This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

Zscaler, Inc.
5/29/2025
Thank you for standing by, and welcome to Zscaler's third quarter fiscal year 2025 earnings conference call. At this time, all participants are in a listen-only mode. After the speaker presentation, there will be a question and answer session. To ask a question during the session, you will need to press star 11 on your telephone. To remove yourself from the queue, you may press star 11 again. I would now like to hand the call over to Ashwin K. Seredi, Vice President, Investor Relations and Strategic Finance. Please go ahead.
Good afternoon, everyone, and welcome to the Zscaler Third Quarter Fiscal Year 2025 Earnings Conference Call. On the call with me today are Jay Chowdhury, Chairman and CEO, and Remo Kanissa, CFO. Please note, we have posted our earnings release and a supplemental financial schedule to our investor relations website. Unless otherwise noted, all numbers we talk about today will be on an adjusted non-GAAP basis. You will find the reconciliation of GAAP to the non-GAAP financial measures in our earnings release. I'd like to remind you that today's discussion will contain forward-looking statements. including, but not limited to, the company's anticipated future revenue, annual recurring revenue, calculated billings, operating performance, gross margin, operating expenses, operating income, net income, free cash flow, dollar-based net retention rate, future hiring decisions, remaining performance obligations, income taxes, earnings per share, our objectives and outlook, our customer response to our products, and our market share and market opportunity. These statements and other comments are not guarantees of future performance, but rather are subject to risk and uncertainty, some of which are beyond our control. These forward-looking statements apply as of today, and you should not rely on them as representing our views in the future. We undertake no obligation to update these statements after this call For a more complete discussion of the risks and uncertainties, please see our filings with the SEC, as well as in today's earnings release. I also want to inform you that we'll be attending the following conferences. Bank of America Global Technology Conference on June 5th. FBN Virtual Technology Conference on June 6th. BMO Virtual Software Conference on June 9th. Now, I'll turn the call over to Jay.
Thank you, Ashwin. Our strong Q3 results demonstrate growing demand for our platform and continued improvement in our sales productivity. More customers are adopting Zscaler's comprehensive solutions with platform-wide deals for our zero trust security. Driven by the strong demand, we achieved two significant milestones. First, we achieved our best Q3 with TCV bookings of over $1 billion. And second, our remaining performance obligations, or RPO, are now nearly $5 billion. New logo ACV had strong growth of over 40% year over year. Total new ACV was up double digits year over year once again in the quarter. Our annual recurring revenue, or ARR, was approximately $2.9 billion, representing the third straight quarter of 23% year-over-year growth. We remain on track to reach $3 billion or more in ARR by the end of this quarter. We are proud of achieving these strong top-line results at scale while delivering strong profitability. Our year-to-date fiscal 25 revenue growth of 24% combined with our free cash flow margin of 28% resulted in rule of 52 performance. While many SaaS companies struggle to achieve rule of 40 performance, we have exceeded this industry benchmark for each of the last 21 quarters. Moving on to discussion of our platform. I am very pleased to share that our platform now secures over 50 million users, another significant milestone. This milestone gives us several competitive advantages. First, more users deliver powerful network effect and strengthen our market leadership. Zscaler's Zero Trust Exchange platform sits in line for enterprise communications. Every time we secure a user from a new attack, we apply that protection for all users of our platform, creating a flywheel for improving security. The magnitude of this effect is staggering. Last year alone, our exchange processed over 100 trillion transactions, blocked over 60 billion threats, and enforced over 5 trillion policies. This unique network effect differentiates Zscaler from other vendors trying to pursue this market segment and delivers unparalleled cybersecurity to our customers. Hence, more and more enterprises are selecting Zscaler as the partner of choice. Second, more users mean more high-quality data for our AI solutions. The millions of users, workloads, and IoT devices on our platform result in over 500 billion transactions, generating over 20 petabytes of high-fidelity data per day. As you know, AI is only as good as the data that powers it, and I believe we have the best data. There are two unique aspects to our proprietary data. One, its vast quantity. and two, its high fidelity, both of which we utilize to train our models and deliver highly effective AI solutions. Third, the large volume of proprietary data I just talked about empowers us to deliver cutting edge solutions for security operations. By leveraging our data fabric technology, and correlating our logs with third-party data, we have introduced exposure management and threat management solutions, which deliver a new level of actionable insights for our customers' security operations. Leveraging our scale, we're building new security operations solutions, co-pilots, and agentic AI solutions that will be showcased at our upcoming Zenith Live conferences. With our Zero Trust Exchange platform, we fundamentally transform cybersecurity from firewall-based model to Zero Trust architecture. Firewall-based security creates trusted and untrusted networks. Once a user or a threat actor gets on the trusted network, they are then blindly trusted and can move unchecked across the enterprise network. That is what makes ransomware and other cyber attacks so dangerous. With Zscaler's Zero Trust architecture, there's no concept of trusted networks. Every user, every workload, every IoT device, and every AI model is untrusted. With Zero Trust, we connect only the authorized party to the authorized application. While legacy vendors are attempting to cobble together disjointed point products and calling it a platform, we are constantly expanding our core zero trust exchange by integrating new functionality to solve more and more of our customers' security concerns. Our industry-leading capabilities are recognized by our customers, partners, and leading third-party analyst firms. Of note, I am thrilled to share that Gartner once again recognized Zscaler as a leader in their SSE magic quadrant, extending our status as a leader in the MQ for user security for over a decade. Moving on to the macro environment, customers remain cautious about their IT spending due to ongoing economic uncertainties. While customers are still prioritizing cyber and data protection, return on investment and the value delivered remain important to customers. A couple of quarters ago, we launched our Cost Taker program to help customers identify and eliminate legacy security and networking products such as firewalls, VPNs, VDIs, and more. We are seeing great success with our program as more and more customers are embracing it to reduce cost and complexity while improving security. Additionally, to help our customers unlock more cost savings, we launched a new purchasing program in Q3 called ZFlex. ZFlex allows customers to flexibly scale their adoption of our platform to meet the constantly evolving organizational demands for cyber and data protection. Customers can seamlessly adopt, scale, and change modules based on agreed pricing, which simplifies the procurement process. Since its recent launch, ZFlex commitments contributed over $65 million in TCV bookings. To give you an example, An existing Fortune 500 technology customer made a multi-year commitment under the ZFlex program, increasing their ARR by over 40% to approximately $19 million. As part of the Flex commitment, the customer added managed threat hunting, micro-segmentation, identity threat detection, GenAI protection, and several data security modules. This win also demonstrates our growing capabilities in the SOC and Zero Trust Cloud. I expect the contribution from ZFlex to grow meaningfully in the next fiscal year. Moving to products, we are seeing significant growth drivers in three categories. Zero Trust Everywhere, Data Security Everywhere, and Agentic Operations. Each of these categories is growing significantly faster than our overall ARR. and their combined ARR is approaching $1 billion. Let me cover each of these categories in more detail. On our last earnings call, we introduced Zero Trust Everywhere, which highlights our unique ability to take Zero Trust security beyond users, Zero Trust for cloud workloads, and Zero Trust for branches. In Q3, 59% of customers who bought Zero Trust Branch were new logo customers. Many of these new logo customers are starting their branch journey by securing a small number of branches, which creates significant upsell opportunities for us. We are enhancing our Zero Trust Branch functionality with several innovations. For example, in Q3, we launched our new unified appliance for branch that brings together Zero Trust branch connectivity and Zero Trust device segmentation into a single plug-and-play appliance. This solution dramatically simplifies branch infrastructure, eliminating the need for SD-WAN, firewall, NAC, and legacy segmentation. I expect Zero Trust branch to be a significant growth contributor in fiscal 26. Another key pillar of our Zero Trust Everywhere strategy is Zero Trust Cloud, which enables secure communication from workload to workload and from workload to the internet. Initially, our customers leverage Zero Trust Cloud to secure a small number of workloads to get comfortable with this innovative approach that requires no east-west firewalls, no north-south firewalls, No virtual private networks, no access routes, and no direct connects. Now we are seeing larger deals for Zero Trust Cloud to secure a larger number of workloads, resulting in acceleration of Zero Trust Cloud ARR. To share an example, an existing financial services customer made their initial purchase of cloud workload protection to secure all their internal workload traffic. This is an impressive seven-figure ACV land deal for workload protection. We are seeing tremendous success as more customers are becoming Zero Trust Everywhere enterprises by embracing Zero Trust for Users, Branches, and Cloud. Last quarter, we shared our goal to triple the number of Zero Trust Everywhere customers from over 130 to over 390 by the end of fiscal 26. I'm pleased to share that we ended Q3 with over 210 Zero Trust Everywhere enterprises, which is over 60% quarter-over-quarter growth. With this strong momentum, we remain on track to achieve our target. The second category driving our growth is data security everywhere. We have the most comprehensive data security capabilities to secure all types of data, whether structured or unstructured, data in motion or data at rest, and data across all channels, including Gen AI apps, web, email, endpoint, SAS, DSPM, and more. Our comprehensive data security capabilities are resonating with customers and helping us win large deals. To give you an example, in a seven-figure ACV deal, an existing Fortune 50 automotive customer added an endpoint DLP module and privileged remote access, or PRA, while expanding zero-trust users with more ZPA seats. This customer now has six of our eight data security modules, including inline DLP, SaaS security, cyber isolation, data isolation, classification and encryption, and endpoint DLP. With this deal, the customer's annual spend with us increased by over 50% to well over $10 million. Historically, data security was an important consideration for data-heavy regulated industries such as finance and healthcare. With the increasing adoption of Gen AI and SaaS applications, data security is now becoming important to all industries. To give you an example, in a seven-figure ACV deal, a new logo, Fortune 100 food and beverage company, adopted zero-trust users, and multiple data security modules. Moving to agentic operations, our third category of growth. Our agentic operations are expanding rapidly in two areas, IT ops and SEC ops. For ITOps, we delivered ZDX CoPilot last year as an embedded feature in our ZDX Advanced Plus package. Since the launch of ZDX CoPilot a year ago, bookings for ZDX Advanced Plus grew over 70% year-over-year to nearly $75 million. ZDX CoPilot helps lower the mean time-to-resolution of service tickets. and its capabilities are becoming a key differentiator for us. To give you an example, an existing US-based large healthcare customer purchased ZDX Advanced Plus for 140,000 users in a seven-figure ACV deal. ZDX Co-Pilot was an important consideration for this win. Moving on to the second area of agentic operations, SecOps, where we have several modules, including RISC-360, Business Insights, Unified Vulnerability Management, Identity Threat Detection, and Cyber Asset Attack Surface Management, or CASM. Our SecOps solution, built on the data fabric technology we acquired last year, is gaining traction, and it drove over 120% year-over-year growth in SecOps ACV. To share a customer example, an existing U.S.-based healthcare customer purchased Unified Vulnerability Management for 400,000 assets in a seven-figure ACV deal. The customer told me that UVM gave them an accurate asset inventory within two hours, which is a dramatic reduction from the six months it would have taken them otherwise. We will continue to expand our SecOps solution. The acquisition of Red Canary will allow us to expand into SOC categories of managed detection and response, or MDR, and threat intel. We expect to close this transaction in August 2025. In addition to developing AI-powered solutions, we are enabling customers to safely adopt AI. Our GenAI data security module is enabling enterprises to securely use public GenAI apps such as Microsoft 365 Copilot, DeepSeek, ChatGPT, and more. In Q3, many customers, including an existing global 2000 tech company, a leading fleet management company, and a large federal customer and more purchased our GenAI data security module. In addition to securing public AI apps, We are introducing solutions to secure customers' private AI apps, such as AI models, chatbots, and inference engines. We are expanding the functionality of our Zero Trust Exchange with an LLN proxy to analyze prompt queries to detect and prevent prompt injections and other malicious activities, and analyze responses to prevent data leakage and enforce the right access. I believe these cutting-edge innovations will position Zscaler to be a market leader in the AI security space. Our customer obsession, employee dedication to our mission, and our customers' trust in our platform are driving us to deliver innovations that solve our customers' most critical security challenges. With a strong guru market machine and strong momentum in zero trust everywhere and AI security, I am more excited than ever about our continued growth to $5 billion or more in ARR. Now, I'd like to turn over the call to Remo for our financial results.
You're reading a preview of the ZS Q3 2025 earnings call.
Free account.