we talk about AI, it also includes how data is coming with it.

The three pillars are discovering data everywhere and making sure the AI that is using that data is also discovered, securing every AI interaction and securing it with, against cyber incidents like prompt injections and the data that is getting transferred in those interactions, and protecting those AI apps and infrastructure that you are building. Let us go deeper into the discovery to understand the shadow AI usage. The problem is more layered than just shadow AI. It is not just AI visibility, but understanding how AI is connecting to data and identities. Let me explain it further. First question to answer in discovery is what AI and data exists in my enterprise and where is it being used? We discover all kind of AI assets, agents, MCPs, agentic applications, deployed everywhere, including public cloud, customer's data centers, and SaaS applications.

One important example of that discovery is our Zscaler Endpoint AI asset inventory, where we discover agentic apps, local AI models, AI development environments that your developers are using, local AI models and AI that your employees are using within the browser through extensions, and what skills they are using. This sets the foundation and brings full visibility of not just AI, but the lineage of data and identity within AI. Which is really differentiated compared to siloed visibility that customers are getting through their EDRs, identity tools, and cloud security solutions. Once we have discovered the AI and data in organization, it is important to understand who has access to that data and what are they doing with it. This is where our acquisition of Symmetry comes into the picture.

It allows us to connect with various AI data and identity tools that organizations are using and build a full relationship or the lineage. That is a very hard problem to solve for a lot of large, complex organization. One of the key differentiator here is that we can connect to hundreds of trusted tools in the organization with the connectors that we have built, and also the data that we discover inline through our Zero Trust Exchange and what we discover on the endpoint, we bring it together. With this, we can provide the granular insights in the usage of these applications and how they connect to the enterprise data and understand the overall risk. Now, risk is broadly defined in two broad categories here, risk tied to data and the risk that is tied to your AI.

For data, we provide full visibility into risky behavior associated with the enterprise data, including sprawl of data, which is you could have a lot of duplicate data in your environments that could be very expensive. Sensitive data exposed to third parties or with the elevated privileges. Most importantly, we classify data everywhere, whether it is on the endpoint, whether it is inline, sitting in your SaaS services or public cloud, and figure out the risk associated in these very complex environments. This is what we do with Zscaler DSPM or Data Security Posture Management. Now let us look at the risk that is tied to AI, and that includes how risky is AI deployments in the public cloud. Understand the risk tied to AI models and risk tied to the configuration and posture of these models.

Finally, help organization build a full AI bill of material to understand the supply chain. Your AI applications are not living on their own. They connect to software packages, they connect to data stores. Building that full bill of material is something that we give organizations with the full risk, and that is what Zscaler AI-SPM or AI Security Posture Management does. Most importantly, we remediate the risk with AI agents and integrate with enterprise workflows. Enterprises are really struggling in this area as we interact more and more with them. They end up buying multiple tools and need to manually connect the dots. Connecting the dots is where our acquisition of Symmetry has done a really good job. We not just connect the dots in these complex environments, but we also offer agentic remediation.

Now let's move to the second area of our Security for AI and data, which is securing all the AI interaction. As you saw during Adam and Jay's presentation, our Zero Trust Exchange secures every enterprise interaction, including for the AI traffic that might be associated to agents that you are currently deploying or building. Think about a lot of our customers are deploying Claude Code. Many of you use Claude Cowork or Codex, as well as autonomous agents and AI assistant that are running on your computer or agents that run in the public cloud. For agentic traffic coming from employee laptops, enforcement happens on the endpoint from Zscaler with Zscaler Endpoint AI Security. For the AI agents that are deployed everywhere else, we secure it with our Zscaler AI Gateway.

Before we proceed further, everyone in the industry is talking about intent and context. Your LinkedIn feeds, you must have seen what is a context-based engine, what is an intent-based engine. Let's talk a bit about that. When we secure users today, context is typically who is the user, what is their identity, where do they come from? A corporate network. What devices do they use? What applications they are trying to go to. What is the user's risk profile or risk posture? Is it a risky user because they clicked on a lot of bad links? Once we determine all these actions, our Zero Trust Exchange grants the access to the user, and this context layer is gold. Zscaler has one of the richest context layer that we have built for user over the years.

When you think about the agents, the same context layer is now extended to AI agents. Agents also have their own unique context, such as agent risk. Everyone is worried about your agents might burn too many tokens, so cost management token usage is important. Agents also need to be governed based on the intent. Intent is essentially the task with which the agent was set up. For example, a customer support agent for a bank should not be giving stock advice. That task behavior is very important to understand with the intent. It is also important to understand how these agents are executing these tasks. They should not use very risky skills. There are now marketplace from where you can get these skills and use them to complete your task. The skill files, for example, can tell agents to steer traffic to an attacker server.

This is where Zscaler differentiation come into picture because we are only gateway in the industry today that supports context and intent-based policy to secure the agents. AI agents could be deployed everywhere, most commonly on user devices, but also in public cloud such as AWS Bedrock or Azure Agent 365 or neo cloud platforms which have edge compute. Our customers can send traffic from agents deployed anywhere to our AI Gateway in Zero Trust Exchange. This is where we integrate with agent identity platforms because identity is foundational for zero trust and start building the context layer. We just do not secure agents based on what they are, but also understand, cost-based routing or more advanced policies that come with it. Our AI Access Graph gives us a unique and differentiated bottom-up context layer.

What it means that we know what data agents are using, what identities they have, and that context layer is unmatched in the industry today. When we think about this architecture, what we are doing here, we are bringing the identity, we are bringing the context and intent as part of the policy evaluation. If I have to summarize the three key points on why this approach really stands out for our customers, we not just secure agents going to internet, but also understand more advanced protocols like MCP deployments. MCPs are de facto in many enterprises to standardize agentic communication, and we have a MCP gateway built here as well.

We are also the only gateway to support both deep context and intent, as I explained, and most importantly, built with our DNA of building large scale gateways, ZIA, ZPA, in last decade to deploy these gateways to handle billions of entities that going to come at a very large scale compared to many agentic gateways that we see that are deployed only within a specific project or do not scale at that level. Let us talk about the one immediate security problem that I am running into while talking to security teams every single day. How to securely deploy agentic apps such as Claude, Codex, or one of many AI assistants securely within the enterprise. Traditionally, attacks have focused on user devices such as laptops, purely on the operating system, file systems, and software that employees are using.

This is where we partner with every EDR vendor because they are really good at securing that attack vector. AI is introducing new attacks targeting users that are primarily focused on the apps that your employees are using, AI assistant they are using, and the AI they use within their browser. For example, employees are downloading seemingly benign files that look clean when they are downloaded initially. These files can reassemble later and become malicious using what is called a last mile reassembly attacks that EDRs can not easily find. What EDRs also do not secure is data exfiltration on the endpoint, whether that is transmitted locally using a USB stick or using a local MCP server that a developer has installed on their computer. This is where our Endpoint AI Security product comes into the picture.

As AI apps usually get full access to data on the user device and can transform that data via prompts and transfer it to unauthorized destination. We provide three fundamental set of capabilities here. AI usage control to provide controls on usage of sanctioned AI and detecting unsanctioned or shadow AI on corporate devices, and do granular controls with these apps. For example, we do not allow data transfer between a corporate version of ChatGPT and a personal ChatGPT in the same browser. Cyber protection to understand malicious skill usage, use of risky AI models on the endpoint. You know that you can actually run a small local model embedded inside your browser or on the device now. These could be used to create sophisticated phishing attacks through prompt injection in multiple turns, and these are the kind of things that EDRs can't find. Finally, data protection.

Zscaler has a endpoint DLP product that discovers, classifies, monitors data everywhere and allows you to build consistent DLP policies around your data, including what goes inside the prompts and access or data that is going out through browser plugins. This is a very refreshing approach for enterprises that we work with, the security teams we work with, because they do not need to deploy multiple agents and get fully integrated AI and data security solution, which is very complementary to their EDRs. Data also needs to be secured in line or when data is in motion. That is where we had a significant advantage as we secure data with Zscaler DLP across all channels where data can exfiltrate. Data, as Jay explained, in ransomware attacks, either is going to internet to attacker servers or to unsanctioned applications.

Data can exfiltrate over email or prompts within these applications, or embedded chatbots that you're using. For example, if you use a food ordering app, it has a GPT-powered chatbot in it. Underlying intent of ransomware attacks is always to steal data, and if you have deployed Zscaler DLP to protect those channels, we prevent this from happening. So what I do want to highlight here is the fact that because of our Zero Trust Exchange architecture, we have a unique advantage. We have a proven proxy-based architecture to intercept and secure any data leaking to the internet. We provide a uniform policy layer for data security across all channels, and all of this is delivered through a single Zscaler client that is running on more than 55 million devices today, and customers don't need to deploy a new agent.

Which is really a very important point for organizations as they want to simplify what goes on their corporate endpoints. Let's look at an example of a large, global financial asset management firm that leaned in with our data security and how that created an upsell for our AI security solution. The challenge this organization was facing is lack of visibility into data in their public cloud environments and limited classification of data sitting there. Using different data security products to secure data in public cloud and different for on-prem and something different from endpoint, they lack the full picture of where is data and what is happening to that data. With Zscaler DSPM solution, they upleveled their data classification and got a much broader coverage of data asset stores that they have deployed.

As they connected more data stores, they understood the AI sprawl and how AI is connecting to their data. That led to the evaluation of Zscaler for AI security offerings, and within one quarter, we upsold them Zscaler AI Security. The benefit from customer perspective, one of the main benefit was discovering petabytes of redundant data, which they removed and had lot of cost savings around it. They also understood the data access across their organization with upgraded data classification, and most importantly, single solution to secure data everywhere with pre-supported connector for every data store that they use within their organization. This also led to $5 million worth of ARR expansion for Zscaler in this account, and our DSPM outperformed the standalone DSPM they were using, which they replaced with this.

Now, let's move to the third pillar, which is helping organizations protect first-party AI apps, MCPs, models, and data stores they are using within their organization. To protect AI systems, we focus on securing full lifecycle of AI within the organization. So starting from when you are building these application to when you start deploying these in production using our Zscaler AI Red Teaming product, as I explained, that came through acquisition of SPLX. Then once you deploy them in production, we secure these apps with our Zscaler AI Guard solution. Today, we are the only vendor in the market that is a fully integrated AI red teaming and a guardrail solution that takes input from the red teaming and enforces automated guardrail policies to secure runtime behavior of these applications. Now, let's take a look at red teaming for a moment.

In this solution, we provide a catalog of dozens of supported agent platforms or model providers. Hundreds of model providers are supported and thousands of MCP servers on internet are already pre-built and supported with it. Next, we have a library of pre-configured test profiles around safety, security, hallucinations of these models. Once you configure those tests, we can simulate 5,000 attacks, like how attackers would attack your applications, and test it with multimodality of throwing text, images, files to see how your applications break. This help enterprises find vulnerabilities and risk in their apps before they go live in production. But with our model benchmarking and baselining for frontier labs, open weight models, we help organization compare and pick the best models. One important thing to remember is that the entropy or the change in AI applications is usually very high.

Every time a new model version comes or a new software library is released, the overall risk posture of these applications changes. This is why we support automated on-demand red teaming. Finally, we are the only AI red teaming solution that provides an integrated and a standalone prompt hardening service, making sure your apps that you're building, like chatbots, when they interact with your model, they have a very consistent hardened prompts they're creating. If prompts are not harder, we offer the remediation as well. Next, when these apps move into production, such as everyone is building an employee-facing chatbot today, which almost every enterprise has built with a small or a large language model they have deployed or a front-end model they have deployed within their organization.

This is where we basically analyze the risk requests going into these chatbots and the response that come from the applications, through their models and a true intent-based inference or a runtime AI security policy engine that secures every prompt and reviews every prompt as it is getting to these applications. This strategy of securing prompts across heterogeneous environments such as multi-cloud systems. A lot of our customers basically are running their or consuming their model from one hyperscaler, their application is running on different hyperscaler. One good moat that we have built here is that our customers, like how Adam talked about Zero Trust Cloud to provide same security for across all hyperscalers. We provide consistent guardrails across any model provider, any hyperscaler.

Since we anticipated the need for such intent-based policy a few years ago, we had a head start in this area when we introduced AI Guard two years ago and have started creating a catalog of predefined detectors across different industry verticals and different use cases that are trained with use case-specific datasets and small language models that we run on GPU-based infrastructure in our cloud, so customer can easily deploy it with few clicks. We have also extended the guardrails or this AI Guard to prompts that are going through our Zscaler Internet Access for 3,000+ application. Finally, here we are able to enforce policies based on the token usage by these application. They can tell you which user are using how many tokens, and we can do cost controls on that as well.

As we bring this together, to summarize, what we have covered so far across three pillars and how it comes together is a single integrated solution for our customer is that it starts with the discovery layer of every AI asset, including on the endpoint, models, applications, MCP tools, and understanding its deep relationship with data and identities to create an AI Access Graph that allows us to build very comprehensive DSPM and AI Security Posture Management solutions. This also builds a highly differentiated context layer that enforces policies to secure every interaction with our AI Gateway and of our agents deployed everywhere while we extend AI security to user devices with discovery, with our AI Endpoint Security. By the way, with AI Endpoint Security, we have also embedded Mythos 5.1 model in early access to find more sophisticated attack paths on the endpoint as well.

Then protecting AI apps through build, deploy, and runtime life cycle with AI Red Teaming and AI Guard. Let's look at another example, or a case study of a large global system integrator with more than 400,000 employees who leaned in with our entire AI security portfolio that I just talked about. This organization had a very open access to GenAI applications for a couple of years, then got audited for very high risk due to data exfiltration risks. As a result, access to all AI applications was revoked within this organization. Business started losing competitive edge, as you would know in today's world. Customer who was already a Zscaler Zero Trust for Users customer, started enabling sanctioned AI applications for employees with GenAI visibility and AI Guard for users to secure traffic.

They also started mandating AI red teaming for first-party apps they are building and also started deploying agentic coworker application for their employees using our Zscaler Endpoint AI Security. This customer saw the value of consolidated AI platform, which already integrates with investments in data security DLP and did a full Z-Flex deal for entire AI security portfolio. That gives them access to the entire portfolio that I talked about and everything else we are building in this area. From a benefits perspective, broader access to a catalog of AI apps and being able to do on-demand red teaming of first-party apps while keeping the compliance with some European EU AI Act or NIST AI Risk Management was a big differentiator, and this customer did a $5 million+ Security for AI deal with us in fiscal Q4, raising the overall ARR for this account to $80 million.

Now, as we wrap up the session, I want to summarize what really excites me about this massive opportunity and why we are bringing AI and data security together. Not just, by the way, for us, but also for our customer in terms of the outcomes that they're driving with us. So our leadership in data security creates a strong demand for AI security, as AI security outcomes are closely tied to data security and data problems. Pace of AI innovation is moving at lightning speed. Customers are looking to buy consolidated platforms versus individual point products to secure AI usage. And we believe the zero trust architecture is fundamentally built to handle the scale of AI agents, and this is where we have an undue advantage.

And finally, both Security for AI and data security solutions allow customers to deploy these products with no dependence on rest of the Zero Trust SASE portfolio. It can be onboarded and sold on its own. And with that, I would like to wrap this presentation. Thank you for paying attention. And next, we will move to the customer panel. You have heard this morning us talking about our architectural advantages, power of Zero Trust Exchange, and how our solutions are helping our customers navigate a rapidly evolving threat landscape. But ultimately, the most important perspective is coming from our customers. And this is why I'm glad to be joined by three of our esteemed customers here. AkzoNobel, they are a leader in global paints and coatings with a presence in 150 countries.

And I ideally know this customer because they became a customer the year I joined Zscaler in 2012. So they're a long-term Zscaler customer. Marsh McLennan, they are the world's largest insurance broker and a Zscaler customer since 2019. And Merck, a leading global pharmaceutical company, our customer since 2022. We were intentional about bringing together customers from different industries to illustrate both the breadth of all the challenges that enterprises are facing and increasingly universal need for modern security architecture across different verticals. Our panelists will share more about the challenges they are facing, how they prioritize their security challenges, how their priorities are changing in the AI era, and what they're looking from AI security solutions. So let me introduce our panelists. Please welcome Kurt De Ruwe, who is the CIO of AkzoNobel. Kurt, please join us here.

Jon Eastern, who is Global Head of Networks and Security at Marsh McLennan. Jon. Finally, joining us virtually is Bob Stasio, who is the Deputy CISO at Merck. Thank you, everyone, for being here. I will kick it off with a quick question, then we will open up the floor for the audience in the last 10 minutes as well. The challenges that your company faced when you first deployed Zscaler, and what your Zscaler journey has looked since then.

Kurt De Ruwe
CIO, AkzoNobel

Yes. I think first of all, it was the protecting of the internet. It was at the time that we still had MPLS networks. I think if you look at the journey, all the products that were at the bottom that Adam showed, I think we have deployed them. So visibility with ZDX. We have the ZPA. We have Risk360. I think if you look at it more recently, like two years ago, we wanted to go to open internet everywhere, so that's 995 locations. So we do that on the one hand with ZPA, on the other hand, with the Branch Connector. So it's really, I think Zscaler is fully underpinning or giving us the technology to do what we would like to do.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Interesting. Coming to you, Jon, you've been a customer for a while as well. Our relationship has been evolving. I remember especially interesting time during COVID on ZPA deployment. Can you share some of your initial thoughts on how you deployed Zscaler initially and how that has been evolving?

Jon Eastern
Global Head of Networks and Security, Marsh McLennan

Sure. Yes. So when we started with Zscaler, we were, I think like many other companies, we had a centralized internet. Everything went through data centers in a couple different regions. Legacy proxies. We wanted to digitize our workforce, and Zscaler was really what we thought was the best way for us to secure that internet traffic, in particular, enable that business to use those more modern tools. ZPA, we began testing initially. We had a specific business use case for it, then COVID accelerated that plan pretty quickly. But really to their credit, we deployed over a matter of days to our workforce of, I think, probably 75,000- 80,000 at the time. We're 100,000 now. Everybody using that as our primary tool for remote access and even in the branch office in our Zero Trust model, which I'll talk about a little more later.

But yeah, our relationship has continued to grow as your product portfolio has grown very successfully.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

So key point is that you started with focus on protecting users, and the use cases have been evolving since then.

Bob, I'm going to come to you. You have been a full platform adopter. What advantages you believe you got from leveraging the full breadth of our platform, and how that has been evolving for you in the last four to five years?

Bob Stasio
Deputy CISO, Merck

Yeah, sure. Thanks for having me. Yeah, I mean, the way—

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

You are looking the whole spectrum of Zscaler offerings. You are also a Z-Flex customer, right? Can you talk a bit about as you looked at the entire landscape of what Zscaler are doing, and we talk regularly on what is on the truck coming soon, how did you move from product-based licensing to Z-Flex, and what was the thought process behind it?

Jon Eastern
Global Head of Networks and Security, Marsh McLennan

Pull in another capability to test out without having to go back and do specific product-based licensing. We have been able to check out things like the Branch Connector, and even some of the more, I guess, newer offerings, advanced offerings like the Zscaler Cellular in some of our manufacturing areas. That has been very helpful for us as we have deployed these capabilities across the enterprise.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

That is amazing to hear that we have customers who have started adopting, deploying cellular technology that we have the ZSIM on actually production environment. We are seeing a significant uptick in that now. Coming to Kurt. You have been an at-scale customer for our Zero Trust Branch offering. You started pretty early when we had the Branch Connector. You also have some very complex OT environments, and securing OT comes with a lot of legacy infrastructure as well. Can you talk a bit about when you thought about bringing Zero Trust to the branches, and I am pretty sure you had SD-WAN, what made you think about adopting Zero Trust Branch, and how do you see that as fundamentally different from SD-WAN?

Kurt De Ruwe
CIO, AkzoNobel

Basically, we had the [inaudible] internet everywhere with the aim of taking out all firewalls everywhere and also getting rid of SD-WAN. Yeah.

Now, if you look at the offices, if you look at warehouses, that's fairly simple, if I can say. If you take that into the factories, it's more difficult because you have the PLCs, you have SCADA, you have devices on which you cannot implement agents.

That's where we looked at the Branch Connector, and it's actually 4th of October was our first deployment last year.

Not two days ago. We're currently at 69 factory sites that have been deployed out of 110. The thing is that we have a mix of everything. Any equipment you could buy in the last 30 years, we have. We have fairly old, we have fairly new. But basically, the intention is to implement the Branch Connector and the micro-segmentation.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah.

Kurt De Ruwe
CIO, AkzoNobel

If you look at it, I think in addition to that also what's said is that, with the aim of going to open internet, it was also aiming at a significant cost reduction. Also the Zscaler SIM, so rather than replacing all the network equipment, for instance, in a warehouse, we put the SIMs into the scanner, so we don't have to do the big investment. Maybe one anecdote. When we did Como, that was the first site. We organized a prize setting for our security team, so said the first person that can break in, and they were allowed to use any tool, would get a nice prize. I think two days later, they came back as, well, we can't find it. So I think that was also one of the statements. If you can't see it, you can't hack it.

But for me, that was really an important proof point—

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah.

Kurt De Ruwe
CIO, AkzoNobel

—that this is the right way to go.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

That's amazing. We actually, a lot of customers do that. As part of testing, they bring the rogue access points in their shop floors, plug it in and say: What can I find? The technology, the way we have built it, you won't find anything else with that. Now, Jon, you have unique advantage of running network and security both, right, in the firm. So one thing that everyone wants to know is how do you realize the advantage of using a Zero Trust architecture? Sometimes security and network look other way. So how did you bring that convergence of Zero Trust for architecture to protect your users everywhere?

Jon Eastern
Global Head of Networks and Security, Marsh McLennan

Well, I think over the past five years, network and security have really converged, and that's why we've made the organizational decision to combine them. But in today's business world, we need to really support our business to be able to execute at almost machine speed. AI's only accelerated that. So our ability to, or using Zero Trust, we reduce the elements of friction for our users, giving them better access, faster access, while simultaneously improving the security model. So it's a nice convergence that you don't often see. We find our users are preferring the new model. Leveraging Zero Trust, they are able to do more, and we have more visibility and able to secure it more. And those Zscaler tools have really enabled that.

ZPA has become the foundation of our Zero Trust model, providing that access broker for all applications, making sure that all of our users can access the applications they need to and don't have access to the applications that they don't.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah. I think experience is very important with security, and I think what ZDX does in this space is giving you visibility of user experience with a Zero Trust architecture also unlocks a lot of bottlenecks that we traditionally have seen with network, right?

Jon Eastern
Global Head of Networks and Security, Marsh McLennan

Absolutely.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah. Let's switch gear towards AI. I talked a lot about AI and how awesome our AI security is, but I want to start with these speakers. Bob, coming to you. You guys have a big directive to use AI for innovations. Can you talk us, first of all, key use cases where Merck as a company is leaning in with AI, and what security challenges it create for you as a security leader as AI gets adopted widely?

Bob Stasio
Deputy CISO, Merck

Oh.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Oh.

Bob Stasio
Deputy CISO, Merck

I am muted. I didn't want you to hear my Teams alerts as they were going off. Sorry. Yeah, we made a public announcement earlier this year about a $1 billion investment into Google Gemini as kind of our main orchestration platform across our enterprise. We have several, we call lighthouses, or kind of lines of effort, across the enterprise to help our organization. At a high level, what we're trying to do is typically a drug takes about 10 years of development, and of all the drugs you look at, of all the molecules you start to investigate, maybe 1% of them will go to market. We're trying to get that down to five years and 10%, right? So it's a really interesting multiplication there of effort, and AI's going to really help us drive that forward.

So, there's various efforts to help the research element of Merck, even the manufacturing, even some of our global support functions to include IT and finance, be more efficient with what we have and roll out more drugs in our pipeline over the next 5- 10 years. So AI is a big part of that. And obviously the business is focused on it, so we have to be focused on coming behind and making sure it's secure. So what I'd like to talk about is the AI governance, safety and security governance life cycle. So we're focused on how we're intaking various AI applications, agents and models. We're categorizing them by risk. We're applying appropriate controls. We're monitoring those controls. And then we have compliance and auditing against them.

So we're using some of the Zscaler AI products to help in that journey, and we've started rolling them out actually last quarter.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah. That's great. Jon, I'm pretty sure you are looking at AI very closely in the firm as well. Some of the challenges that you are seeing, not just from security, but from also how you connect your networks traditionally to these AI ecosystems.

Jon Eastern
Global Head of Networks and Security, Marsh McLennan

Yeah. From a business perspective, we have three pillars of strategy for AI. The first is individual productivity using internal chatbots, similar to a ChatGPT. Working at business process optimization. How can we take our existing processes, and use AI to improve efficiency and optimize there? And then more business process transformation. How do we transform our business to operate more effectively and win in the AI-enabled world? So with all those challenges, you need to secure the environment using AI, and you need to protect the environment from AI. And that's become really the critical challenge that we're working on, working closely with partners like Zscaler to do that with the portfolio.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

And you have been giving great feedback on our guardrails and detectors as the use cases requirements in each organization keep evolving. So really appreciate the feedback that we got from you.

Your world is very different, Kurt, when it comes to agents and security, and we were at dinner last night. Actually, we were surprised to see how vast is your footprint of AI from, not just employees, but also in your plants and manufacturing and other places as you're thinking about AI usage. How are you thinking about security evolution in order to protect AI in these complex environments?

Kurt De Ruwe
CIO, AkzoNobel

I think currently we have eight AI towers, where a lot of the things we offer internally.

Like all users have access to more than 12 models, including some of the Chinese models, which may sound strange. But we allow within a framework to use it. And on the 26th, basically, we will offer a toolkit to all our users to create their own agents.

So it's really the challenge to make sure that the guardrails we have, that they're good enough, and then basically to see what everybody is doing, and to be able to intervene where things might get out of control.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Mm-hmm. Okay. We know that you have recently started looking at AI Security portfolio, and we are going to take a deeper look at it as well.

Kurt De Ruwe
CIO, AkzoNobel

Now we are piloting—

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah.

Kurt De Ruwe
CIO, AkzoNobel

—your solution. So, yeah.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

All right. In interest of time, last question for you, Bob. We recently launched our SecOps offering, and you have been a Red Canary customer prior to acquisition, and you have been a strong voice in how we should be evolving the acquisition of Red Canary into the Agentic SecOps that we have built. Can you share some insights what you are looking in terms of how this should come together?

Bob Stasio
Deputy CISO, Merck

Yeah. I am actually a three-time Red Canary customer. So, my original view of the managed defense or MDR solution in Red Canary is to really push all of your, what I call high fidelity alerts into the platform, and it can really triage it at scale. So those types of alerts would be coming from your EDR or maybe things like Wiz or GuardDuty. Low fidelity alerts would be things coming from Palo Alto or even in some cases, like the actual Zscaler alerts, like ZIA alerts coming through. Because it is just such high volume, most of them are either false positives or just indications of blocking. So I initially tried to focus the Red Canary solution on the high-fidelity alerts, which we had about 20 agents in the platform that are running over all the data and really automating everything we did.

It really helped us out lower our meantime to remediate significantly, and lower the number of incidents we are seeing per day or investigating per day, and allowed us to move up the maturity curve. That was stage one or phase one, which worked really well. Now what I am really excited about for phase two is that lower fidelity data, how can we use agents to go across that data and do more of hunting? So the first one, the first case was more of like triage and maybe automating the initial stages of an investigation. In the second phase, it is more like true hunting, looking for anomalies, pulling threads. I think AI is very good for that, kind of recognizing patterns. We are kind of experimenting with that now as a design partner with Zscaler to roll that out.

I think that is going to make a huge difference and really complete a full AI-driven SOC.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Okay. Thanks for sharing the insights as well. Now, we will open the podium for the questions from the audience. If you could please raise your hand, we have mic runners in the room who will come to you. Please state your name, your firm's name, and ask your question to the panelist. Let's start over here in the front.

Mike Cikos
Analyst, Needham

Hey. Mike Cikos with Needham. Thank you for doing this, guys. We're all hearing the presentations. You guys are here listening to this on AI security, and I'm just trying to get a sense. If you're thinking about your cyber budget today, let's say it's $100, right? And you're spending, make up a number, $10 on Zscaler two years ago. What is that percentage of spend today? How does that change in the next two or three years, just given incremental AI security budget that you guys will be spending on these solutions?

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

I think this question was not addressed to anyone, so I'll take the liberty for maybe starting with you, Kurt.

Kurt De Ruwe
CIO, AkzoNobel

I think to give percentages is difficult. The only thing I can say is that almost every new thing that comes out, we look at and we adopt.

Mike Cikos
Analyst, Needham

Do you see more of that value accruing to Zscaler [inaudible] ?

Kurt De Ruwe
CIO, AkzoNobel

No.

Mike Cikos
Analyst, Needham

[inaudible]

Kurt De Ruwe
CIO, AkzoNobel

I think it is mainly additional because the good thing about Zscaler is they think about the problems you will have that you do not know yet that you will have them. By the time you encounter the issues, there is already a solution there.

In several cases, we did not even do an RFP, like on ZDX. Basically, we tested it, we liked it, we agreed on a price, and we deployed it.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Bob—

Kurt De Ruwe
CIO, AkzoNobel

The whole, I think what is very important with Zscaler is the concept on if you have the clients, I think it is also what you said, deployments happen within days of new capabilities.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Bob, anything you want to add to this?

Bob Stasio
Deputy CISO, Merck

Well, I guess we are in a slightly different boat because we have sort of like an ELA with Zscaler. So, we have nearly all the portfolio or access to it. Obviously, there are some separate items that we buy à la carte. But I will say, I do not want to give percentages, but I will say it is one of our top security vendors that we have on spend. Spending in security is obviously a little difficult to calculate because we spend a lot on Microsoft and security, but that is part of our larger Microsoft budget. But for our own budget within our security group, it is one of our top items.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Let us go to the next question. In the front here.

Saket Kalia
Analyst, Barclays

Absolutely. Thanks so much. Saket Kalia at Barclays. Thanks so much for hosting this panel. Super helpful. Maybe this is a question for everybody, Dhawal, if possible. As your usage of agents across the business, across your respective businesses grows, how do you think about your usage of current Zscaler products like a ZIA or ZPA, and which other Zscaler products maybe become more relevant as that adoption grows? Does that make sense?

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Jon?

Jon Eastern
Global Head of Networks and Security, Marsh McLennan

Yeah. What I would say is in the AI world, obviously things change, but we don't see that a strong well-architected, layered security model is still the best defense against the security environment. Nothing changes for us from that core set of tools we purchase from Zscaler or anyone. There are absolutely AI specific use cases that we need to address and Zscaler is building a really interesting portfolio that we're evaluating. But really our focus is on, AI speeds everything up, especially in the attack space. But that core is still really important, and something I would say we're still very focused on and even doubling down on.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Any other comments?

Kurt De Ruwe
CIO, AkzoNobel

Maybe one example is we want to go to fully ticketless, which basically we need to have all the inputs and the signals. What you see is that Zscaler is also AI enabling, if I can call them the older products, like ZDX. So we have an intelligent hub, and then ZDX feeds in basically what is going on. That also basically allows us to do more in a fully automated way.

And I think as security becomes ever more important, it just is the whole suite that adds the value.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

That is a very good point because what I have talked about was Security for AI, but we are also doing AI for security in every core product, and that also is leading to a lot of expansion. A good example is Deception product where we actually have LLM decoys for LLM. So that becomes a natural expansion use case as well. Let us move on to this side. Right in the front here.

Keith Bachman
Analyst, Bank of Montreal

Hi, it is Keith Bachman from Bank of Montreal. Thanks so much for doing this. I wanted to ask a two-parter. Where do you think you are today in your AI journey in terms of AI adoption versus where you might be 12- 18 months from now? The corollary part of the question is how do you think about, not necessarily the companies per se, but just the incremental security that you need to adopt to enable further AI penetration? For instance, a lot of vendors talk about governance solution, cloud security, agent identities. How do you think about just where you need to adopt technologies, buckets of spend, if you will, and security, and how does that compare and contrast to your aspirations for AI adoption over the next 12- 18 months? Thank you.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Bob, you want to take it?

Bob Stasio
Deputy CISO, Merck

Yeah, I can jump in. Your question is, you are asking, where are we with AI adoption, like at the enterprise or within the security organization?

Keith Bachman
Analyst, Bank of Montreal

Within the enterprise, broadly.

Bob Stasio
Deputy CISO, Merck

Okay. Yeah. Here we have a pretty accelerating model on AI adoption. The core folks in our TAT, we call them lighthouses, too, within our lighthouses, like in the research labs at MMD are fully adopted in those use cases. But across the enterprise with business process assistance, the copilots, things like that we are moving towards the higher percentages there. It is accelerating every month. We are keeping an eye on that. But those agents are pretty controlled in orchestration platforms. For example, the Gemini that we use is this orchestration layer that automatically has controls and harnesses across all the agents developed in there. We feel that they are pretty safe rolling out there. We are trying to drive users to adopt there instead of bringing in a new type of agent or model. That is good.

Your question about where do you see the spending going, especially around security governance. I think every organization is struggling with this. Every vendor I talk to has a different approach on security governance. I do not think it is figured out yet. The first thing we want to do, or we are doing, is this kind of like a blocking and tackling mindset. Just because the AI is rolling out very quickly, it is in use, we need to be monitoring it, controlling it, and blocking and tackling issues that pop up. We have established a couple different vendors to help us with that and a bit of these tiger teams to stand up and do that. But that is kind of a temporary solution. It is a process that we had to develop because it was needed.

We are having a study going on right now in our organization to identify how we are going to do the governance process over time, build a larger orchestration platform that is going to work across legal, governance, ethics, compliance, IT, and engineering, which is pretty complicated. That is kind of where I think the funding will go in the next couple of years, is towards a more robust solution that can take these atomic-level feeds from all these areas to monitor what is going on, categorize it, and satisfy the stakeholders that I just mentioned, which is pretty challenging. We have not really seen anybody come across and do that yet. Zscaler is certainly a part of the solution, right? But it is not the whole solution because there is a lot more that has to be involved in it.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah. I think the key point that Bob is making, it is an evolving landscape, and one of the things that we are able to do is provide flexibility for customers to see what is relevant and needed for them, and they can switch to what is needed.

Kurt De Ruwe
CIO, AkzoNobel

Can I maybe just. Spending money on security for AI is not a choice. You have to do it. Spending money on agents, there you have the choice, depending on the consumption.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

All right. Let us go in the middle somewhere. Over here.

Brian Essex
Analyst, JPMorgan

Thank you. Brian Essex from JP Morgan. Thank you all for doing this. I had a question for Kurt. Within your manufacturing facilities or shop floor, I would love to know how you are addressing the risk to your operational technology within those facilities. I think you mentioned you might have some stuff running on SCADA. How are you addressing the architecture and risk posture within your manufacturing facilities, and how does Zscaler help you do that?

Kurt De Ruwe
CIO, AkzoNobel

Yeah. Previously, the way we run our factories is like islands connected from the main network. But once a hacker is in, they can go everywhere. I think first of all, with the Branch Connector, we try to make the site invisible, and then in case there is still a breach with the micro-segmentation, we limit it to just a number of systems. With regards to the PLCs, Zscaler has solutions for that, for the horizontal flow, and I think it has been a challenge, to be honest, because a lot of the technologies that we have are different. It was not you have done one, you can now do the 100 other ones. Every site, we need to learn. Basically, the impact that Zscaler brings is totally reducing the attack surface. When something happens, we have the visibility.

Brian Essex
Analyst, JPMorgan

Are you adopting AI within those facilities, and how are you addressing the potential risk if you are in fact doing that? Thank you.

Kurt De Ruwe
CIO, AkzoNobel

I think AI is the next step. It is initially in putting in place the protection, and then you have the triggers, and then those triggers basically are being followed up. I think more and more AI will be used there to then, yeah, just take those triggers that are really relevant.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

I think this is a great point to wrap the session. We have a great point where we actually have had wide variety of topics that we discovered. I want to thank all of our panelists for joining us here today, and for the insightful discussion with me and all of you. Before we break, I want to take a minute to reflect on a few key themes that have emerged in this conversation, and what we have been discussing since the morning, and based on discussions that I have been having with customers. First, these conversations continue to reinforce our position as a strategic partner to our customers. What often begins as a single use case, for example, to protect users, then evolves, because of the architectural advantages, into expansion of Zero Trust Exchange beyond users to workloads and branches, and expanding our platform deployed with the customers.

Second, our customers are increasingly relying on Zscaler to solve complex problem. The Z-Flex programs give them that flexibility. They can co-innovate with us. They can be design partners and solve security challenges and go hand-in-hand with us on some of these emerging priorities. Third, AI is a big opportunity, and it is also a challenge from an architecture perspective, and we are looking to help our customers navigate both. The need to securely enable AI, while also making sure that you are protected from threats is critical requirement. Against this backdrop, the opportunity is significant, and we believe Zscaler is uniquely positioned to capture it, helping our customers succeed in this very complex world. With that, thank you again, Kurt, Jon, Bob, for joining us here, and I will now welcome back Kim to the stage. Thank you.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay. Thank you very much. Now we are heading into a short break, which you are probably very relieved about. We will take about a 10-minute break, but before we do, I just want to put the demo slide up once again. Right outside the door, we have four demos. A lot of the solutions that we have talked about today, from our Zero Trust SASE offering to Agentic SecOps, which Adam talked about both of those, the Zero Trust Exchange for Agents. There is a familiar face there. That is also what Dhawal talked about, and data security solutions, which Dhawal talked about as well. The person who is hosting that is actually the CEO of Symmetry . The former CEO of Symmetry, now a Zscaler employee. Enjoy those, and we will see you in 10 minutes. Thank you.

[Break]

We are ready to get started again, so come on in, take your seat. Before I introduce our next speaker, I wanted to mention that we'll be sending out a post-event survey after today's program. We would really love your feedback. Please, please, fill it out. Our goal is to make sure these types of days are most valuable for you. I also wanted to give you a brief reminder. Today's presentations contain forward-looking statements within the meaning of the safe harbor provisions of the Federal securities laws, including statements regarding our future financial performance, business strategy, and market opportunities. With that, it's my pleasure to introduce Ross Tackett, Zscaler's Chief Revenue Officer. Ross.

Yeah, thank you.

Ross Tackett
CRO, Zscaler

All right. Thank you, Kim. Welcome back from break. I am going to go over our go-to-market strategy for the next four hours, so I hope you buckle in. I kid. I am going to go over our go-to-market strategy for about the next 20 minutes. Before I do, I wanted to provide some background on myself and introduce myself to you all. I have been at Zscaler for about three years now. The first 2.5 of that, I was successfully running our largest geography, the Americas. In the last roughly six months, I stepped into the worldwide sales leader role, where I was responsible for delivering on our global sales number. As part of that role, I have been heavily engaged in the annual planning process for both our operational and financial plans.

We have a strong strategy, a strong plan in place, and the entire team is focused on executing. I am very confident this will be a seamless transition. There are some key messages that we want to make sure we get across in this session. The big one, as Adam and Dhawal and Jay have mentioned, is Zscaler was and is built for this AI moment. We have the right platform, the right team. It is the right time right now to be successful. We have built this durable go-to-market engine, and we will talk about how we are leveraging that go-to-market engine to capitalize on these AI tailwinds. I will begin with a few key reasons we are well-positioned to capitalize on this moment. First, scale and global presence.

Our customers are global, their security challenges are global, and we have local geographic coverage all over the world to provide the best customer experience possible. We serve customers in more than 185 countries globally, with 25 countries generating over $10 million in ARR and seven countries exceeding $100 million in ARR. This worldwide reach is a differentiator for us, and our international scale and strength is evident with greater than 45% of our ARR coming from international markets. Next, we serve an incredibly diverse customer base spanning across all industries and verticals. Overall, we serve over 50% of the Fortune 500 and over 40% of Global 2000 customers and accounts. This broad presence demonstrates the universal relevance of our solution to enterprises globally.

You can see a few examples on this slide of verticals like hospitality, technology, and retail, where we work with a majority of the top companies in those sectors. This broad coverage has a strong network effect. CISOs and CIOs often buy based on advice from other CISOs and CIOs. This places Zscaler in a unique position for continued growth. Now, I want to talk about how we go to market by segment, how we're organized internally. Our major segment at the top of the pyramid generally includes accounts with 40,000+ employees or a very large propensity to buy from Zscaler. These are covered by sales executives that have just a very few accounts so that they can focus on a high-touch, sales-led approach, often in conjunction with our GSI partners, and these partners are in every one of the largest global accounts.

Our middle enterprise segment covers 5,000- 40,000 employee accounts, and these are jointly led by Zscaler and a partner, either a GSI or a national VAR. We see this part of our business as an area where we can accelerate new logos, and so we've invested in creating more hunter territories to drive this growth. Finally, our commercial and SMB space. These are businesses and organizations under 5,000 employees. This is increasingly shifting towards a partner-led motion with simplified bundles. This segment is a high-velocity, new logo-generating machine that is bringing on new customers who will one day be our next enterprise accounts. Regardless of segment, building trust, building trusted relationships, and having executive alignment is an important part of our go-to-market approach. This allows us to be a consultative partner as part of a customer-centric strategy.

Put simply, we focus on understanding the problems they are trying to solve to help them transform their security architecture and address every security challenge. Now, I want to double-click on our vertical strategy, because this is a very important part of our growth plan. We have established dedicated teams for the last few years focused on certain verticals, such as U.S. public sector and U.S. healthcare provider. This year, we launched a U.S. financial services vertical as well. All these are critical verticals that require additional coverage and expertise. For example, in our federal business, our FedRAMP High and IL5 accreditations and ability to deliver solutions for highly regulated environments are a competitive advantage for us. We see opportunities to expand our vertical strategy in the future.

As AI and the increasingly regulatory environment create tailwinds in the space, we see a path to future growth and opportunities in areas like international public sector and sovereign cloud. Sovereign cloud is a big focus for us, and we are seeing a lot of demand, both in public sectors as well as regulated industries around the world. Now that I have covered how we structure our go-to-market organization, I am going to focus the rest of my presentation on the four key levers driving our growth. First, platform expansion. The AI security tailwinds are undeniable and tremendous, and we are seeing significant momentum from our new product offerings. Second, we are accelerating our new logo engine, and the team is focused on landing new customers with these expanded offerings.

Third, and crucially, we are scaling through partner leverage, working closer than ever with our ecosystem to reach more customers wherever they are. Finally, everything we do is underpinned by customer obsession. Ensuring relentless focus on our customer success translates into tangible results, with platform expansion and new products being purchased. I am now going to touch on a little more detail on each of those areas. First, starting with platform expansion.

As you have heard, Zscaler is truly a cybersecurity platform. Here you can see a snapshot of this platform. You have seen it before many times today already. Our four product categories are built around a common architecture, as you have heard from others. What we have not shared is there are more than 30+ distinct products underpinning each of these categories, and that number continues to grow as Adam and Dhawal and their product innovation teams build more products.

This is a key differentiator for us versus other companies that claim to be platforms but are really just a collection of point products that have been acquired. We see substantial demand as our customers continue to invest with us and consolidate point solutions in exchange for a platform they can trust, and one where they can realize significant long-term savings. Today, the majority of our ARR comes from customers who have at least one product across three or more product categories, demonstrating the breadth of our platform and the value proposition of what we offer. These customers not only have significantly higher ARR, they also have a higher retention rate. Critically, there is still significant upside potential for Zscaler inside of our existing customer base. Today, on average, customers have purchased only nine out of the more than 30+ products we offer.

There is a lot of opportunity to grow. When you look at the white space across our install base, the opportunity is significant. As you can see, we conservatively estimate our current TAM, not including our future TAM, but our current TAM of $19 billion. When you consider our FY 2026 ending ARR of $3.8 billion, we have a significant $15 billion worth of white space available to capture. That represents a 5x expansion potential just by cross-selling our existing products to customers who already know us and trust us. Notably, this expansion potential is spread across majors, enterprise, and commercial segments, with roughly 3/4 of the expansion opportunity among majors and enterprise. Regardless of the customer, the story is the same. Once a customer experiences the power of the Zscaler platform, they want to consume more of it.

And as our customers navigate a rapidly evolving threat landscape, we are perfectly positioned to grow alongside them. Let me give you an example of that growth. This is through the lens of a global investment firm. This is a customer that we landed with a $2 million ARR that was Zero Trust SASE for users, and that was in FY 2019. In FY 2022, they expanded into data security, and then they added SecOps in FY 2024. Then recently, last year, they added Zero Trust SASE for cloud and Security for AI, growing this ARR to more than $15 million, or 7x the initial land. This growth is fueled by deep executive alignment on strategic transformation, which drives the customer's continuous investment as our platform expands. But the most important part of this chart is the trajectory to the far right.

And even at $15 million, we still have a substantial upsell opportunity ahead of us as this customer continues to consolidate on our platform. Next, our new logo engine. We have a significant untapped opportunity remaining in our target market of organizations with more than 1,500 employees. Our current customer base represents just 4,600 of these estimated 20,000 + enterprises globally. There is over 75% of the market that we have not yet reached. And as we head into FY 2027, we have made some changes to ensure the field is best positioned to capture this significant opportunity. For example, as we approach territory design for FY 2027, we put a strong emphasis on new logos. We significantly increased the number of hunter territories globally, and we have also focused and incentivized our field for new logos and driving that growth.

And finally, we work very closely with our partners to provide further leverage in opening doors for new customers that have been shut for us, and I'll touch on that a little bit in a moment. You've heard it from Adam, you've heard it from Dhawal, you heard it from Jay. Our platform has expanded. We now have a multitude of solutions to land with new customers, with entry points across each product category. Here are just a few examples of use cases where we can help prospective customers address with our growing platform. I won't go through all of them, but I do want to call out Security for AI, as it is a huge area of interest in every conversation that we are having. You heard that from our customer panel today. I'll also call out Zero Trust Branch.

We're winning very large new logo seven-figure deals with ZTB, and they do not have users. Great landing spot. And let me give you an example of just one customer. We recently had a seven-figure win with a Fortune 500 life sciences leader. This deal is a perfect illustration of the power of the Zscaler platform and our Security for AI innovations. It was led by a newly appointed CISO who is a repeat Zscaler customer. You heard that from Jay. This is a very common theme. And we won this customer thanks to our superior Security for AI capabilities. Our platform gave this customer the specific controls they needed to safely adopt AI without compromising sensitive data, allowing us to displace a legacy firewall-based SASE platform. Next, I'm going to talk about partners. All right. Okay. I want to talk about partners. Sorry, technical issue.

I got a pointer problem. Our partner ecosystem is the engine that allows us to scale across the entire market. At the top of the pyramid, in our majors and enterprise segments, we are seeing incredible progress with GSIs, with greater than 75% year-on-year TCV growth in FY 2026. These partners are leading multi-year, board-level digital transformation initiatives where Security for AI has become a central theme. Strategic VARs also remain an important partner for us. We work with these partners across all of our segments, especially in our enterprise business. These organizations have local expertise, long-standing relationships, and we recently launched a new incentive program to further penetrate this market. Moving down market into commercial and SMB, our strategy shifts towards scale and velocity. Here, we are intentionally leveraging distribution and managed service partners for scale and speed.

One example that we announced is our recently expanded partnership with Carahsoft, targeting commercial and SMB accounts. This shift towards a partner-led motion is designed to drive high volume, new logo acquisition. You will continue to see this strategy deployed in other geographies of the world in the future. Finally, our tech alliances with hyperscalers and frontier labs. They act as a force multiplier across all segments. They ensure that Zscaler remains at the forefront of AI innovation regardless of company size. In FY 2026, we captured a record $1.5 billion in TCV through marketplaces and saw over 125% year-on-year growth in TCV through our tech alliances. Our final growth lever, this is so important for us. This is a huge focus for our sales teams and for the company as a whole, and that is customer obsession.

So many of you may recognize this infinity loop from our 2024 transition towards an account-centric selling model. It represents a continuous cycle where pre-sales alignment and post-sale success are inseparable. On the buy side, we focus on deepening CXO engagement and differentiating the Zscaler brand to ensure we are not just a line item, but a strategic partner. Our teams are highly engaged, and this is a consistent point of feedback we hear from customers when they choose to partner with us. On the own side, we introduced Z-Flex six quarters ago, and the results have been incredible. Ultimately, Z-Flex allows our customers to do larger and longer-term deals with us to test newer offerings and to swap products at their own pace. This has led to more strategic engagements with customers and prospects, so it really is a win-win all around.

We've seen tremendous momentum with Z-Flex bookings increasing over 60% quarter- over- quarter in Q4. Kevin will go into these results in more detail when he speaks. In addition, by leveraging partners for expert deployment, we ensure that first-year adoption is seamless and scales as our customer base expands. The big takeaway here is this: we have evolved the way we go to market to ensure customer success is at the center of everything we do. Let me give you an example of how focusing on customer success pays off. I want to highlight a public sector customer where early adoption led to rapid scaling, thanks to our focus on customer success. We began the journey with this customer in FY 2023 with a small land with our foundational Zero Trust SASE for users and data security solutions.

Growing the ARR to $1 million in FY 2024 as we expanded in both of those categories. Importantly, because we established Zscaler as the architectural standard early on, we were able to rapidly repeat this success across more than 100 agencies in this country. Most importantly, we layered on Agentic SecOps, providing these agencies with a single pane of glass for risk-based prioritization within their specific business context. This drove our footprint to 16 million, 170x increase from where we landed initially, and we have even more upsell opportunities in our sights. On the next slide, our go-to-market growth levers. They are all underpinned by a relentless focus on go-to-market productivity. One of the most encouraging indicators of our go-to-market health is the consistent double-digit growth in sales productivity we have been able to deliver over the last two years.

I have been deeply involved in the team that is shaping and driving this transformation, and as you can see, the productivity is trending. We are not just growing our headcount, we are making our AEs more effective. This is driven by four specific strategic levers. One, I mentioned customer-centric selling. The scale of our platform. I talked about partners being force multipliers, and the intentional work we have done with territory design and optimization. As we enter FY 2027, continuing this upward trajectory is a top priority of mine. By ensuring our territories are healthy and our partners are activated, we are building highly efficient sales machines that can sustain significant growth while maintaining sales productivity. I am going to very briefly touch on how we are using AI internally in our go-to-market strategy. We think about how we use AI initially as it should be fundamentally reimagined.

We are not just talking about productivity. We are embedding AI across the entire life cycle to drive velocity and quality. In pipeline, we are moving from manual prospecting to agentic outreach, targeting the right whitespace recommendations at the right moment when the customer is ready to engage, and the results are notable. We have seen a 2x higher reply rate to these emails, demonstrating our ability to reach the customers at the right time. In sales productivity, we launched an AI copilot that has become a force multiplier, handling everything from account intelligence and building complex business value cases, and we are now extending it to agentic quoting. This allows our reps to spend less time on administration and more time on high-value strategic selling.

In customer satisfaction, our AI customer support agent has driven a 40% reduction in ticket volume, freeing up our human resources to focus on the most complex customer challenges. Taken together, these are the primary reasons our go-to-market effectiveness continues to outpace the market. Finally, key takeaways that I hope you heard. I could not be more excited about stepping into this CRO role at this moment, at this time, with this trajectory. Zscaler was built to capitalize on this once-in-a-lifetime AI era. Our zero trust architecture, it is highly differentiated. Our platform continues to expand in ways that are clearly resonating in the market. We have taken action to enhance our ability to penetrate the new logo opportunity we have, and we are leveraging our partner market as a force multiplier.

And we are doubling down on all the reasons customers are obsessed with Zscaler in the first place. Our team, we are laser-focused on executing, and we are laser-focused on achieving our financial objectives. Kevin is going to walk you through these financial objectives. Thank you.

Kevin Rubin
CFO, Zscaler

All right. Hello, everybody. Thank you for being here, and thank you for sticking with us. It has been a lot. I would like to start by briefly recapping what you have heard today. We have talked about the structural steps we have taken to increase our TAM, strengthen our product portfolio as we enter the AI era, and enhance our go-to-market engine.

These are each important pieces of the growth opportunity ahead of us, and I am going to walk you through how all of this fits together from a financial point of view. I am going to focus on three areas. First, our multiple growth engines that we believe position us to deliver continued compounding ARR growth. Second, the success we are having in driving broader adoption of our platform, which is supporting new logo growth and upsell opportunities. I will provide some data that helps make that clear.

Finally, our updated long-term financial framework. Let us start with a quick look back at our track record. We are entering our next phase with a proven track record of growth at scale. In fiscal 2026, revenue grew by 25% year-over-year, while ARR also grew by 25%. Excluding Red Canary, revenue and ARR both grew 20%, and we delivered 14% net new ARR growth for the year. That momentum gives us a strong foundation to capitalize on the significant growth opportunities ahead. As we have scaled the top line, we have also continued to improve the profitability of the business. In fiscal 2026, non-GAAP operating margin reached a record approximately 23%. Free cash flow margin was also 23%, and we reached a Rule of 49 performance. Since fiscal 2023, we have expanded operating margin by approximately eight points.

So alongside strong growth, we are driving operating leverage and building a business with a meaningful profitability profile. Okay. As you heard from Jay earlier this morning, we are operating in a large $220 billion addressable market, which you can see here mapped to our platform. We use this Investor Day as an opportunity to refresh our market forecast, and we are now leveraging industry forecasts from third-party market research firms as the inputs to our TAM. In addition, you heard from Adam and Dhawal today, we continue to innovate and introduce new products, which has significantly expanded the markets we play in today. We strongly believe our platform is perfectly positioned to capture a growing share of this market. Others have presented a similar view of our platform this morning, but I want to drill down on how we organize the platform from a financial point of view.

Fundamentally, our platform consists of four product categories with different levels of maturity and growth profiles. Zero Trust SASE Everywhere is the foundation. It accounts for approximately $3 billion of total ARR and has grown at a 20% CAGR over the past three years. Since this is the first time we're breaking out the platform in this way, I also wanted to double-click on two distinct offerings within this category. Zero Trust SASE for users, which includes ZIA, ZPA, ZDX, and Zero Trust Browser, is our largest business. Zero Trust Branch and Cloud are much newer offerings on a relative basis and growing considerably faster at 75% ARR CAGR over the past three years. Combined, these have now reached $250 million of ARR, an encouraging milestone, and one that reinforces our confidence in the long-term growth potential of the solution.

The second product category is data security, which has grown at a more than 30% CAGR over the last three years. Under this new view of the platform, we have shifted Zero Trust Browser into Zero Trust SASE for users to better reflect how we go to market with this offering, and as a result, have updated our data security ARR accordingly. The two newer product categories in our portfolio are Security for AI and Agentic SecOps. Within Security for AI, we ended the year with approximately $70 million in ARR, an incredibly strong momentum as evidenced by the growth we've been seeing. We are very pleased with our results to date, adding to our optimism about the future. Finally, looking at Agentic SecOps, we just launched our new integrated offering, so the historical performance here is less important than where we're headed.

Across this portfolio, we see three growth engines that will continue to propel our growth going forward. Zero Trust SASE for Branch and Cloud, Data Security, and Security for AI. Combined, these three growth engines delivered 60% ARR growth year-over-year in fiscal 2026. You can expect that we will continue to update you on the performance of these growth engines as a group quarterly, and on an individual basis annually going forward. I want to spend a few minutes double-clicking on each part of our platform, starting first with our Zero Trust SASE Everywhere portfolio. We continue to see healthy growth from our Zero Trust SASE for user solution, despite running into the law of large numbers.

While today these solutions form the foundation of our portfolio, our business continues to shift more towards non-user products, and our goal is ultimately for our growth to not be tied to seats. We are making great strides in this regard. As we shared at earnings, 30% of our new and upsell ACV in fiscal 2026 was from non-seat-based or metered products. Branch and Cloud are key contributors to this, and both have been strong contributors to our growth, with Zero Trust Branch and Cloud ARR growth exceeding 60% for each and every quarter over the last two years. Even more encouragingly, we still see significant white space opportunities for these solutions, with just 10% penetration in the Global 2000.

Looking holistically at our Zero Trust SASE solution, our customers who are Zero Trust SASE Everywhere enterprises, or those who have purchased ZIA, ZPA, Branch, and Cloud, are also our most valuable customers. These customers delivered over 5x the ARR of customers who did not have Branch or Cloud, and they have 121% NRR, or six points higher than our overall NRR. Next, our data security portfolio has become an increasingly important contributor as enterprises confront a new wave of data exfiltration risks. Data security ARR accelerated to 34% in fiscal 2026, with bookings increasing more than 40% year-over-year. As you heard from Dhawal, our data security solution is the most comprehensive in the market, with products that span both data in motion and data at rest.

We have seen over 40% ARR growth from customers who deploy multiple data security products, and today, less than 20% of Zscaler customers have multiple products, representing a meaningful upsell opportunity as we look ahead. Finally, our new Security for AI offering is becoming an increasingly meaningful contributor to our performance. In the fourth quarter of fiscal 2026, Security for AI bookings increased more than 50% sequentially on top of a strong Q3, and our pipeline increased more than 75% sequentially. This is exciting progress, and we are still in early days, with over 65% of our Security for AI ACV in Q4 coming from products that have only been in market less than two quarters. This gives us significant confidence that these products will become increasingly meaningful contributors as adoption grows.

As more products within the portfolio enter general availability later in fiscal 2027, including our Zero Trust Exchange for agents, we expect even further momentum. As we've expanded our product portfolio, we've naturally created more ways for customers to land with Zscaler, beyond foundational Zero Trust SASE for user offerings. We are seeing tremendous interest in our newer products, and they are becoming a meaningful part of our new logo ARR. In fact, roughly 1/3 of our new logo ARR today is being driven by these offerings. This is up 3x versus 2023, demonstrating that Zscaler's platform value proposition is increasingly resonating with customers. Once customers are on our platform, we see consistently strong retention and healthy expansion. Net revenue retention has remained consistent around 115%, while gross revenue retention remains in the mid-90s.

This reflects both the mission-critical nature of our solutions and expansion opportunities we are unlocking with our customers. The power of this expansion story is evident in our largest customers. As customers expand their investment with Zscaler, we see growth accelerate. In fact, our $10 million ARR plus customers have grown ARR nine points faster than our $1 million-$10 million ARR customers over the last three years. Among those, our top 10 customers are growing even faster still. That is powerful validation of the platform strategy and the results that we are providing to our customers. As you heard from Ross earlier today, one of the tools helping us accelerate platform adoption and drive customer expansion is Z-Flex. By giving customers the flexibility to consume capabilities across the platform, Z-Flex lowers friction in the buying process and encourages broader adoption from day one.

And these results have been compelling, with 30% ARR uplift in fiscal 2026 from customers with Z-Flex. As I mentioned on our Q4 earnings call, Z-Flex bookings exceeded $1.7 billion in fiscal 2026, which equates to nearly $500 million in ARR. This is how we will be sharing Z-Flex progress going forward. We have included both Z-Flex TCV and ARR in this slide so you have the history. Importantly, even with the success of expanding within our customer base, we still see significant opportunity ahead. Today, our approximate $3.8 billion of ARR represents only a fraction of the $19+ billion of addressable spend within our existing customers. That leaves over $15 billion of white space opportunity sitting inside our installed base. This includes our Zero Trust SASE for user solution, where we see approximately $6 billion of expansion opportunity.

As you heard from Adam, this includes the meaningful expansion opportunity in our installed base from ZPA, with 30% of ZIA users today who have not yet adopted ZPA. More broadly, we also see significant expansion opportunities with our newer solutions. The fact that over 40% of our installed base has not yet purchased any of our solutions beyond Zero Trust SASE for user underscores the magnitude of this runway. Bringing all this together, I wanted to walk through a customer journey that reflects what we are increasingly seeing across our customer base. In this example, our relationship with this Fortune 500 technology company began with a relatively modest deployment focused on Zero Trust SASE for users and data security. Over time, this customer expanded into additional use cases, including branch, cloud, and SecOps.

We ultimately saw this customer commit to a Z-Flex deal in fiscal 2025, enabling them to adopt the full platform and accelerate deployment across the organization. Then, in fiscal 2026, following the launch of our Security for AI portfolio, they expanded their deployment with us to include these new solutions, and as a result, further expanded their investment with Zscaler. Over six years, this customer grew their ARR roughly 30x, with ARR increasing at a CAGR of approximately 74% to $20+ million ARR by the end of fiscal 2026. While, of course, every customer journey is different, this demonstrates the growth drivers we see as customers move from an initial deployment to a broader platform adoption. As we look ahead, it is the power of our customer growth flywheel and the meaningful runway for new logo growth that Ross shared that reinforces our confidence in the opportunities ahead.

We are reaffirming our fiscal 2027 guidance, which you can see here on the slide. Beyond fiscal 2027, where do we see the business going? You have heard us speak about our aspiration to reach $10 billion in ARR. As we execute on this trajectory, we see a clear path to grow ARR organically to over $8 billion in ARR by fiscal 2031, more than doubling our current ARR within the next five years. How will we get there? We expect continued strong growth from our three growth engines: Security for AI, Data Security, and Zero Trust Branch and Cloud. At the same time, our Zero Trust architecture is more important than ever, and we expect our foundational Zero Trust SASE for users offering to remain strong, delivering sustained double-digit growth. As you heard today, we see significant opportunity driven by the adoption of agentic AI.

This is still a new and emerging area. We are not asking you to underwrite this upside today, but we believe it has the potential to be a meaningful accelerant across every part of our business. Let me talk you through this scenario. While this is not in guidance, it is intended to show the potential of the business assuming a more rapid adoption of agentic AI. Our Zero Trust architecture uniquely protects against the threats created by agentic AI, which we believe will accelerate demand for our Zero Trust SASE Everywhere solution across users, branches, and workloads. With the increasing prevalence of AI, data security and Security for AI become even more critical as enterprises look to safely deploy agentic AI at scale.

With AI-driven threats operating at machine speed, we believe our Agentic SecOps offering is poised to disrupt the SecOps market, opening a meaningful adjacent growth opportunity. We believe these tailwinds could be significant over the next two years and could contribute nearly $2 billion of upside to our ARR.

This would put us on a path to reaching $10 billion in ARR by fiscal 2031, with each part of our business growing at a faster rate than in our base case. Let us now turn to our financial framework. This assumes over $8 billion in ARR by fiscal 2031. I will start with gross margins. As you can see, our gross margins have consistently been around 80%, and we expect this to continue. We have been driving productivity in our go-to-market organization, and we expect this to continue as well, with sales and marketing as a percentage of revenue trending down.

For R&D, we expect modest leverage from our more mature products while continuing to invest in new innovations. In G&A, we see this ticking down modestly from AI adoption and automation. All of this leads to continued operating margin expansion by fiscal 2031. Regarding free cash flow, we expect margins to be above operating margin. However, there are some timing considerations given the current memory price backdrop. Specifically, we are expecting CapEx as a percentage of revenue to remain elevated until fiscal 2028, then normalize back towards high single digits as manufacturing capacity comes online and memory and component prices decline, which aligns with the forecast from Gartner and IDC. Finally, I want to touch a little bit on stock-based compensation, as this is a key factor in driving GAAP profitability. Over the long term, we are focused on bringing this in line with our peer group average.

This excludes any future M&A, which has historically contributed one to two points. With this in mind, we are always evaluating the best use of capital to maximize shareholder value, and our capital allocation framework is clear. Our first priority is reinvesting in the business to drive continuing innovation, resiliency, and product expansion to drive sustained long-term growth. Second, we deploy capital into M&A, focusing primarily on technology and talent tuck-ins to strengthen the platform. Third, we are committed to maintaining a strong balance sheet to preserve financial and operational flexibility. To wrap up, I would like to leave you with a few points. First, we are operating in a very large and expanding market, and our innovation continues to broaden the opportunity in front of us. Second, we have a demonstrated ability to translate that opportunity into profitable growth at scale.

And third, with multiple growth vectors, significant white space in our target market, and the tailwinds from agentic AI across the platform, we are positioned to drive durable and compounding ARR growth for years to come, with both new and existing customers. Taken together, we have a strong foundation, clear visibility into the path ahead, and confidence in our ability to create long-term shareholder value. Thank you. Okay. All right. Up next, we have our Q&A session, so I would like to bring all of our speakers up to the stage for this section.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay, I see the hands up. So when we call on you, just remember to state your name and your company name for the webcast. Really, really appreciate that. Brad, I think you had your hand up first.

So we will go with you.

Brad Zelnick
Analyst, Deutsche Bank

That is one of my skills. Brad Zelnick with Deutsche Bank. Thank you for an amazing day. Really great and compelling presentation. I want to direct my question at Ross, and maybe for Jay to chime in as well. It seems there has been a lot of change in the sales organization. Great to see you stepping into the role as well. I guess as we think about the underlying drivers of turnover that you have seen, what it is that there might be to know why we should not be concerned by any ongoing disruption as a result of these changes? And then I would also love to hear from you what is new. From going from one leader to the next, usually there are your fingerprints that you are going to want to put on things.

As I look at the presentation you gave today, it sounds like with the 75% of the market that you haven't reached yet, it would seem like there's a real opportunity to go further down market. Related to that, I'm just wondering, the resources put behind that versus maybe not then allocating enough towards this amazing $2 billion AI opportunity that we see and how you balance that. I know a few different questions, but all related. Thank you.

Ross Tackett
CRO, Zscaler

Four-part question, I think. Let me see if I can remember all those. I'll start with the latter parts. New logos, as you heard, are a real emphasis for us. With the expanding platform and things that we've done in our go-to-market machine around focus and incentivizing our teams, I feel like we'll accelerate there.

As we look at the down-market opportunity, that is not a discrete focus for us. It is an opportunity, and that's why we're leveraging relationships like Carahsoft that I mentioned. We need to drive velocity and scale, and that's what we're focused on there. We will remain very focused on enterprise and majors. We do have an opportunity in that space. We're not ignoring it, but that's where we're really going to leverage our partners. You asked what I would do differently. You led the witness a little bit in that new logos are very important for us. We're driving verticals. I think I talked about vertical strategy. We have a lot of opportunity in public sector international, as well as sovereign cloud. We are really leaning in there. Then obviously the platform opportunity. I have a long history of selling platforms.

I know how to do it. I know how to lead those teams, and so very focused on that. Then I think coming around to your first question, and Jay, I'd encourage you to chime in as well. Yes, there have been some changes, and they've all been unrelated to each other, frankly. There's not any individual macro thing. We've got a strong leadership bench. We have our leadership team in place. I'm very happy. As I've mentioned multiple times, we are really focused just on execution.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

If I may add, you saw us reiterating the guidance. That tells us the confidence we have. You also saw us give long-term guidance as well, that could tell you that we are very confident on the opportunity. The overall platform need for cyber, our role as being the linchpin is fundamental. The sales process and strategy we put in place is doing well. We just need to keep on accelerating on it. I think we have a strong leadership team, and there will be some changes from time to time. Very confident.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay. We are going to go to Fatima, and then we will head over to Joe. So Fatima and Joe in the first row. Can we get a mic over to Fatima in the middle? Can you keep your hand up for a sec?

Webcast.

Ross Tackett
CRO, Zscaler

Webcast.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Thank you.

Fatima Boolani
Analyst, Citi

Fatima Boolani from Citi. Thank you so much for such an insightful set of comments and presentations. Dhawal or Adam, for you. Dhawal, you mentioned something that was really interesting to me in your session, just around this intersectionality of Security for AI and data security. Now, those two seem to me very interrelated because you cannot have secure AI usage without having a handle on your data assets. The data attack surface or the data risk surface, as you pointed out, is absolutely metastasizing. Why is there still a distinction from a product standpoint if presumably data security is going to be a conduit for Security for AI and vice versa? As a related question to Ross, why not unleash Z-Flex to the entire base? What are some of the limiting reagents?

Because if you are going full force from a platform perspective, you talked about only nine of the 30 individualized SKUs are being uptaken. Why not just tear up the traditional motion? You have seen the success with Z-Flex and go all hands on deck. Thank you.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

I will start with the first part. When we look at the AI security broadly, or Security for AI, data security is a very strong tailwind as I was explaining the numbers. Security for AI is broader than that. A lot of new cyber attacks that we are seeing, think about how users are being tricked to get phished these days is happening through prompts. Prompt injection, jailbreaking is happening through that as well. There is definitely more to it, but, as you saw, securing AI also needs to secure AI applications and infrastructure that you are using from what goes into your models. Data security then becomes a key pillar on that. You are absolutely right that AI agents are not just consuming data, or models are not just consuming data, they transform your data. They also leave remnants of this data in multiple places.

This is why we have been classifying data and we have a strong DLP business that has grown significantly. The challenges that come with data security in the AI world are also different, and this was one of our core thesis for acquiring Symmetry Systems, that we can discover data everywhere. We can discover AI everywhere. What is really hard in this world is understanding the relationship between data and how that data goes into AI, and how identities are playing pale with very excessive permissions and role. That problem is getting compounded with stat that Jay showed. There are 75 agents for every single user. The short answer, in my opinion, is yes, data security is a big part of it, but AI security in itself is much broader. That is why we are keeping it that way, but we are bringing it together. Adam?

Adam Geller
Chief Product Officer, Zscaler

Yeah, maybe just one quick add on that. This is why data security is part of a platform, and it's a consistent capability that crosses everything. I didn't spend much time talking about it, but it's foundational in everything we're doing in Zero Trust SASE as well. What we've been recognizing is where does that need to evolve and primarily AI has just served as a major accelerator of, if we knew this was important before our customer knew, now it's really, really important. Then you're seeing these specific pieces around data security is always about find the data, classify it, and then enforce policy.

What we've learned in AI, there are new elements of what that policy looks like, and it's broadly applicable, not just for AI, but AI is driving that, and that's why we're doing it at a platform level, so we can use it across every one of our product areas.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Ross?

Ross Tackett
CRO, Zscaler

Z-Flex. Kevin, chime in if you have any thoughts. That is a growth enabler for us. We don't have any limiters on. There's some obvious baseline, you need to spend X minimum, but yes, Z-Flex is kind of a core motion for us.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

We did give an example where a customer, actually, in the case study, is able to take the entire security portfolio through Z-Flex as well.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

With so many questions coming up, we are going to keep our answers short.

We can take more questions.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Thank you, Jay.

Yeah. It is taking my role. Now we are with Joe.

Joe Gallo
Analyst, Jefferies

Okay, so I have a question for— Joe Gallo, Jefferies. Thanks for this. A question for Adam, primarily on SecOps. I know it's early, but who are you competing with? I assume in your existing customers, you are the network security platform. So I assume you're competing with the endpoint-centric platforms. I'm just curious your right to win there, because those vendors also have a lot of data.

Adam Geller
Chief Product Officer, Zscaler

They certainly do, and I think the data gravity is the main point. Every customer that we work with, when they're figuring out SecOps, they're going to orient around some center of gravity. And in some cases, in many cases, that's going to be us. It can also be other players that they have. The solutions, anyone who has a SecOps solution, if they don't have that data gravity, they're a new Agentic SecOps startup, I don't think they have that easier right to win compared to a Zscaler or a larger platform play. SecOps has become more and more of a platform play. It's why I think we have that right and that shot to be competing in that space. With the telemetry of the data we have and that agent-first approach that we're taking. I think Kim likes to bring it up.

I have this comment where I say, we get sometimes a second-mover advantage." We weren't first to this space. We recognize that. But the benefit is, we didn't spend all of our time building a solution around log collection and storage. We built it all around an agent-first approach.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Adam, we are first mover when it comes to solution built for agents. Others built solutions for humans.

Adam Geller
Chief Product Officer, Zscaler

Right.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

And tried to add agent to it. That's point one. The second short answer would be data. We got full inline data. We got endpoint data. We got cloud workload data. We also got branch devices data. We have better telemetry than anybody out there.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

And we bring in third parties.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Yes.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

We'll go Itai, and we'll do you, too, Adam. Can we get a mic right here in the front? Thank you.

Ittai Kidron
Analyst, Oppenheimer

Thank you very much. Ittai Kidron from Oppenheimer. Great presentation. Really appreciate the disclosure. A couple of questions from me for you, Adam. First, on the technology side, you talked about the importance of context. I guess why not own the identity side of the equation? It sounds like you are drawing from identity in order to create context. Some of your biggest competitor has decided to own that layer. We already see some data security companies moving into the identity side to create that context more closely linked. I guess the question is, why not own that category instead of partner over there, and potentially end up with no partners if they get acquired? So that's question one. For you, Kevin, on the financial side of the equation, appreciate the long-term targets on fiscal 2031.

I guess if I think about just that $8 billion target, just kind of doing back of the envelope, it sounds like net new ARR needs to be growing around the 10% plus minus on a consistent basis for you to reach that target. That's already well ahead of your target right now for fiscal 27. So are you already raising the numbers, or should we look for a little bit— Are you going to grow into this fiscal 20 31 number, or how do we think about that?

Kevin Rubin
CFO, Zscaler

Yeah, I guess I'll go first. The 17% CAGR is in line with the midpoint of the guidance for this year. So that would be my direction there. As we think about the opportunity to $8 billion and potentially $10 billion, let's remember, we have a huge opportunity in a giant market. We've talked about new logos. We've talked about continued extension of the platform. We've talked about moving even beyond into adjacent SecOps. So I think there's a lot of opportunity and a lot of reason to be really excited about the opportunity. That's how I would think about the longer-term model.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

If I may add, I am only focused on $10 billion number.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Adam, do you want to finish off the first question?

Adam Geller
Chief Product Officer, Zscaler

Let me try to. From the identity piece, look, leveraging identity as context is part and parcel to everything we have done in Zero Trust. It requires that. Does not require you necessarily owning it. Customers use identity for lots of different things, and they have identity players and components that bridge well beyond security. If you want to get into that space, you have to sign up to do all of those pieces. We have been very successful leveraging it as key context. The other piece is identity players are not typically in line. They are in line for one piece of it. They are not an in-line processing engine, which is what we are. That is where we are focused. We are focused on leveraging that context. It is a relationship for sure. It is getting a lot of attention.

But I don't see the burning need to say we have to own it. Because I think that brings a lot of other distraction, and you saw what we have to go after. We have a lot in front of us, and I think focus is going to be very important as well.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

If I may add, in the agentic world, identity, basic identity about who are you, is coming from the party that's creating agents. That's the starting point. Identity doesn't give any more context than who you are. Who are you? The rest of the context come from sitting in line. We have lots of context today for user identity that, as Dhawal talked about, without having the core identity. Would I go and spend $25 billion and hoping that this business will become agentic identity? Not really. Will I work with Microsoft and Azure and AWS and Google on the world and take identity from them, add context to it, add intent to it? That's the winning formula.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Adam.

Adam Borg
Analyst, Stifel

Awesome. Adam Borg with Stifel. Thanks so much for the time and really appreciate the conversation today. Maybe for us, talking about the new logo opportunity, especially down market, talk about the confidence you have there, especially given investor perception, it's a lot more competitive down market. So, what changes would need to be made, if any, on the pricing and packaging side to be more competitive there? Thanks.

Ross Tackett
CRO, Zscaler

Sure. So at a high level, and to keep this brief, a couple of things. A, we are looking at more simple bundles, like T-shirt sizes, that we are then leveraging our partner ecosystem. I talked about Carahsoft, and we are looking at doing similar relationships in other geographies. And so having those simplified bundles through a partner machine that can leverage and touch all those organizations that we just don't have the human capacity to do is why I feel confident that we can grow the new logos in our commercial and SMB space.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

For me, an interesting challenge we have is the upsell opportunity is so big, the new logo opportunity is so big, we are trying to do balancing act rather than saying A versus B.

Kevin Rubin
CFO, Zscaler

The only thing I would add to it is, remember that we have about 4,600 of what we've determined to be about 20,000 of the largest customers. So there is a 75% white space, if you will, relative to new logos. So there is a large opportunity for us to continue to replicate the success that we've had with existing customers into the 75% that we've yet to serve.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay. Let's go back to John in the corner and then Saket up in the front.

John DiFucci
Analyst, Guggenheim Securities

Thanks. Good eyes, Kim. I'm way back here.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Yeah.

John DiFucci
Analyst, Guggenheim Securities

It's John DiFucci from Guggenheim. I guess I want to go back to Fatima's question because AI does look like a discrete opportunity at this point out there, and that's how all cyber companies are addressing it. But if AI becomes part of everything and is much broader, as Dhawal mentioned earlier, doesn't it just become part of everything you do and everything everybody does? If that's the case, that $2 billion number you put out there, to me, I just wonder how we should be thinking about that and frankly, how the risk in it. Then just a quick follow-up for Kevin. Why in 2026 did the delta between free cash flow and operating cash flow narrow so much in 2026? I don't think it was just CapEx. But thank you.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

You want to start?

Kevin Rubin
CFO, Zscaler

Yeah, I'm happy to go with the last one. John, we did see a pretty significant tick-up in CapEx as a result of pricing and supply chain related items. The other deviations is really just timing.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Maybe I can start on the AI and data side of it. We're going to keep the answer short this time.

Yes, AI and data are interrelated. You saw the presentation. For the first time I've seen any presentation with AI and data is sitting together. Discovery of AI data, risk of AI and data, who accesses what? They're all related in our solution. We are selling it as a combined solution, but also giving option to customer to buy individual solutions. There are separate buying centers for data security today. AI is separate, but they're coming together. As time goes on, you're going to see more and more stuff being sold together.

John DiFucci
Analyst, Guggenheim Securities

But it's more than just data, Jay. I'm sorry. It's more than just data. If you think of endpoint, you think of identity, you think of They're all related to data, but it's more than just data. It's process. It's things happening, everything happening out there, right?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Right.

John DiFucci
Analyst, Guggenheim Securities

It's—

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Right.

John DiFucci
Analyst, Guggenheim Securities

I'm just concerned about the $2 billion out there because I think you guys are doing a great job, but it seems like some risk to put that out there.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Lots is happening, but we need to figure it out. Our job is to make sure right entity can access right entity, so thing don't get compromised and data doesn't lose, leak out. We're not trying to figure and fix every workflow in the company. Right security, the right access. For that, identity plays a role, inspection plays a role, and AI is a main source, and data is one of the key pieces to look at. We can take it more offline. But it's good. Yeah.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Thank you, John. Saket, right up here in front.

Saket Kalia
Analyst, Barclays

Thanks. Saket Kalia at Barclays. Great session as always. Jay, this question's for you, right? The message on the mix shift, right, as part of this long-term plan is very clear, right? There's about 25% of ARR, give or take, right? That will become a bigger mix by 2031, right? What about the user part, right? Which right now is the vast majority. I think let's just assume the $8 billion right now, right? Just for a base case. That'll still be the majority, I think, right, by 2031. You correct me if I'm wrong. I just want to ask the question, can the user part of the business grow faster than double digits? A question that hasn't been asked yet today that I think is on all of our minds is, what about competition? Can we just do a level set on competition in the user market?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

If you think about competition, first of all, we pioneered securing users with Zero Trust. Largely, competition is now trying to secure users without Zero Trust. When you guys talk about all the firewall vendors as a competition, none of them are Zero Trust even for users. All the SASE and SSE It's still firewalls and VPNs running in the cloud. That's a starting point, and they cannot afford to change to Zero Trust architecture because of cannibalization that's going to cause because all the firewalls go away. Our customers are telling us that they need to take care of that. Number one. The next part, we are not selling any users. Customers are asking for Zero Trust everywhere. I'm not going and saying, buy my user stuff. I'm going and saying, you need Zero Trust everywhere. Users, branches, devices, cloud workloads, and next becomes agents.

You need to look at the solution and customers buying us holistic story. User is one part of it. It's an important part of it. I think if you ask me what piece will be the biggest piece, it's too early to tell, but I'll tell you agents will become the biggest piece because that number will grow significantly. That's even more risk than users. We are so well positioned to sit in line, understand how to deal with agent traffic. Also, we've taken one other approach. A lot of stuff will happen in the cloud and exchange. Some will happen on the endpoint. We've all talked about having a solution that takes our endpoint and exchange both. We are pretty unique in that area.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay, we'll do Peter in the second row, and then up to the front for Roger.

Peter Levine
Analyst, Evercore

Thank you. Peter Levine, Evercore. A follow-up question to Saket. We think about competition, your predecessor. What are you keeping? What are you changing? If you think about you now stepping in the role, what are you thinking about? Just help us level set some of the changes, anything that you're thinking about that worked. Then second, Kevin, to John's question, I was going to ask it similar, but maybe if you think about the $2 billion, is that a base case? Is that bull case, bear case? How did you come up with that number, and the realistic based on the products you have today, what is that fit?

Kevin Rubin
CFO, Zscaler

Yeah. So I'm happy to kick it off. Look, we outlined a base case that gets us to $8 billion by fiscal 2031, more than double the ARR. I kind of articulated through how we see the growth opportunities to achieve that case. The $10 billion is really a scenario where AI happens faster and in a much more meaningful way, and it happens across the totality of what we offer, right? One of the things that you've heard from us this entire morning is we believe that the architectural foundation of what we offer is uniquely going to be driven by AI, right? When you think about all of the different threats and exposures that exist, the ability to reduce your tech surface and eliminate lateral movement is just fundamental to how you secure AI. So we think that everything in the platform will ultimately benefit.

I'm not trying to put a $2 billion bogey on just AI. It really is the momentum that likely could play out with AI and the benefits across the totality of the platform as a result of that. I don't know, Jay, if—

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

If I may add. I think the demand is growing, everything's growing so rapidly. We will not be constrained by market size. I don't believe we'll be constrained by competition. The main thing will be how well we execute as a company. Our execution on internal products and go-to- market is really what we are looking at, and that's why we've given you the targets we're giving you.

Ross Tackett
CRO, Zscaler

Yeah. On your first question, great segue, Jay. What I'm thinking about is execution. I've been at Zscaler three years. I've been part of every strategic conversation. I was part of the annual planning. We have a plan, and it's time to go execute it. The elements of that plan we've talked about, I think, a bunch. New logos, platform expansion, international public sector, sovereign cloud, maximizing our specialty sales team. Those are the things I'm focused on, and it's really about execution versus a change in strategy because I think we have the right strategy, and it's time to put the foot on the gas.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Yes, to add on. The question was what changes. As Ross has said, we aren't expecting any meaningful changes. The approach is working. We just need to keep on executing with focus. A strong team, strong bench. Changes from time to time are a good thing. I'm very confident in the leadership and go-to- market, and we will execute and we'll deliver on our numbers.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay. Roger, right here at front.

Roger Boyd
Analyst, UBS

Cool, thank you. Roger Boyd with UBS. Jay, it felt like one of the themes today was the strength that new products are having in driving new logos, and you talked about the 40% of Zero Trust Branch customers that are new to Zscaler, the 350,000 branch win that you had, and the ability to land with AI Gateway. It seems like a lot of this might be product led. You talked about the differentiation you have compared to SD-WAN as well as AI Gateway, but can you talk about how these customers are finding Zscaler? For Ross, how do you think about building sustainable sales motions to go after these non-ZIA and ZPA lands, and how does that kind of factor in the next five years?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Your first part, Zero Trust Branch. It's growing very rapidly. The new logo, actually new logos aren't coming because of just the branch. New logos are coming because when the customer buys Zero Trust for Users, they want Zero Trust Branch at the same time. So the deal is getting bigger, and this is helping us win bigger deals and a bigger part of the solution. You always seen us do early on. Remember we used to have ZIA just for business enterprise. We combined the bundles, ZIA, ZPA. It's natural. When customers want a bigger part of the platform, Zero Trust for Users and Branch is happening together. We'll see, as we're starting to see more and more cloud workloads happening together. Our goal is to sell the platform. Since it's integrated platform, it's working.

Ross Tackett
CRO, Zscaler

And I think your other question is around sales plays?

Roger Boyd
Analyst, UBS

[inaudible] investing around landing something like AI Gateway?

Ross Tackett
CRO, Zscaler

Very important. Adam, maybe you can chime in. We work with the product teams very closely to develop these sales plays and make these sales plays consumable for our field as well as our customers, pardon me. Then we work with our marketing team to launch that out there. We've got roughly five to six sales plays that our teams have been enabled on, which are at a high level conversation, and then they bring in the real technical people to get under the covers.

Adam Geller
Chief Product Officer, Zscaler

Yeah. Very quick add on that. The reason why I highlighted this in my presentation, yeah, I'm glad you did pick up on it. I'm two years at Zscaler. That was not as high a priority of a focus. That did involve, you have to adjust your products so that they are easier to land and more focused, and that's what we did. That creates this new opportunity for messaging and how to explain to customers where you can start with us, and then the selling motion of that. This is really the year where we're driving that with force. We're excited to see where that plays out, and it's why we wanted to articulate that to this group.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay, we'll go to the second row here, Shrenik and then Gray, and then we'll move down to Gregg.

Shrenik Kothari
Analyst, Baird

Great. Shrenik Kothari from Baird. All of you guys did reinforce the re-acceleration potential, the re-acceleration embedded in the long-term framework. But did not go too deep into what is still relatively under-monetized or unmonetized opportunity to monetize the Zero Trust Exchange for agents. Which is going to be indexed towards traffic and agent transactions. Just how should we think about that agentic monetization evolving, and then how is that contemplated in the long-term framework beyond just kind of re-acceleration through new logos and users and seats?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

I'll start. If there's number one thing that's holding enterprises back from fully rolling out agents is the security policy governance concern. It's not easy to do. Everyone seems to talk, well, I got control plane, I got this in plane. How do you even get the data? Agents can be, the control plane can be sitting on an EDR endpoint. It can be sitting here. You need to be able to take agentic traffic coming from Salesforce, coming from Snowflake, Databricks, hyperscalers, endpoint, all these places. We've done some of the same kind of stuff before when we did cloud workloads, when we did Zscaler for Users part of it. So we are pretty well-positioned. We have a product that we launched in June. It's in early availability right now.

And this is going to take some time, even though there's more interest in the design partners, customers for this product than any other product. When you're sitting in line, you need to understand things right. There are many things that are little nuanced in the agentic world, intent, all those contexts. Our team is figuring out working with them. But agentic product, agentic exchange will take some longer time. The other products, visibility, discovery, Access Graph, all this stuff is good seeding for us. I think we are well-prepared. Are we really factoring exactly in what we know about agentic exchange? It is a little bit too early to say, but early indicators are very positive.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah. To add to what Jay said, one of the advantage we have that we already have a footprint where agents are getting deployed. On the endpoint, we have a client that can steer traffic to our AI Gateway already. Then we have seen in public clouds, neo clouds, edge compute platforms, SaaS services where the agents are embedded. We are able to steer traffic from them. A lot of that complexity is what we have solved. Now, building the functional layer of features and policies and intent and context is what we are building, so very strong design partnership, and we expect this to grow in a meaningful way.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Let us head to Gray in the second row right there.

Gray Powell
Analyst, U.S. Bank

Great. Thank you. Thank you very much. Gray Powell with U.S. Bank. I actually wanted to follow up on Roger’s question earlier, and Jay, you hit on this. We frequently hear that customers, they want to buy security service edge and SD-WAN together in the same motion. I guess my question is, what gets customers comfortable with your product over a dedicated SD-WAN product or something that just gets bundled in with network security? Then, it sounds like you are seeing good demand for it. I am just curious, what kind of uplift do you see to the typical Zero Trust for Users ACV or whatever metric you want to give when customers take Zero Trust Branch?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

First of all, industry analysts have asked us, go into SD-WAN business. I said we want disruptive technologies that have no lateral movement. We refuse to really go with SD-WAN market when everyone kind of say, I'm SD-WAN, I'm SD-WAN. It took us some time to build Zero Trust Branch, no lateral movement. It's becoming more and more important today. When we were getting the product out last year or early stage, I was thinking that perhaps 2/3 of our customers will embrace it. Others will still say, I want my SD-WAN. I can tell you every Zscaler customer I talk to, they're all ready to dump SD-WAN and go with Zero Trust Branch. I am surprised, but that's what results are. In this frontier model world, where risks are growing of breaches and lateral movement, SD-WAN is a risk.

The only time customers buy SD-WAN now, when we haven't been able to spend time and show them the merits of it. When we engage, we tell them, SD-WAN elimination and having Zero Trust Branch and user is a very natural thing. The next day, I want to be here and say Zero Trust Cloud workload is a natural thing, and for the same thing in agents. Being able to do Zero Trust Everywhere is the key strength of Zscaler, and we'll build upon it.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Gregg?

Gregg Moskowitz
Analyst, Mizuho

Hi, it's Gregg Moskowitz from Mizuho. I thought you did a really good job today outlining your Zero Trust Everywhere solution and specifically the benefits of it, hiding all applications, strong microsegmentation, preventing lateral movement, layering on extensive AI security protection, et cetera. But the SASE market does seem to have become more crowded or minimally noisier, I would say in recent months, if not the last year or two. When you speak with customers, Jay, Ross, how much confusion exists? I think all of us here can appreciate that strong execution can drive a winning outcome. But over, again, the past year or so, has it become a bit more difficult to articulate your value proposition to customers and to close new and upsell transactions? Thank you.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

I'll start by saying, look, when we get engaged, we almost always win because we're able to clarify it. It is true that every vendor in security wants to be in SASE because if they aren't in SASE, if SASE is a big part of it, then what are they? SASE eventually, if done right, will consume all the firewall business. Okay. If really firewall vendors were to do real SASE, they'll be worried about SASE because no firewalls will be needed. But our goal is really not to pigeonhole SASE for users. We bring the story together. Our goal is to show differentiation on branch level, show differentiation on cloud workload level. Wherever we go, who offers Zero Trust Everywhere? Or who offers Zero Trust SASE Everywhere? What do you do in the cloud? It's the same old virtual firewalls. Nothing is new.

Branch is the same old SD-WAN. In the user level, it is firewall in the cloud as a virtual firewall. It is VPN in the cloud as a virtual VPN. That is not real competition. I think a lot of bundling that has happened, that will come out, and I am feeling very bullish and confident. We just need to keep on executing on the sales side.

Ross Tackett
CRO, Zscaler

Jay, I do not have a lot to add. I am very bullish and confident as well. It is about execution. As Jay mentioned, we are fundamentally different, and it is our job to explain the value in that difference.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Let us go to Eric.

Eric Heath
Analyst, KeyBanc

All right. Thank you. Eric Heath with KeyBanc. A question for Dhawal, I guess. I thought it was really interesting, the comment you had, that you were the only vendor with the context and intent to understand agentic and AI actions. Can you just elaborate on that point a little bit more and maybe help us delineate the lines of where the endpoint visibility ends and where your visibility picks up? Obviously there is a lot of rhetoric that a lot of the agentic activity happens on the endpoint. Help us understand what is incremental in terms of unique data that you can provide and be that enforcement point.

Dhawal Sharma
EVP of AI Security and Strategic Initiatives, Zscaler

Yeah. I will start by saying that context layer in a lot of agent security platform is tied to agent identity only. Going back to what I said earlier, the visibility we are building with connecting the dots of data identity and AI and using that as the context with our gateway and endpoint is unique. So that context layer is the golden layer. A lot of new AI gateways that are coming in the market are very intent-focused or use case-focused. I think one of the biggest advantage in that area is, yes, the intent policy stack will become very commoditized over a period of time. But being able to build AI Gateway at scale at which we run our cloud is something, as a muscle that we as a company have built.

So bringing context from a Zero Trust perspective and intent from a functional perspective, when you bring it together, we are seeing that validation coming from our customers, from a design perspective, that we are unique. Your point on Endpoint AI Security is good because when we think about where policies can be enforced, the amount of attacks or phase that gets generated on the endpoint with the actions that AI agentic applications can do on the endpoint with data, as well as actions they can take, they actually are becoming hard to control before even it hits the network. You can do a lot of damage within the network itself or before it hits the gateway. That's why being able to meaningfully do when things are happening within a prompt and controlling that kind of skill files that people are downloading, for example.

Those kind of controls could be implemented there, but one thing we have already done is our Endpoint AI Security product is fully integrated with our gateway. When the traffic needs to leave to the internet or to an agentic application, that is subject to gateway policy if the agentic action on the endpoint is not triggered. So it's best of both our approaches that we are taking in such things. It's either/or.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay, hands one more time. Josh, right there.

Joshua Tilton
Analyst, Wolfe Research

Thanks, guys. Joshua Tilton from Wolfe Research. There has been a lot of talk today about re-accelerating new logos. If you look at the other side of that, it has been pretty impressive that you have been able to sustain a mid-teens NRR for the last three years. When you look at the FY 2031 target, maybe just in the context that $8 billion, do you still expect to be achieving a mid-teens NRR rate?

Kevin Rubin
CFO, Zscaler

I did not call out a particular longer-term target for net expansion, but it is fair to say that I would expect that we continue to have significant success upselling based on everything that you heard today, the broader platform, et cetera.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay, probably time for one, maybe two more. We will go over to the second row aisle. Then I think we have one here, and you will be our last.

Mike Cikos
Analyst, Needham

Thanks. Mike Cikos from Needham, and thanks again for hosting the day. Maybe just building off the building blocks here, but Ross, I know you were saying we are looking at the execution, and you had spoken about the hunter territories earlier. Can you just give us or elaborate on that further, like where are we? Was that something that we just established at sales kickoff, and what is required as far as hiring bodies to stand that up, ramp time to start seeing the fruits of those investments?

Ross Tackett
CRO, Zscaler

Yeah, and Jay, if you want to chime in as well. You and I have had a lot of discussions about this. Historically, we have had new logo hunters around the globe, and we have expanded that here in FY 2027. That is not our only new logo motion, though. We have territories that have a combination. They're hybrid territories with new logos and existing customers where that makes sense. So, we are building out those additional territories, or they have been built out, I should say, and hiring is almost complete for all of those. We've talked about new logos. I do want to come back and remind everybody the white space opportunity we have within our existing customers. We've only got 4,600 out of the 20,000, and then if you look at those 4,600, there's like a $20 billion TAM, and we have $3.8 billion of that.

Yes, new logos are important, but we have a tremendous opportunity within our existing customer set.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

If I may add, yes, as a part of the fiscal 2027 plan, the territories were very well done. We spent a lot of time understanding each territory. What's the mix of new logo versus upsell current customers? Because ideally, you want to give a balance of both to many reps. But then having some of the very focused hunter territories. Both are in motion, so I don't want to send a message that we are expecting new logo only from hunters-only territories. That's one more step. A combination of that and existing reps who have both new and upsell opportunities. We expect—

Ross Tackett
CRO, Zscaler

Spot on.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

—good results this year.

Ross Tackett
CRO, Zscaler

Yes, spot on, Jay.

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Yeah.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay, well, Junaid, then I am going to add one more, Rich Poland, and then we are going to wrap.

Junaid Siddiqui
Analyst, Truist Securities

Thank you. Junaid Siddiqui, Truist Securities. Jay, we have seen some of your competitors expand deeper into observability, and we are seeing some of the swim lanes converge in security. Where do you see Zscaler uniquely positioned in that convergence and, given your inline architecture and vision around Agentic SecOps, do you see evolving towards an operational control plane beyond just security?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

We generally got very strong convictions about where we want to go, where we do not want to go. Generally, it is not driven by somebody buying a vendor A or vendor B or vendor C. We think our customers want meaningful integrated solutions in certain areas. You saw the TAM we had today. It is a massive TAM in a very synergistic area. Do we need to get into observability to look at performance across everything? That is a secondary area, not really. The core markets we shared with you, they are so big, so massive. I would rather dominate those markets than trying to expand into other markets.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay.

Adam Geller
Chief Product Officer, Zscaler

Where it becomes complementary really quick and additional, though, is, as I said, if we are mission-critical infrastructure for a customer with our Zero Trust SASE Everywhere, understanding the end-to-end experience on that is quite important, and that is why we do have our ZDX, but it is specifically about the experience for things on Zscaler's platform across Zero Trust SASE, not general IT observability. I think that is the right lane for us to be in for it, and it is a big value for our customers.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay, I'm going to try to squeeze one more in. Rich Poland in the front row.

Rich Poland
Analyst, Wells Fargo

Thank you, Kim. Rich Poland from Wells Fargo. I think just to kind of bring it all together, I think one of the questions that we've gotten from investors is just thinking about SASE and the architectural shift that Zscaler proposes is a large undertaking. I think part of the reason why you've seen some of the SD-WAN is because it's kind of almost the path of least resistance in some cases. While customers are thinking about AI and all these other things that are going on right now in this current environment, just kind of how do you think about getting customers that would be new logos who are embracing Zero Trust Everywhere over that hump?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Yeah. I'll start. Actually moving to Zscaler Zero Trust is not a large undertaking. We've seen customers deploying, say, Zero Trust for Users in a matter of weeks or a few months. All you need to do is start with a lightweight agent on the endpoint. You don't even touch your network. The traffic starts taking whatever path is available. You define some policies. We can be fully up and running. Now, it can take time to dismantle all the stuff that's sitting there. But customers typically get moving with rolled out Zscaler, start getting the benefit of security, and then have the benefit of removing the stuff. Now, if we get some inertia and pushback, generally that comes from lower level, people who own those stuff. A little bit job security, a little bit of inertia. I know this thing too.

That's why we have very strong relationship with CIOs, CSOs, CTOs, AI officers. Who drives change? The leadership does. When they want to embrace AI, they really become a catalyst for us. So we're seeing AI as a catalyst. Not to say that Zscaler requires a big infra change. The world is moved to the level where the management is buying our story. That's why we're seeing a lot of expansion. The customer you heard today, and the example we shared with you today, these customers starting with $1 million to $5 million to $10 million to $20 million. This is real, it's happening because the benefits we offer.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay. That's it on Q&A. Jay, do you want to wrap us up?

Jay Chaudhry
CEO, Chairman, and Founder, Zscaler

Yes. Thank you again for joining us today. We hope that today's presentation has given an opportunity to see that, one, Zscaler is the cybersecurity platform for the AI era. Two, AI is the largest tailwind our business has ever seen. And three, we have strengthened our go-to-market engine, and we intend to keep on penetrating it, driving it to achieve our large TAM. We have multiple growth engines that will accelerate our growth to move forward, and we look forward to proving you that we can do it in coming quarters.

Kim Watkins
SVP of Investor Relations and Strategic Finance, Zscaler

Okay. Thank you, Jay. And thanks for all of you for joining us today and making the time. For those of you online, this will end our webcast.