SEC EDGAR · 10-K

10-K – 2026-03-05 – okta-20260131.htm

390148 tecken · 3 HTML-del(ar)

Fulltext som ren TXT · Öppna originalkällan

Automatiskt nyckeltalsindex

Detta är sökträffar och textkontext, inte verifierade eller normaliserade redovisningsvärden.

Omsättning
  • Forward-looking statements contained in this Annual Report on Form 10-K include, but are not limited to, statements about: | • our future financial performance, including our revenue, costs of revenue, gross profits, margins and operating expenses; | • trends in our key business metrics;
  • • our ability to adequately fund research and development, and introduce new solutions, enhance existing solutions and address new use cases; | • the sufficiency of our cash and cash equivalents, investments and cash provided by sales of our solutions to meet our liquidity needs; | • our ability to effectively sustain or manage our revenue growth and profitability;
  • • the sufficiency of our cash and cash equivalents, investments and cash provided by sales of our solutions to meet our liquidity needs; | • our ability to effectively sustain or manage our revenue growth and profitability; | • our ability to partner with third-party software vendors and system integrators;
  • • our ability to partner with third-party software vendors and system integrators; | • our ability to expand our international business operations and product sales; | • our ability to adequately fund research and development, and introduce new solutions, enhance existing solutions and address new use cases;
  • • our ability to adequately fund research and development, and introduce new solutions, enhance existing solutions and address new use cases; | • our ability to successfully expand our existing marketing and sales capabilities, including further specializing our go-to-market organization; | • our ability to expand our product sales by promoting our brand and engaging channel partners;
  • • our ability to successfully expand our existing marketing and sales capabilities, including further specializing our go-to-market organization; | • our ability to expand our product sales by promoting our brand and engaging channel partners; | • potential impacts of cybersecurity incidents to our reputation, customer relations and financial results;
  • As of January 31, 2026, more than 20,000 customers across nearly every industry used our solutions to secure and manage identities around the world. These customers consist of leading global organizations ranging from the largest enterprises to small- and medium-sized businesses, universities, nonprofits and government agencies. We partner with a broad range of application, IT infrastructure and security vendors through our Okta Integration Network. As of January 31, 2026, we had over 7,000 inte | We employ a SaaS business model and generate revenue primarily by selling multi-year subscriptions to our cloud-based offerings. We focus on attracting and retaining our customers by building on and increasing the value we provide to them over time. This commitment to our customers’ success helps drive increased customer investment in the number of users of our Okta Platform and Auth0 Platform and adoption of our additional product offerings. We sell our product offerings directly through our fi | Our Platforms
  • Execute with Our Platforms | • Deepen Relationships within Our Existing Customer Base . We strive to further increase revenue from our existing customers by cross-selling and up-selling additional and new product offerings. We also believe we can expand our footprint by focusing on current customers that have deployed our Okta Platform and expanding those customers’ use of our Auth0 Platform, or vice versa. In addition, we believe there is a potential opportunity to offer existing customers our solutions to manage and secur | • Drive Growth with Large Customers . To increase our market share, we intend to focus on growing our base of large customers using a land-and-expand sales model, with a focus on key markets by size of customers, as well as key verticals, including highly regulated sectors.
Rörelseresultat
  • Total operating expenses 2,109 2,066 2,198 | Operating income (loss) | 149 (74) (516)
  • Total operating expenses 72 79 97 | Operating income (loss) | 5 (3) (23)
  • Total operating expenses 2,109 2,066 2,198 | Operating income (loss) | 149 ( 74 ) ( 516 )
Periodens resultat
  • Financial Information and Segments | We operate our business as one reportable segment. For fiscal 2026, 2025 and 2024, our revenue was $2,919 million, $2,610 million and $2,263 million, respectively, representing a growth rate of 12% and 15% in fiscal 2026 and 2025, respectively. For fiscal 2026 and 2025, we generated net income of $235 million and $28 million, respectively, and for fiscal 2024, we generated a net loss of $355 million. Our accumulated deficit as of January 31, 2026 was $2,567 million. | Key Business Metrics
  • 20 18 18 | Net income (loss) | $ 235 $ 28 $ (355)
  • Provision for income taxes 1 1 1 | Net income (loss) 8 % 1 % (16) %
  • 20 18 18 | Net income (loss) | $ 235 $ 28 $ ( 355 )
  • Net income (loss) per share, basic $ 1.33 $ 0.16 $ ( 2.17 ) | Net income (loss) per share, diluted $ 1.31 $ 0.06 $ ( 2.17 )
  • Weighted-average shares used to compute net income (loss) per share, basic 175,882 169,569 163,634 | Weighted-average shares used to compute net income (loss) per share, diluted 179,290 175,086 163,634
  • 2026 2025 2024 | Net income (loss) | $ 235 $ 28 $ ( 355 )
  • — — — — — ( 6 ) — ( 6 ) | Net income | — — — — — — 28 28
Resultat per aktie
  • The Company computes basic and diluted net income (loss) per share attributable to common stockholders for Class A and Class B common stock using the two-class method required for participating securities. Under the two-class method, basic net income (loss) per share attributable to common stockholders is computed by dividing the net income (loss) attributable to common stockholders by the weighted-average number of shares of common stock outstanding during the period. | Diluted earnings per share attributable to common stockholders is computed by giving effect to all potential shares of common stock, including shares underlying convertible senior notes, unvested RSUs, outstanding stock options, unvested common stock and restricted stock issued in connection with certain business combinations, and ESPP obligations, to the extent they are dilutive. The dilutive effect of potentially dilutive common shares included in diluted earnings per share is determined in ac | The rights of the holders of the Company’s Class A and Class B common stock are identical, except with respect to voting and conversion rights.
Kassaflöde
  • Our prior revenue growth rates may not be indicative of our future growth or performance. | Our revenue growth depends on several factors, including pricing our platforms to attract new and retain existing customers; managing demand for our solutions; competing against larger companies and new market entrants; capitalizing on new acquisitions, technologies or growth opportunities; and other conditions described in these risk factors. If we are unable to grow our revenue, it will be difficult to maintain our profitability, or maintain or increase our cash flow on a consistent basis. We | Our growth depends, in part, on the success of our strategic relationships with third parties.
  • Servicing our debt may require a significant amount of cash. We may not have sufficient cash flow from our business to pay our indebtedness. | We have issued convertible notes due in 2026 (the “2026 Notes”). Our ability to make scheduled payments of the principal of, to pay interest on or to refinance our indebtedness, including the 2026 Notes, depends on our future performance, which is subject to economic, financial, competitive and other factors beyond our control. Our business may not generate cash flow from operations in the future sufficient to service our debt and make necessary capital expenditures. If we are unable to generate
  • Servicing our debt may require a significant amount of cash. We may not have sufficient cash flow from our business to pay our indebtedness. | We have issued convertible notes due in 2026 (the “2026 Notes”). Our ability to make scheduled payments of the principal of, to pay interest on or to refinance our indebtedness, including the 2026 Notes, depends on our future performance, which is subject to economic, financial, competitive and other factors beyond our control. Our business may not generate cash flow from operations in the future sufficient to service our debt and make necessary capital expenditures. If we are unable to generate | We may not have the ability to raise the funds necessary for cash settlement upon conversion of the 2026 Notes or to repurchase them for cash upon a fundamental change, and our future debt may contain limitations on our ability to pay cash upon conversion of the 2026 Notes or to repurchase the 2026 Notes.
  • We employ a SaaS business model and generate revenue primarily by selling multi-year subscriptions to our cloud-based offerings. We focus on attracting and retaining our customers by building on and increasing the value we provide to them over time. This commitment to our customers’ success helps drive increased customer investment in the number of users of our Okta Platform and Auth0 Platform and adoption of our additional product offerings. We sell our product offerings directly through our fi | Our revenue is relatively predictable as a result of our subscription-based business model, which constituted approximately 98% of total revenue for fiscal 2026. Future growth may be impacted by longer sales cycles, which we have experienced, which in turn, could result in delays in deals closing, creating near-term headwinds for cash flow, remaining performance obligations (“RPO”) and billings growth as well as potential future impacts on revenue growth and other key metrics on a trailing basis | Impact of Cybersecurity Incidents
  • Supplementary cash flow disclosure:
Likvida medel
  • • our ability to adequately fund research and development, and introduce new solutions, enhance existing solutions and address new use cases; | • the sufficiency of our cash and cash equivalents, investments and cash provided by sales of our solutions to meet our liquidity needs; | • our ability to effectively sustain or manage our revenue growth and profitability;
  • As of January 31, 2026, our principal sources of liquidity were cash, cash equivalents and short-term investments totaling $2,553 million, which were held for working capital and general corporate purposes, including potential future acquisition activity. Our cash equivalents and investments consisted primarily of U.S. treasury securities, money market funds, corporate debt securities and certificates of deposit. | Recent macroeconomic events, including changes in interest rates, global inflation and bank failures, have led to further economic uncertainty in the global economy. To mitigate risk, our cash and cash equivalents are distributed across large financial institutions. In addition, we have policy restrictions in place on the types of securities that can be purchased as part of our available-for-sale securities portfolio. These restrictions take credit quality, liquidity and diversification into con | In January 2026, our board authorized a stock repurchase program of up to $1 billion of our outstanding shares of Class A common stock (the “Share Repurchase Program”). We have and may repurchase shares of our Class A common stock from time to time through open market purchases, in privately negotiated transactions, or by other means. Open market repurchases may be structured to occur in accordance with the requirements of Rule 10b-18. We may also, from time to time, enter into Rule 10b5-1 tradi
  • On September 4, 2025, we acquired all of the outstanding equity of Axiom Security Ltd (“Axiom”), a privately held company specializing in privileged access management solutions. The acquisition date cash consideration was $54 million. See Note 16 to our consolidated financial statements “Business Combinations” for additional information. | We believe our existing cash and cash equivalents, our investments and cash provided by sales of our solutions will be sufficient to meet our short-term and long-term projected working capital and capital expenditure needs for the foreseeable future. Our future capital requirements will depend on many factors, including our subscription growth rate, subscription renewal activity, billing frequency, the timing and extent of spending to support development efforts, the expansion of sales and marke | A significant majority of our customers pay in advance for annual subscriptions. Therefore, a substantial source of our cash is from our deferred revenue, which is included on our consolidated balance sheet as a liability. Deferred revenue consists of the unearned portion of billed fees for our subscriptions, which is recognized as revenue in accordance with our revenue recognition policy. As of January 31, 2026, we had deferred revenue of $1,905 million, of which $1,875 million was recorded as
  • Interest Rate Risk | We had cash, cash equivalents and short-term investments totaling $2,553 million as of January 31, 2026, of which $2,365 million was invested in U.S. treasury securities, money market funds, corporate debt securities and certificates of deposit. Our cash and cash equivalents are held for working capital and general corporate purposes, including potential future acquisition activity. Our short-term investments are made for capital preservation purposes. We do not enter into investments for tradin | Our cash equivalents and our investment portfolio are subject to market risk due to changes in interest rates. Fixed rate securities may have their market value adversely affected due to a rise in interest rates. Due in part to these factors, our future investment income may fall short of our expectations due to changes in interest rates or we may suffer losses in principal if we are forced to sell securities that decline in market value due to changes in interest rates. However, because we clas
  • Current assets: | Cash and cash equivalents $ 858 $ 409 | Short-term investments 1,695 2,114
  • Reconciliation of cash, cash equivalents, and restricted cash within the consolidated balance sheets to the amounts shown in the statements of cash flows above: | Cash and cash equivalents $ 858 $ 409 $ 334 | Restricted cash, current included in prepaid expenses and other current assets 1 1 2
  • Cash, Cash Equivalents and Restricted Cash | Cash and cash equivalents consist of cash on hand and highly liquid investments with original maturities of three months or less from the date of purchase. Cash equivalents generally consist of investments in money market funds. The fair market value of cash equivalents approximated their carrying value as of January 31, 2026 and 2025. | 73
  • Concentrations of Risk | Financial instruments that are exposed to concentrations of credit risk consist primarily of cash and cash equivalents, short-term investments and accounts receivable. The Company’s short-term investments are primarily intended to facilitate liquidity and capital preservation and consist predominately of highly liquid investment-grade fixed-income securities, diversified among industries and individual issuers. The Company’s policy is designed to limit exposure from any particular issuer or inst | Credit risk arising from accounts receivable is mitigated due to the large number of customers and their dispersion across various industries and geographies. For the periods presented, there were no customers that represented more than 10% of the Company’s accounts receivable balance or total revenue.
Nettoskuld
  • transactions, which are generally required to be computed on an arm’s-length basis pursuant to intercompany arrangements or disagree with our determinations as to the income and expenses attributable to specific jurisdictions. If such a challenge or disagreement were to occur and our position was not sustained, we could be required to pay additional taxes, interest and penalties, which could result in one-time tax charges, higher effective tax rates, reduced net cash flows and lower overall prof | Changes in tax laws or regulations in the various tax jurisdictions we are subject to that are applied adversely to us or our customers could increase the costs of our solutions and harm our business.
  • (dollars in millions) | Net cash provided by operating activities $ 884 $ 750 $ 512 | Net cash provided by (used in) investing activities 271 (314) 441
  • Net cash provided by operating activities $ 884 $ 750 $ 512 | Net cash provided by (used in) investing activities 271 (314) 441 | Net cash used in financing activities
  • Net cash provided by (used in) investing activities 271 (314) 441 | Net cash used in financing activities | (720) (359) (883)
  • Net income (loss) $ 235 $ 28 $ ( 355 ) | Adjustments to reconcile net income (loss) to net cash provided by operating activities: | Stock-based compensation 544 565 684
  • Deferred revenue 187 207 250 | Net cash provided by operating activities 884 750 512 | Cash flows from investing activities:
  • Purchases of intangible assets — — ( 1 ) | Net cash provided by (used in) investing activities 271 ( 314 ) 441 | Cash flows from financing activities:
  • Net cash used in financing activities | ( 720 ) ( 359 ) ( 883 )
Eget kapital
  • (1) Includes related commissions. | (2) On January 5, 2026, our board authorized a program to repurchase up to $1 billion of our common stock. See Note 1 1 to our consolidated financial statements “Stockholders’ Equity” for additional information. | 43
  • Consolidated Statements of Stockholders’ Equity | 67
  • Opinion on the Financial Statements | We have audited the accompanying consolidated balance sheets of Okta, Inc. (the Company) as of January 31, 2026 and 2025, the related consolidated statements of operations, comprehensive income (loss), stockholders’ equity and cash flows for each of the three years in the period ended January 31, 2026, and the related notes (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the fin | We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company’s internal control over financial reporting as of January 31, 2026, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework), and our report dated March 5, 2026 expressed an unqualified opinion thereon.
  • We have audited Okta, Inc.’s internal control over financial reporting as of January 31, 2026, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) (the COSO criteria). In our opinion, Okta, Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of January 31, 2026, based on the COSO criteria. | We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of January 31, 2026 and 2025, the related consolidated statements of operations, comprehensive income (loss), stockholders’ equity and cash flows for each of the three years in the period ended January 31, 2026, and the related notes and our report dated March 5, 2026 expressed an unqualified opinion thereon. | Basis for Opinion
  • Total assets $ 9,710 $ 9,437 | Liabilities and stockholders’ equity | Current liabilities:
  • Stockholders’ equity: | Preferred stock, par value $ 0.0001 per share; 100,000 shares authorized, no shares issued and outstanding as of January 31, 2026 and 2025.
  • Accumulated deficit ( 2,567 ) ( 2,802 ) | Total stockholders’ equity 6,999 6,405 | Total liabilities and stockholders’ equity $ 9,710 $ 9,437
  • Total stockholders’ equity 6,999 6,405 | Total liabilities and stockholders’ equity $ 9,710 $ 9,437
Antal aktier
  • Future transfers by holders of Class B common stock will generally result in those shares converting to Class A common stock, subject to limited exceptions, such as certain transfers effected for estate planning purposes. The conversion of Class B common stock to Class A common stock will have the effect, over time, of increasing the relative voting power of those holders of Class B common stock who have retained their shares. | Sales of a substantial number of shares of our Class A common stock in the public markets, or the perception that sales might occur, could cause the market price of our Class A common stock to decline. | Sales of a substantial number of shares of our Class A common stock into the public market, particularly sales by our directors, executive officers and principal stockholders, or the perception that these sales might occur, could cause the market price of our Class A common stock to decline.
  • Sales of a substantial number of shares of our Class A common stock in the public markets, or the perception that sales might occur, could cause the market price of our Class A common stock to decline. | Sales of a substantial number of shares of our Class A common stock into the public market, particularly sales by our directors, executive officers and principal stockholders, or the perception that these sales might occur, could cause the market price of our Class A common stock to decline. | In addition, we have options outstanding that, if fully exercised, would result in the issuance of shares of our Class A and Class B common stock. We also have RSUs outstanding that, if vested and settled, would result in the issuance of shares of Class A common stock. All of the shares of Class A and Class B common stock issuable upon the exercise of stock options and vesting of RSUs and the shares reserved for future issuance under our equity incentive plans, are registered for public resale u
  • In addition, we have options outstanding that, if fully exercised, would result in the issuance of shares of our Class A and Class B common stock. We also have RSUs outstanding that, if vested and settled, would result in the issuance of shares of Class A common stock. All of the shares of Class A and Class B common stock issuable upon the exercise of stock options and vesting of RSUs and the shares reserved for future issuance under our equity incentive plans, are registered for public resale u | Furthermore, a substantial number of shares of our Class A common stock is reserved for issuance upon the exercise of the 2026 Notes (as defined below). If we elect to satisfy our conversion obligation on the 2026 Notes solely in shares of our Class A common stock upon conversion of the 2026 Notes, we will be required to deliver the shares of our Class A common stock, together with cash for any fractional share, on the second business day following the relevant conversion date. | We cannot guarantee that our Share Repurchase Program will be fully consummated or will enhance long-term stockholder value, and stock repurchases could increase the volatility of the trading price of our Class A common stock and diminish our cash reserves.
  • We cannot guarantee that our Share Repurchase Program will be fully consummated or will enhance long-term stockholder value, and stock repurchases could increase the volatility of the trading price of our Class A common stock and diminish our cash reserves. | On January 5, 2026, we announced that our board of directors (our “board”) approved a stock repurchase program with authorization to purchase up to $1 billion of our Class A common stock from time to time (the “Share Repurchase Program”). As of January 31, 2026, a total of $921 million remained available for repurchase under the Share Repurchase Program. Repurchases under the Share Repurchase Program are made in the open market, through privately negotiated transactions or other means, including | If securities or industry analysts do not publish or cease publishing research, or publish inaccurate or unfavorable research, about our business, the price of our Class A common stock and trading volume could decline.
  • Transactions relating to the 2026 Notes may affect the value of our Class A common stock. | The conversion of some or all of the 2026 Notes would dilute the ownership interests of existing stockholders to the extent we satisfy our conversion obligation by delivering shares of our Class A common stock upon any conversion of such notes. Our 2026 Notes may become in the future convertible at the option of their holders under certain circumstances. If holders of the 2026 Notes elect to convert their notes, we may settle our conversion obligation by delivering to them a significant number o | In addition, in connection with the issuance of the 2026 Notes, we entered into Capped Calls with certain financial institutions (the “Option Counterparties”). The Capped Calls are generally expected to reduce potential dilution to our Class A common stock upon any conversion or settlement of the 2026 Notes and/or offset any cash payments we are required to make in excess of the principal amount of converted 2026 Notes, as the case may be, with such reduction and/or offset subject to a cap. If w
  • Period | Total Number of Shares Purchased | (in thousands)
  • Average Price Paid Per Share (1) | Total Number of Shares Purchased as Part of Publicly Announced Program | (in thousands)
  • Recent macroeconomic events, including changes in interest rates, global inflation and bank failures, have led to further economic uncertainty in the global economy. To mitigate risk, our cash and cash equivalents are distributed across large financial institutions. In addition, we have policy restrictions in place on the types of securities that can be purchased as part of our available-for-sale securities portfolio. These restrictions take credit quality, liquidity and diversification into con | In January 2026, our board authorized a stock repurchase program of up to $1 billion of our outstanding shares of Class A common stock (the “Share Repurchase Program”). We have and may repurchase shares of our Class A common stock from time to time through open market purchases, in privately negotiated transactions, or by other means. Open market repurchases may be structured to occur in accordance with the requirements of Rule 10b-18. We may also, from time to time, enter into Rule 10b5-1 tradi | We satisfy employee tax withholding obligations due upon the vesting of share-based awards through net share settlement using available cash. This practice reduces our equity dilution rate and impacts liquidity as our cash requirements for these obligations are primarily driven by the market price of our Class A common stock at the time of vesting. In fiscal 2026 and 2025 , cash paid to satisfy these employee tax withholding obligations was $192 million and $148 million , respectively.
Antal anställda
  • • our ability to release the valuation allowance on our deferred tax assets in the United States; | • the attraction and retention of qualified employees and key personnel; | • the impact of recent accounting pronouncements on our financial statements; and
  • We are the leading independent identity partner. Our vision is to free everyone to safely use any technology, and we believe identity is the key to making that happen. Our purpose is to bring simple and secure digital access to people and organizations everywhere. Our Okta Platform and Auth0 Platform enable our customers to securely connect the right people to the right technologies and services at the right time. | Identity is becoming the most critical layer of an organization’s security. The acceleration of digital transformation, cloud adoption and the evolving security threat landscape continue to drive a shift in how organizations securely manage the identity of their employees, contractors and partners. As organizations shift from network-based security models to a Zero Trust security model focused on adaptive and context-aware controls, identity has become the most reliable way to manage user access | In addition to these established drivers, the emergence of artificial intelligence (“AI”) and the deployment of AI agents may, over time, create new opportunities for identity management. We see a potential long-term opportunity for our platforms to serve as a unified, independent control plane for non-human identities (“NHIs”) and AI agents, a distinct class of identity that requires authenticated, secure access to sensitive resources at a scale and speed exceeding traditional security models d
  • designed to securely connect users to the technology that they choose. We prioritize the compatibility of our platforms with public clouds, on-premises infrastructures and hybrid clouds. Our platforms are traditionally used by organizations in two distinct ways: “workforce identity”, supported by our Okta Platform, to manage and secure employees, contractors and partners; and “customer identity”, supported by both our Okta Platform and Auth0 Platform, to secure customers. | We are extending our platforms to address the unique identity security challenges posed by AI agents. Okta for AI Agents, currently available in early access, provides governance and visibility for AI agents through the Okta Platform. Auth0 for AI Agents enables developers to leverage the Auth0 Platform to secure and scale agentic applications from pilot to production. Cross App Access, currently available in early access, is the interoperability standard that allows these AI agents to securely
  • Okta Platform | The Okta Platform governs and simplifies the way an organization’s employees, contractors, partners and NHIs connect to applications and data from any device. It serves as the central system for an organization’s governance, access management, authentication, connectivity and identity lifecycle management needs. We are expanding these capabilities to include AI agents with the introduction of new product offerings currently in development and early access. We enable our customers to easily deplo | We deliver the capabilities of the Okta Platform by providing:
  • Our Product Offerings | Our portfolio of product offerings and services is designed to manage and secure identity for people, NHIs and, increasingly, AI agents. Our product offerings are designed to be versatile, with most offerings applicable to both customer and workforce identity use cases. Workforce identity solutions are primarily consumed through web and mobile interfaces, providing IT organizations with simple ways to manage access for employees, contractors, partners, NHIs and, through product offerings in earl | Okta Platform Product Offerings
  • Our Customers | As of January 31, 2026, we had more than 20,000 customers, including 5,100 customers with an annual contract value greater than $100,000. Our customers span nearly all industry verticals and range from small organizations with fewer than 100 employees to companies in the Fortune 50, with up to hundreds of thousands of employees, some of which use our platforms to manage millions of their customers’ identities. | 10
  • We are the registered holder of a variety of domestic and international domain names that include “Okta,” “Auth0” and similar variations. | In addition to the protection provided by our intellectual property rights, we enter into confidentiality and proprietary rights or similar agreements with our employees, consultants and contractors. Our employees, consultants and contractors are also subject to invention assignment agreements. We further control the use of our proprietary technology and intellectual property through provisions in both general and product-specific terms of use. | Additional information regarding certain risks related to our intellectual property is included in “ Risk Factors ” under Part I, Item 1A of this Annual Report on Form 10-K.
  • Human Capital Resources | Our core values—love our customers, always secure and always on, build and own it, and drive what’s next—inform and guide our human capital initiatives and objectives. In order to continue to innovate and drive customer success, it is crucial that we continue to attract, develop and retain exceptional talent. To that end, we strive to make our workplace one in which employees feel like they have opportunities to grow and develop in their careers. We support our employees with fair and competitiv | As of January 31, 2026, we had 6,366 employees, of which approximately 56% were in the United States and 44% were in our international locations. We have not experienced any work stoppages, and we consider our relations with our employees to be good. Our employee engagement program helps us understand employee sentiment on a wide range of topics throughout the employee lifecycle, providing insights that inform our decisions about company initiatives, employee programs, talent risks, management o
Bruttomarginal
  • We allocate shared costs, such as facilities costs (including rent, utilities and depreciation on assets shared by all departments), certain information technology costs, security costs and recruiting costs to all departments based on headcount. As such, allocated shared costs are reflected in each of the cost of revenue and operating expense categories. Employee compensation costs reflected in each of the cost of revenue and operating expense categories include salaries, bonuses, compensation r | Cost of Revenue and Gross Margin | Cost of Subscription . Cost of subscription primarily consists of expenses related to hosting our services and providing support. These expenses include employee-related costs associated with our cloud-based infrastructure, our product security organization and our customer support organization, third-party hosting fees, software and maintenance costs, outside services associated with the delivery of our subscription services, amortization expense associated with capitalized internal-use softwar
  • expect our investment in technology to expand the capability of our platforms, enabling us to improve our gross margin over time. The level and timing of investment in these areas could affect our cost of subscription revenue in the future. | Cost of Professional Services and Other . Cost of professional services consists primarily of employee-related costs for our professional services delivery team, travel-related costs, allocated overhead and costs of outside services associated with supplementing our professional services delivery team. The cost of providing professional services has historically been higher than the associated revenue we generate.
  • Cost of Professional Services and Other . Cost of professional services consists primarily of employee-related costs for our professional services delivery team, travel-related costs, allocated overhead and costs of outside services associated with supplementing our professional services delivery team. The cost of providing professional services has historically been higher than the associated revenue we generate. | Gross Margin . Gross margin is gross profit expressed as a percentage of total revenue. Our gross margin may fluctuate from period to period as a result of the timing and amount of investments to expand our hosting capacity and our continued efforts to build platform support and professional services teams. | Operating Expenses
  • For fiscal 2026, the increase in professional services and other revenue was due to higher bookings associated with professional services. Beginning in fiscal 2027, we expect professional services and other revenue to decline as we shift more engagements to our partner ecosystem. | Cost of Revenue, Gross Profit and Gross Margin | Year Ended January 31,
  • Gross profit $ 2,258 $ 1,992 $ 266 13 % | Gross margin: | Subscription 80 % 79 %
  • Professional services and other (29) (29) | Total gross margin 77 % 76 %
  • For fiscal 2026, cost of subscription revenue increased primarily due to an increase of $20 million in labor costs, third-party hosting costs of $15 million, and software costs of $9 million. This was offset by decreases in consulting costs of $10 million and stock-based compensation of $8 million. | Our gross margin for subscription revenue improved from 79% to 80% during fiscal 2026. The increase was primarily driven by improved spend efficiency resulting in lower relative cost of subscription revenue. | For fiscal 2026, cost of professional services and other revenue increased due to an increase in labor costs of $15 million offset by a decrease in stock-based compensation of $2 million.
  • Our gross margin for professional services and other revenue remained relatively flat. | Operating Expenses

Fulltext

Dokumentet är delat för att hålla varje sida lätt att hämta. Del 1 · Del 2 · Del 3

okta-20260131 false 0001660134 2026 FY P1Y P3Y 0.0041912 0.33 0.33 0.33 93 184 340 181 181 iso4217:USD xbrli:shares iso4217:USD xbrli:shares okta:segment xbrli:pure okta:tradingDay okta:renewalOption okta:plaintiff okta:vote okta:numberOfIncentivePlan okta:offering_period 0001660134 2025-02-01 2026-01-31 0001660134 2025-07-31 0001660134 us-gaap:CommonClassAMember 2026-02-27 0001660134 us-gaap:CommonClassBMember 2026-02-27 0001660134 2026-01-31 0001660134 2025-01-31 0001660134 us-gaap:CommonClassAMember 2026-01-31 0001660134 us-gaap:CommonClassAMember 2025-01-31 0001660134 us-gaap:CommonClassBMember 2025-01-31 0001660134 us-gaap:CommonClassBMember 2026-01-31 0001660134 us-gaap:SubscriptionAndCirculationMember 2025-02-01 2026-01-31 0001660134 us-gaap:SubscriptionAndCirculationMember 2024-02-01 2025-01-31 0001660134 us-gaap:SubscriptionAndCirculationMember 2023-02-01 2024-01-31 0001660134 us-gaap:TechnologyServiceMember 2025-02-01 2026-01-31 0001660134 us-gaap:TechnologyServiceMember 2024-02-01 2025-01-31 0001660134 us-gaap:TechnologyServiceMember 2023-02-01 2024-01-31 0001660134 2024-02-01 2025-01-31 0001660134 2023-02-01 2024-01-31 0001660134 us-gaap:CommonClassAMember us-gaap:CommonStockMember 2023-01-31 0001660134 us-gaap:CommonClassBMember us-gaap:CommonStockMember 2023-01-31 0001660134 us-gaap:AdditionalPaidInCapitalMember 2023-01-31 0001660134 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2023-01-31 0001660134 us-gaap:RetainedEarningsMember 2023-01-31 0001660134 2023-01-31 0001660134 us-gaap:CommonClassAMember us-gaap:CommonStockMember 2023-02-01 2024-01-31 0001660134 us-gaap:AdditionalPaidInCapitalMember 2023-02-01 2024-01-31 0001660134 us-gaap:CommonClassAMember okta:ConversionOfCommonStockMember us-gaap:CommonStockMember 2023-02-01 2024-01-31 0001660134 us-gaap:CommonClassBMember okta:ConversionOfCommonStockMember us-gaap:CommonStockMember 2023-02-01 2024-01-31 0001660134 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2023-02-01 2024-01-31 0001660134 us-gaap:RetainedEarningsMember 2023-02-01 2024-01-31 0001660134 us-gaap:CommonClassAMember us-gaap:CommonStockMember 2024-01-31 0001660134 us-gaap:CommonClassBMember us-gaap:CommonStockMember 2024-01-31 0001660134 us-gaap:AdditionalPaidInCapitalMember 2024-01-31 0001660134 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2024-01-31 0001660134 us-gaap:RetainedEarningsMember 2024-01-31 0001660134 2024-01-31 0001660134 us-gaap:CommonClassAMember us-gaap:CommonStockMember 2024-02-01 2025-01-31 0001660134 us-gaap:CommonClassBMember us-gaap:CommonStockMember 2024-02-01 2025-01-31 0001660134 us-gaap:AdditionalPaidInCapitalMember 2024-02-01 2025-01-31 0001660134 us-gaap:CommonClassAMember okta:ConversionOfCommonStockMember us-gaap:CommonStockMember 2024-02-01 2025-01-31 0001660134 us-gaap:CommonClassBMember okta:ConversionOfCommonStockMember us-gaap:CommonStockMember 2024-02-01 2025-01-31 0001660134 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2024-02-01 2025-01-31 0001660134 us-gaap:RetainedEarningsMember 2024-02-01 2025-01-31 0001660134 us-gaap:CommonClassAMember us-gaap:CommonStockMember 2025-01-31 0001660134 us-gaap:CommonClassBMember us-gaap:CommonStockMember 2025-01-31 0001660134 us-gaap:AdditionalPaidInCapitalMember 2025-01-31 0001660134 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2025-01-31 0001660134 us-gaap:RetainedEarningsMember 2025-01-31 0001660134 us-gaap:CommonClassAMember us-gaap:CommonStockMember 2025-02-01 2026-01-31 0001660134 us-gaap:CommonClassBMember us-gaap:CommonStockMember 2025-02-01 2026-01-31 0001660134 us-gaap:AdditionalPaidInCapitalMember 2025-02-01 2026-01-31 0001660134 us-gaap:CommonStockMember 2025-02-01 2026-01-31 0001660134 us-gaap:CommonClassAMember okta:ConversionOfCommonStockMember us-gaap:CommonStockMember 2025-02-01 2026-01-31 0001660134 us-gaap:CommonClassBMember okta:ConversionOfCommonStockMember us-gaap:CommonStockMember 2025-02-01 2026-01-31 0001660134 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2025-02-01 2026-01-31 0001660134 us-gaap:RetainedEarningsMember 2025-02-01 2026-01-31 0001660134 us-gaap:CommonClassAMember us-gaap:CommonStockMember 2026-01-31 0001660134 us-gaap:CommonClassBMember us-gaap:CommonStockMember 2026-01-31 0001660134 us-gaap:AdditionalPaidInCapitalMember 2026-01-31 0001660134 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2026-01-31 0001660134 us-gaap:RetainedEarningsMember 2026-01-31 0001660134 srt:MinimumMember 2025-02-01 2026-01-31 0001660134 srt:MaximumMember 2025-02-01 2026-01-31 0001660134 us-gaap:ComputerSoftwareIntangibleAssetMember 2026-01-31 0001660134 srt:MinimumMember us-gaap:RestrictedStockUnitsRSUMember 2025-02-01 2026-01-31 0001660134 srt:MaximumMember us-gaap:RestrictedStockUnitsRSUMember 2025-02-01 2026-01-31 0001660134 us-gaap:FurnitureAndFixturesMember 2026-01-31 0001660134 us-gaap:EmployeeSeveranceMember 2024-01-31 0001660134 us-gaap:EmployeeSeveranceMember 2024-02-01 2025-01-31 0001660134 us-gaap:EmployeeSeveranceMember 2025-01-31 0001660134 us-gaap:EmployeeSeveranceMember 2025-02-01 2026-01-31 0001660134 us-gaap:EmployeeSeveranceMember 2026-01-31 0001660134 us-gaap:MoneyMarketFundsMember us-gaap:FairValueInputsLevel1Member 2026-01-31 0001660134 us-gaap:MoneyMarketFundsMember us-gaap:FairValueInputsLevel1Member 2025-01-31 0001660134 us-gaap:CertificatesOfDepositMember us-gaap:FairValueInputsLevel2Member 2026-01-31 0001660134 us-gaap:CertificatesOfDepositMember us-gaap:FairValueInputsLevel2Member 2025-01-31 0001660134 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel2Member 2026-01-31 0001660134 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel2Member 2025-01-31 0001660134 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel2Member 2026-01-31 0001660134 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueInputsLevel2Member 2025-01-31 0001660134 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueInputsLevel2Member 2026-01-31 0001660134 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueInputsLevel2Member 2025-01-31 0001660134 us-gaap:CertificatesOfDepositMember us-gaap:FairValueInputsLevel2Member 2026-01-31 0001660134 us-gaap:CertificatesOfDepositMember us-gaap:FairValueInputsLevel2Member 2025-01-31 0001660134 us-gaap:DevelopedTechnologyRightsMember 2026-01-31 0001660134 us-gaap:CustomerRelationshipsMember 2026-01-31 0001660134 us-gaap:TradeNamesMember 2026-01-31 0001660134 us-gaap:OtherIntangibleAssetsMember 2026-01-31 0001660134 us-gaap:DevelopedTechnologyRightsMember 2025-01-31 0001660134 us-gaap:CustomerRelationshipsMember 2025-01-31 0001660134 us-gaap:ComputerSoftwareIntangibleAssetMember 2025-01-31 0001660134 us-gaap:TradeNamesMember 2025-01-31 0001660134 us-gaap:OtherIntangibleAssetsMember 2025-01-31 0001660134 us-gaap:DevelopedTechnologyRightsMember 2025-02-01 2026-01-31 0001660134 us-gaap:DevelopedTechnologyRightsMember 2024-02-01 2025-01-31 0001660134 us-gaap:CustomerRelationshipsMember 2025-02-01 2026-01-31 0001660134 us-gaap:CustomerRelationshipsMember 2024-02-01 2025-01-31 0001660134 us-gaap:TradeNamesMember 2025-02-01 2026-01-31 0001660134 us-gaap:TradeNamesMember 2024-02-01 2025-01-31 0001660134 us-gaap:FurnitureAndFixturesMember 2025-01-31 0001660134 us-gaap:LeaseholdImprovementsMember 2026-01-31 0001660134 us-gaap:LeaseholdImprovementsMember 2025-01-31 0001660134 2026-02-01 2026-01-31 0001660134 okta:ConvertibleSeniorNotesDue2025Member us-gaap:SeniorNotesMember 2024-02-01 2025-01-31 0001660134 okta:ConvertibleSeniorNotesDue2026Member us-gaap:SeniorNotesMember 2024-02-01 2025-01-31 0001660134 us-gaap:SeniorNotesMember 2024-02-01 2025-01-31 0001660134 okta:ConvertibleSeniorNotesDue2025Member us-gaap:SeniorNotesMember 2023-02-01 2024-01-31 0001660134 okta:ConvertibleSeniorNotesDue2026Member us-gaap:SeniorNotesMember 2023-02-01 2024-01-31 0001660134 us-gaap:SeniorNotesMember 2023-02-01 2024-01-31 0001660134 okta:ConvertibleSeniorNotesDue2025Member us-gaap:SeniorNotesMember 2025-09-01 2025-09-01 0001660134 okta:ConvertibleSeniorNotesDue2026Member us-gaap:SeniorNotesMember 2026-01-31 0001660134 okta:ConvertibleSeniorNotesDue2026Member us-gaap:SeniorNotesMember 2025-02-01 2026-01-31 0001660134 okta:ConvertibleSeniorNotesDue2026Member 2025-02-01 2026-01-31 0001660134 us-gaap:ConvertibleDebtSecuritiesMember okta:ConvertibleSeniorNotesDue2026Member 2025-02-01 2026-01-31 0001660134 us-gaap:EstimateOfFairValueFairValueDisclosureMember okta:ConvertibleSeniorNotesDue2026Member us-gaap:SeniorNotesMember 2026-01-31 0001660134 okta:SanFranciscoTenYearLeaseMember 2026-01-31 0001660134 us-gaap:LetterOfCreditMember 2026-01-31 0001660134 us-gaap:LetterOfCreditMember 2025-01-31 0001660134 okta:SecuritiesLitigationMember 2024-05-28 2024-05-28 0001660134 okta:DerivativeLawsuitMember 2022-11-28 2022-12-13 0001660134 okta:DerivativeLawsuitMember 2025-01-10 2025-01-10 0001660134 us-gaap:CommonClassAMember 2025-02-01 2026-01-31 0001660134 us-gaap:CommonClassBMember 2025-02-01 2026-01-31 0001660134 okta:StockOptionsAndRestrictedStockUnitsMember 2026-01-31 0001660134 us-gaap:EmployeeStockMember 2026-01-31 0001660134 okta:A2017EquityIncentivePlanMember us-gaap:CommonClassAMember 2026-01-31 0001660134 okta:A2017EquityIncentivePlanMember us-gaap:CommonClassBMember 2026-01-31 0001660134 us-gaap:EmployeeStockOptionMember 2025-02-01 2026-01-31 0001660134 us-gaap:EmployeeStockOptionMember 2024-02-01 2025-01-31 0001660134 us-gaap:EmployeeStockOptionMember 2023-02-01 2024-01-31 0001660134 us-gaap:RestrictedStockUnitsRSUMember 2025-02-01 2026-01-31 0001660134 us-gaap:RestrictedStockUnitsRSUMember 2024-02-01 2025-01-31 0001660134 us-gaap:RestrictedStockUnitsRSUMember 2023-02-01 2024-01-31 0001660134 okta:MarketBasedRSUsMember 2025-02-01 2026-01-31 0001660134 okta:MarketBasedRSUsMember 2024-02-01 2025-01-31 0001660134 okta:MarketBasedRSUsMember 2023-02-01 2024-01-31 0001660134 us-gaap:EmployeeStockMember 2025-02-01 2026-01-31 0001660134 us-gaap:EmployeeStockMember 2024-02-01 2025-01-31 0001660134 us-gaap:EmployeeStockMember 2023-02-01 2024-01-31 0001660134 us-gaap:RestrictedStockMember 2025-02-01 2026-01-31 0001660134 us-gaap:RestrictedStockMember 2024-02-01 2025-01-31 0001660134 us-gaap:RestrictedStockMember 2023-02-01 2024-01-31 0001660134 okta:CostofServicesLicensesandServicesMember 2025-02-01 2026-01-31 0001660134 okta:CostofServicesLicensesandServicesMember 2024-02-01 2025-01-31 0001660134 okta:CostofServicesLicensesandServicesMember 2023-02-01 2024-01-31 0001660134 okta:TechnologyServicesCostsMember 2025-02-01 2026-01-31 0001660134 okta:TechnologyServicesCostsMember 2024-02-01 2025-01-31 0001660134 okta:TechnologyServicesCostsMember 2023-02-01 2024-01-31 0001660134 us-gaap:ResearchAndDevelopmentExpenseMember 2025-02-01 2026-01-31 0001660134 us-gaap:ResearchAndDevelopmentExpenseMember 2024-02-01 2025-01-31 0001660134 us-gaap:ResearchAndDevelopmentExpenseMember 2023-02-01 2024-01-31 0001660134 us-gaap:SellingAndMarketingExpenseMember 2025-02-01 2026-01-31 0001660134 us-gaap:SellingAndMarketingExpenseMember 2024-02-01 2025-01-31 0001660134 us-gaap:SellingAndMarketingExpenseMember 2023-02-01 2024-01-31 0001660134 us-gaap:GeneralAndAdministrativeExpenseMember 2025-02-01 2026-01-31 0001660134 us-gaap:GeneralAndAdministrativeExpenseMember 2024-02-01 2025-01-31 0001660134 us-gaap:GeneralAndAdministrativeExpenseMember 2023-02-01 2024-01-31 0001660134 us-gaap:EmployeeStockOptionMember us-gaap:ShareBasedCompensationAwardTrancheOneMember 2025-02-01 2026-01-31 0001660134 us-gaap:RestrictedStockUnitsRSUMember 2025-01-31 0001660134 us-gaap:RestrictedStockUnitsRSUMember 2026-01-31 0001660134 okta:MarketBasedRSUsMember 2025-01-31 0001660134 okta:MarketBasedRSUsMember 2026-01-31 0001660134 srt:MinimumMember okta:MarketBasedRSUsMember 2024-03-01 2024-03-31 0001660134 srt:MinimumMember okta:MarketBasedRSUsMember 2023-03-01 2023-03-31 0001660134 srt:MinimumMember okta:MarketBasedRSUsMember 2025-03-01 2025-03-31 0001660134 srt:MaximumMember okta:MarketBasedRSUsMember 2025-03-01 2025-03-31 0001660134 srt:MaximumMember okta:MarketBasedRSUsMember 2024-03-01 2024-03-31 0001660134 srt:MaximumMember okta:MarketBasedRSUsMember 2023-03-01 2023-03-31 0001660134 okta:SperaCybersecurityMember us-gaap:RestrictedStockMember 2026-01-31 0001660134 okta:SperaCybersecurityMember us-gaap:RestrictedStockMember 2025-02-01 2026-01-31 0001660134 srt:MinimumMember us-gaap:EmployeeStockMember 2025-02-01 2026-01-31 0001660134 srt:MaximumMember us-gaap:EmployeeStockMember 2025-02-01 2026-01-31 0001660134 srt:MinimumMember us-gaap:EmployeeStockMember 2024-02-01 2025-01-31 0001660134 srt:MaximumMember us-gaap:EmployeeStockMember 2024-02-01 2025-01-31 0001660134 srt:MinimumMember us-gaap:EmployeeStockMember 2023-02-01 2024-01-31 0001660134 srt:MaximumMember us-gaap:EmployeeStockMember 2023-02-01 2024-01-31 0001660134 us-gaap:EmployeeStockMember 2025-01-31 0001660134 okta:MarketBasedRSUsMember us-gaap:ShareBasedCompensationAwardTrancheOneMember 2025-02-01 2026-01-31 0001660134 okta:MarketBasedRSUsMember us-gaap:ShareBasedCompensationAwardTrancheTwoMember 2025-02-01 2026-01-31 0001660134 okta:MarketBasedRSUsMember us-gaap:ShareBasedCompensationAwardTrancheThreeMember 2025-02-01 2026-01-31 0001660134 country:AU 2025-02-01 2026-01-31 0001660134 country:GB 2025-02-01 2026-01-31 0001660134 us-gaap:ForeignTaxJurisdictionOtherMember 2025-02-01 2026-01-31 0001660134 us-gaap:DomesticCountryMember 2026-01-31 0001660134 us-gaap:StateAndLocalJurisdictionMember 2026-01-31 0001660134 country:GB 2026-01-31 0001660134 country:IL 2026-01-31 0001660134 us-gaap:DomesticCountryMember us-gaap:ResearchMember 2026-01-31 0001660134 us-gaap:StateAndLocalJurisdictionMember us-gaap:ResearchMember 2026-01-31 0001660134 stpr:NY 2025-02-01 2026-01-31 0001660134 us-gaap:StateAndLocalTaxJurisdictionOtherMember 2025-02-01 2026-01-31 0001660134 country:IN 2025-02-01 2026-01-31 0001660134 country:IL 2025-02-01 2026-01-31 0001660134 country:JP 2025-02-01 2026-01-31 0001660134 us-gaap:CommonClassAMember 2024-02-01 2025-01-31 0001660134 us-gaap:CommonClassBMember 2024-02-01 2025-01-31 0001660134 us-gaap:CommonClassAMember 2023-02-01 2024-01-31 0001660134 us-gaap:CommonClassBMember 2023-02-01 2024-01-31 0001660134 us-gaap:StockCompensationPlanMember 2025-02-01 2026-01-31 0001660134 us-gaap:StockCompensationPlanMember 2024-02-01 2025-01-31 0001660134 us-gaap:StockCompensationPlanMember 2023-02-01 2024-01-31 0001660134 us-gaap:ConvertibleDebtSecuritiesMember 2025-02-01 2026-01-31 0001660134 us-gaap:ConvertibleDebtSecuritiesMember 2024-02-01 2025-01-31 0001660134 us-gaap:ConvertibleDebtSecuritiesMember 2023-02-01 2024-01-31 0001660134 country:US 2025-02-01 2026-01-31 0001660134 country:US 2024-02-01 2025-01-31 0001660134 country:US 2023-02-01 2024-01-31 0001660134 us-gaap:NonUsMember 2025-02-01 2026-01-31 0001660134 us-gaap:NonUsMember 2024-02-01 2025-01-31 0001660134 us-gaap:NonUsMember 2023-02-01 2024-01-31 0001660134 country:US 2026-01-31 0001660134 country:US 2025-01-31 0001660134 us-gaap:NonUsMember 2026-01-31 0001660134 us-gaap:NonUsMember 2025-01-31 0001660134 okta:AxiomSecurityLtdMember 2025-09-04 2025-09-04 0001660134 okta:AxiomSecurityLtdMember us-gaap:DevelopedTechnologyRightsMember 2025-09-04 2025-09-04 0001660134 okta:AxiomSecurityLtdMember 2025-09-04 0001660134 2025-11-01 2026-01-31 0001660134 okta:ShellyeArchambeauMember 2025-11-01 2026-01-31 0001660134 okta:ShellyeArchambeauMember 2026-01-31 0001660134 okta:JonAddisonMember 2025-11-01 2026-01-31 0001660134 okta:MichaelStankeyMember 2025-11-01 2026-01-31 0001660134 okta:MichaelStankeyMember 2026-01-31 0001660134 okta:BrettTigheMember 2025-11-01 2026-01-31 0001660134 okta:BrettTigheMember 2026-01-31 0001660134 okta:DavidSchellhaseMember 2025-11-01 2026-01-31 0001660134 okta:DavidSchellhaseMember 2026-01-31 0001660134 okta:JonAddisonMember 2026-01-31

UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549

FORM 10-K

(Mark One)

☒ ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the fiscal year ended January 31 , 2026
or

☐ TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the transition period from               to             
Commission File Number: 001-38044

Okta, Inc.
(Exact name of Registrant as specified in its charter)

Delaware
100 First Street, Suite 600
26-4175727

(State or Other Jurisdiction of
Incorporation or Organization)
San Francisco
(I.R.S. Employer
Identification Number)

California

94105

(Address of Principal executive offices)

Registrant’s telephone number, including area code: ( 888 ) 722-7871
___________________________________________________
Securities registered pursuant to Section 12(b) of the Act:
(Title of each class) Trading Symbol(s) (Name of each exchange on which registered)
Class A common stock, par value $0.0001 per share
OKTA
The Nasdaq Stock Market LLC

Securities registered pursuant to Section 12(g) of the Act: None
___________________________________________________
Indicate by check mark if the Registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes   ☒   No  ☐
Indicate by check mark if the Registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes  ☐   No    ☒
Indicate by check mark whether the Registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the Registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes    ☒     No   ☐
Indicate by check mark whether the Registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the Registrant was required to submit such files). Yes    ☒     No   ☐
Indicate by check mark whether the Registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
Large Accelerated Filer
☒
Accelerated filer ☐

Non-accelerated filer ☐
Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the Registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the Registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the Registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the Registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐
Indicate by check mark whether the Registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes   ☐ No   ☒
The aggregate market value of the stock of the Registrant as of July 31, 2025 (based on a closing price of $97.80 per share) held by non-affiliates was approximately $ 16.4 billion. As of February 27, 2026, there were 169,200,461 shares of the Registrant’s Class A Common Stock and 7,687,471 shares of the Registrant's Class B Common Stock outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of the registrant's definitive Proxy Statement relating to the 2026 Annual Meeting of Stockholders are incorporated herein by reference in Part III of this Annual Report on Form 10-K to the extent stated herein. Such Proxy Statement will be filed with the Securities and Exchange Commission within 120 days of the registrant's fiscal year ended January 31, 2026.

Okta, Inc.
Form 10-K
For the Fiscal Year Ended January 31, 2026
TABLE OF CONTENTS
Page
Part I
Item 1.
Business
4

Item 1A.
Risk Factors
15

Item 1B.
Unresolved Staff Comments
40

Item 1C.
Cybersecurity
40

Item 2.
Properties
42

Item 3.
Legal Proceedings
42

Item 4.
Mine Safety Disclosures
42

Part II
Item 5.
Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
43

Item 6.
[Reserved]
44

Item 7.
Management’s Discussion and Analysis of Financial Condition and Results of Operations
45

Item 7A.
Quantitative and Qualitative Disclosures About Market Risk
59

Item 8.
Financial Statements and Supplementary Data
60

Item 9.
Changes in and Disagreements with Accountants on Accounting and Financial Disclosure
96

Item 9A.
Controls and Procedures
96

Item 9B.
Other Information
97

Item 9C.
Disclosure Regarding Foreign Jurisdictions that Prevent Inspections
97

Part III
Item 10.
Directors, Executive Officers and Corporate Governance
98

Item 11.
Executive Compensation
98

Item 12.
Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters
98

Item 13.
Certain Relationships and Related Transactions, and Director Independence
98

Item 14.
Principal Accountant Fees and Services
98

Part IV
Item 15.
Exhibits and Financial Statement Schedules
98

Item 16.
Form 10-K Summary
98

Special Note Regarding Forward-Looking Statements 
This Annual Report on Form 10-K contains “forward-looking statements” within the meaning of the “safe harbor” provisions of the Private Securities Litigation Reform Act of 1995. Words such as “expect,” “anticipate,” “should,” “believe,” “hope,” “target,” “project,” “goals,” “estimate,” “potential,” “predict,” “may,” “will,” “might,” “could,” “intend,” “shall” and similar expressions are intended to identify these forward-looking statements, although not all forward-looking statements include these identifying words.
Forward-looking statements contained in this Annual Report on Form 10-K include, but are not limited to, statements about:
• our future financial performance, including our revenue, costs of revenue, gross profits, margins and operating expenses;
• trends in our key business metrics;
• the impact of general economic, business and market conditions, including economic downturns or recessions, market volatility, geopolitical events, inflation and interest rates, and foreign currency fluctuations;
• our ability to retain and sell additional solutions to existing customers;
• our growth strategy and ability to compete;
• our ability to keep pace with technological change and evolving industry standards;
• our ability to adequately fund research and development, and introduce new solutions, enhance existing solutions and address new use cases;
• the sufficiency of our cash and cash equivalents, investments and cash provided by sales of our solutions to meet our liquidity needs;
• our ability to effectively sustain or manage our revenue growth and profitability;
• our ability to partner with third-party software vendors and system integrators;
• our ability to expand our international business operations and product sales;
• our ability to adequately fund research and development, and introduce new solutions, enhance existing solutions and address new use cases;
• our ability to successfully expand our existing marketing and sales capabilities, including further specializing our go-to-market organization;
• our ability to expand our product sales by promoting our brand and engaging channel partners;
• potential impacts of cybersecurity incidents to our reputation, customer relations and financial results;
• our ability to detect, minimize or prevent security breaches to our internal systems and our platforms;
• our ability to maintain the security and service performance of our and our third-party service providers’ systems or data, or our customers’ data;
• our ability of our solutions to effectively integrate with third-party systems and technologies;
• our ability to maintain and protect our proprietary rights and intellectual property;
• our ability to comply with modified or new laws, regulations and industry standards;
• our intent to pay off our convertible senior notes at maturity;
• our ability to release the valuation allowance on our deferred tax assets in the United States;
• the attraction and retention of qualified employees and key personnel;
• the impact of recent accounting pronouncements on our financial statements; and
• our ability to successfully defend litigation or other claims brought against us.
These forward-looking statements are made as of the date they were first issued and are based on current expectations and assumptions that are subject to a number of risks and uncertainties, which could cause our actual results to differ materially from those anticipated or implied by any forward-looking statements. Factors that could cause or contribute to such differences include, but not limited to, those discussed in “Risk Factors” and “Management’s Discussion and Analysis of Financial Condition and Result of Operations” in this Annual Report on Form 10-K, as well as other documents that may be filed by us from time to time with the Securities and Exchange Commission (“SEC”). We undertake no obligation to revise or publicly release the results of any revision to these forward-looking statements, except as required by law. Given these risks and uncertainties, readers are cautioned not to place undue reliance on such forward-looking statements.

Part I

Item 1. Business
Overview
We are the leading independent identity partner. Our vision is to free everyone to safely use any technology, and we believe identity is the key to making that happen. Our purpose is to bring simple and secure digital access to people and organizations everywhere. Our Okta Platform and Auth0 Platform enable our customers to securely connect the right people to the right technologies and services at the right time.
Identity is becoming the most critical layer of an organization’s security. The acceleration of digital transformation, cloud adoption and the evolving security threat landscape continue to drive a shift in how organizations securely manage the identity of their employees, contractors and partners. As organizations shift from network-based security models to a Zero Trust security model focused on adaptive and context-aware controls, identity has become the most reliable way to manage user access and protect digital assets.
In addition to these established drivers, the emergence of artificial intelligence (“AI”) and the deployment of AI agents may, over time, create new opportunities for identity management. We see a potential long-term opportunity for our platforms to serve as a unified, independent control plane for non-human identities (“NHIs”) and AI agents, a distinct class of identity that requires authenticated, secure access to sensitive resources at a scale and speed exceeding traditional security models designed for human users. While adoption is in its early stages, we believe the inherent challenges of governing NHIs and agentic identities may drive increased demand for our solutions as these technologies and customer adoption continue to mature.
Our platforms help organizations effectively harness the power of cloud, mobile, web, and AI technologies by securing and governing users and connecting them with the applications and technology they need. Every day, thousands of organizations and millions of people use our platforms to securely access a wide range of cloud, mobile, web and Software-as-a-Service (“SaaS”) applications, on-premises servers, application programming interfaces (“APIs”), IT infrastructure providers, and services from a multitude of devices. For IT and security leaders, the Okta Platform governs the seamless and secure access by human users and NHIs to the applications they need to do their most important work. We are expanding these capabilities to include AI agents with the introduction of new product offerings currently in development and early access. Developers leverage our Okta Platform and Auth0 Platform to securely and efficiently embed identity for both human users and, increasingly, AI agents into the software they build, allowing them to innovate and focus on their core mission. Our approach to customer identity provides organizations with the scale, interoperability, extensibility and security they need to secure and scale agentic and traditional applications from pilot to production with seamless and private experiences that serve a wide variety of users, from customers to citizens. As we add new customers, users, developers and integrations to our platforms, our business, customers, partners and users benefit from powerful network effects that increase the value and security of our solutions.
As of January 31, 2026, more than 20,000 customers across nearly every industry used our solutions to secure and manage identities around the world. These customers consist of leading global organizations ranging from the largest enterprises to small- and medium-sized businesses, universities, nonprofits and government agencies. We partner with a broad range of application, IT infrastructure and security vendors through our Okta Integration Network. As of January 31, 2026, we had over 7,000 integrations with these cloud, mobile and web applications, and IT infrastructure and security vendors.
We employ a SaaS business model and generate revenue primarily by selling multi-year subscriptions to our cloud-based offerings. We focus on attracting and retaining our customers by building on and increasing the value we provide to them over time. This commitment to our customers’ success helps drive increased customer investment in the number of users of our Okta Platform and Auth0 Platform and adoption of our additional product offerings. We sell our product offerings directly through our field and inside sales teams, as well as indirectly through our network of channel partners, including cloud marketplaces, resellers, system integrators, and other distribution partners.
Our Platforms
We offer independent and neutral cloud-based identity solutions that allow our customers to integrate with nearly any application, service or cloud that they choose through our secure, reliable, and scalable platforms. Our technological neutrality allows our customers to adopt the best technologies easily, and our two platforms are
4

designed to securely connect users to the technology that they choose. We prioritize the compatibility of our platforms with public clouds, on-premises infrastructures and hybrid clouds. Our platforms are traditionally used by organizations in two distinct ways: “workforce identity”, supported by our Okta Platform, to manage and secure employees, contractors and partners; and “customer identity”, supported by both our Okta Platform and Auth0 Platform, to secure customers.
We are extending our platforms to address the unique identity security challenges posed by AI agents. Okta for AI Agents, currently available in early access, provides governance and visibility for AI agents through the Okta Platform. Auth0 for AI Agents enables developers to leverage the Auth0 Platform to secure and scale agentic applications from pilot to production. Cross App Access, currently available in early access, is the interoperability standard that allows these AI agents to securely interact across third-party ecosystems, including through an extension to the emerging Model Context Protocol (“MCP”) standard.
Okta Platform
The Okta Platform governs and simplifies the way an organization’s employees, contractors, partners and NHIs connect to applications and data from any device. It serves as the central system for an organization’s governance, access management, authentication, connectivity and identity lifecycle management needs. We are expanding these capabilities to include AI agents with the introduction of new product offerings currently in development and early access. We enable our customers to easily deploy and secure their environments with a simple, intuitive, consumer-like user experience. For IT and security leaders, the Okta Platform acts as a single control plane, enabling the enforcement of contextual access management decisions based on user identity, device health and real-time threat signals. These features, combined with our technological neutrality, help our customers future-proof their environments.
We deliver the capabilities of the Okta Platform by providing:
• Adaptive Access and Authentication : Enables simple, secure access using continuous risk and policy evaluations to automate the identification and remediation of threats.
• Automated Governance and Lifecycle Management : Automates identity lifecycle management processes while providing the visibility required to govern users.
• Unified Security Posture : Proactively identifies vulnerabilities and security gaps by providing consolidated visibility into identity posture.
For a detailed description of our specific product offerings within the Okta Platform, see “Our Product Offerings—Okta Platform Product Offerings” below.
Auth0 Platform
The Auth0 Platform is developer-centric and enables companies, nonprofits and governmental agencies to rapidly embed secure, extensible identity management into customer- and citizen-facing cloud, mobile, and web applications. It primarily supports consumer and SaaS applications. The Auth0 Platform empowers application builders to innovate faster by removing the complexity from identity and making it simple, extensible and customizable.
We deliver these capabilities through a flexible architecture that provides:
• Developer Empowerment and Innovation : We provide software development kits, comprehensive APIs, and extensive developer tools that empower teams to easily authenticate, manage, and secure their applications. These tools enable organizations to streamline user experiences and improve security, leading to increased customer acquisition, retention and loyalty.
• Agentic Application Development : Through Auth0 for AI Agents, we provide tools that enable developers to integrate generative AI and AI agents into their applications while mitigating risks such as static credential sprawl, including hardcoded API keys and machine-to-machine secrets, and unauthorized data access.
• Advanced Identity Security : We support sophisticated identity security capabilities, including bot detection, fraud prevention, Adaptive Multi-Factor Authentication (“MFA”), and account takeover protection. The Auth0 Platform also supports sophisticated authorization models, such as Fine Grained Authorization
5

(“FGA”), which helps developers build the secure, relationship-based access required for AI agents to interact safely with enterprise data and third-party ecosystems.
For a detailed description of our specific product offerings within the Auth0 Platform, see “Our Product Offerings—Auth0 Platform Product Offerings” below.
Growth Strategy
Key elements of our growth strategy are to:
Execute with Our Platforms
• Deepen Relationships within Our Existing Customer Base . We strive to further increase revenue from our existing customers by cross-selling and up-selling additional and new product offerings. We also believe we can expand our footprint by focusing on current customers that have deployed our Okta Platform and expanding those customers’ use of our Auth0 Platform, or vice versa. In addition, we believe there is a potential opportunity to offer existing customers our solutions to manage and secure NHIs and AI agents.
• Drive Growth with Large Customers . To increase our market share, we intend to focus on growing our base of large customers using a land-and-expand sales model, with a focus on key markets by size of customers, as well as key verticals, including highly regulated sectors.
• Leverage Partner Ecosystem . We plan to further leverage the sales efforts of global system integrators, managed service providers, technology partners and other distribution partners for growth, scale and specialized expertise. Our Okta Elevate Partner Program is designed to incentivize partners to deliver and manage our solutions.
• Expand Our International Footprint . With 20% of our revenue generated outside of the United States in fiscal 2026, we believe there is a significant opportunity to continue to grow our international business. We believe global demand for our product offerings will continue to be a long-term opportunity as organizations outside the United States embrace the transition to cloud computing and develop and adopt AI agents, and larger international organizations take advantage of technology consolidation within their global locations.
Increase Our Opportunities
• Innovate and Extend Our Platforms with New Products . We intend to continue making significant investments in research and development, hiring top technical talent and maintaining an agile organization. By continuing to innovate, introduce new product offerings and extend our platforms, we believe that we can offer increasing value to our existing and potential customers. For example, recent investments have led to the development of Okta for AI Agents, Auth0 for AI Agents and the Cross App Access extension to MCP.
• Extend Our Accessible Market with New Use Cases . As technology and our customers’ needs evolve, we plan to use our platforms to help our customers address new challenges, regulatory requirements and use cases.
• Go-To-Market Specialization . At the start of fiscal 2026, we further specialized our go-to-market organization to better meet the needs of the distinct buying centers. Okta sellers focus engagement on IT and security buyer needs, including all workforce identity products and Okta Customer Identity. Auth0 sellers focus on meeting the unique needs of developers, which include highly technical customer identity customizations and flexible development models.
• Leverage Our Integrations . The Okta Integration Network is an extensive ecosystem, which includes over 7,000 integrations with cloud, mobile and web applications as well as integrated solutions with IT infrastructure providers and security vendors. We continue to add new integrations as we expand the surface area of the Okta Platform. Investing in these partnerships allows us to broaden and deepen our existing integrations while adding new ones, helping us build and promote complementary capabilities that benefit our customers.
• Expand Our Developer Ecosystem . We want to empower every application developer to use our platforms to securely integrate identity into any application. We believe that our platforms enable developers to focus their time and attention on innovating within their core application capabilities while relying on our
6

platforms for their identity-related requirements, leading to more secure and convenient experiences for their own customers.
• Leverage Our Unique Data Assets with Powerful Analytics . Our position at the intersection of people, devices, applications and infrastructure gives us unique access to powerful identity threat intelligence data, and the opportunity to provide differentiated insights based on that data, as well as predictive capabilities based on that data to help keep customers more secure. We expect the value of our analytics to our customer base will increase as customers continue to connect more devices, applications and users to their networks and as we add more customers. We also expect that our analytics ability will enable our customers to use their data and third-party data from our partners, allowing customers to make more informed and secure access decisions. We do not currently derive direct revenue from our unique data assets, but we may explore opportunities for monetization in the future.
• Mergers and Acquisitions and Investments . From time to time, we evaluate opportunities to acquire or invest in emerging and adjacent technologies to complement our organic investments and improve our product offerings, services and customers’ experiences. We will continue to use these types of strategic levers as opportunities arise.
Our Product Offerings
Our portfolio of product offerings and services is designed to manage and secure identity for people, NHIs and, increasingly, AI agents. Our product offerings are designed to be versatile, with most offerings applicable to both customer and workforce identity use cases. Workforce identity solutions are primarily consumed through web and mobile interfaces, providing IT organizations with simple ways to manage access for employees, contractors, partners, NHIs and, through product offerings in early access and development, AI agents. For customer identity, developers leverage our APIs and software development kits to embed identity functionality into their own traditional and agentic applications. We continuously enhance our Okta Platform and Auth0 Platform through the regular release of new product offerings, features, and services.
Okta Platform Product Offerings
Access Management
• Single Sign-on . Enables secure access to cloud and on-premises applications from any device with a single entry of their user credentials. We use modern protocols and a consumer-like user experience, including Okta FastPass for a passwordless login across all major operating systems.
• Adaptive MFA . Provides an intelligent, risk-based layer of security for an organization’s cloud, mobile and web applications built on contextual data. It leverages data intelligence from across the Okta Platform network of thousands of organizations, as well as from our partner ecosystem, to automate threat identification and prompt for additional verification only when risk signals exceed defined thresholds.
• API Access Management . Enables organizations to secure APIs as systems connect to each other. By managing access at the user level, it allows organizations to centrally maintain one set of permissions for any employee, partner or customer across every point of access. API Access Management reduces development time, boosts security, helps achieve compliance, and enables seamless end-user experiences by providing a unified portable service for authorizing secure and always available access to any API.
• Access Gateway . Extends the Okta Platform from the cloud to organizations’ existing on-premises applications so that organizations can harness the benefits of the platform to manage all of their critical systems, whether in the cloud, on-premises or hybrid. Extending the benefits of the Okta Platform to hybrid IT environments delivers a single point of management for our customers’ administrators and a single location from which end users can access their critical applications.
• Okta Device Access . Extends the Okta Platform’s secure access management to the device login experience. Okta Device Access enables end users to securely log in to their devices with their Okta Platform credentials and meet MFA challenges from a set of strong factors, helping organizations to harden their security posture by protecting a user’s device with the same experience that the Okta Platform provides for applications and resources.
7

• Universal Directory . Provides a centralized, cloud-based system of record to store and secure user, application and device profiles for an organization. It serves as the foundational directory for organizations’ authentication and lifecycle management by storing and securing user profiles.
Security
• Identity Threat Protection . Delivers native identity intelligence from the Okta Platform and signals from third-party tools integrated into an organization’s security stack. The Okta Platform’s AI-driven continuous risk and policy evaluations deliver real-time identity threat assessment and automated remediation.
• Identity Security Posture Management (“ISPM”) . Helps organizations fortify their security measures and safeguard their digital assets with greater efficiency. ISPM highlights critical identity security issues like admin sprawl, MFA bypass, and local accounts, and prioritizes them based on risk severity for effective remediation.
• Okta for AI Agents . Gives customers the ability to discover, register, authenticate, govern and manage their AI Agents through a unified identity control plane within the Okta Platform. Currently available in early access.
Identity Governance and Administration (“IGA”)
• Lifecycle Management . Enables IT organizations to manage a user’s identity throughout its lifecycle, from onboarding to offboarding. It automates IT processes and ensures user accounts are created and deactivated at the appropriate times, including the workflow and policies needed to power those processes, and helps ensure compliance requirements are met as user roles evolve and access levels change.
• Okta Workflows . Helps IT teams build identity-related business processes with minimal or no code tools, such as automating user onboarding and provisioning, creating just-in-time authorization for software development and IT processes, automating identity-centric security responses and orchestrating customer data across backend systems.
• Okta Identity Governance . Provides a unified identity access management and identity governance solution focused on improving an organization’s security and compliance posture, helping customers to mitigate everyday security risks and improving IT efficiency. Includes governance capabilities relating to access requests, access certifications and access reporting. It simplifies and automates the process of requesting and approving access to applications and resources.
• Cross App Access (“XAA”) . A standards-based protocol designed to centralize the governance of AI agents and app-to-app connections. By shifting authorization decisions from individual applications to the Okta Platform, XAA allows IT teams to manage delegated access at scale while preserving the user’s identity and authorization context even as AI agents access multiple applications across different trust domains. XAA capabilities and configuration features are currently available in early access.
Privileged Access Management
• Advanced Server Access . Offers continuous, contextual access management to secure cloud infrastructure. Organizations can continuously manage and secure access to on-premises Windows and Linux servers and across leading Infrastructure-as-a-Service vendors, including AWS, Google Cloud Platform and Microsoft Azure. Enables centralize access controls in a seamless manner to better mitigate the risk of credential theft, reuse, sprawl and abandoned administrative accounts.
• Okta Privileged Access . Helps organizations reduce risk with unified access and governance management for on-premises and cloud privileged resources and NHIs, providing better visibility, compliance and security for critical applications, resources and infrastructure requiring privileged access.
Auth0 Platform Product Offerings
• Universal Login . A standards-based login infrastructure that provides a centralized, consistent login experience across many different applications and devices. It supports extensive customization and can be integrated with social media login credential providers, enterprise login services and customer-provided databases.
8

• Attack Protection Suite . A set of security capabilities designed to protect our customers from different types of malicious traffic, including bots, breached passwords, suspicious IP addresses and brute force attacks. It works to minimize risks associated with the ever-growing volume of identity-targeted attacks.
• Adaptive MFA . Simple-to-use and adaptable MFA that minimizes friction to end users. When using Adaptive MFA, our customers leverage risk-assessment algorithms that present MFA challenges only to select authentication attempts that require additional validation.
• Passwordless . Enables users to login without a password and supports a variety of different login methods, including advanced device biometrics such as passkeys.
• Machine-to-Machine Tokens . Provides standards-based authentication and authorization with NHIs, such as non-interactive devices and applications.
• Private Cloud . A deployment option that allows our customers to run a dedicated cloud instance of the Auth0 Platform. Our Private Cloud capability supports multiple cloud providers.
• Organizations . Enables our customers to support a large number of partners or customers of their own with independent configurations, login experiences and security options.
• Extensibility . A suite of products—including Actions, Forms, Event Streams and the Auth0 Marketplace—that enables customers to build customized identity flows using no-code to pro-code tools, extending beyond the out-of-the-box experience.
• Enterprise Connections . Enables Enterprise Federation using pre-built integrations with commonly used enterprise identity systems.
• Fine Grained Authorization . Allows developers to manage complex authorization scenarios efficiently, and reduces latency and downtime as their systems and user bases grow.
• Auth0 for AI Agents . Enables developers to leverage the Auth0 Platform to secure and scale agentic applications from pilot to production.
Through our broad and deep product offerings that support a wide range of workforce and customer identity use cases, we deliver multiple critical business outcomes for our customers. These include boosting their cybersecurity posture, reducing IT spending, addressing regulations, reducing fraud, increasing new customer conversions, creating frictionless customer experiences and helping technical teams deliver products to market faster.
Our Technology
We focus on engineering an intuitive and comprehensive platform to solve complex identity management and security challenges. Our cloud architecture is multi-tenant, encrypted and third-party validated. Our service also allows us to integrate into our customers’ on-premises components and hybrid configurations.
Differentiated Administration, User and Developer Experience
The Okta Platform and Auth0 Platform offer administrators and users a consistent, easy-to-use, consumer-like experience across our product offerings. Our technology integrates with industry-leading browsers and mobile applications to provide seamless access to nearly any web or native mobile application. We also heavily leverage operating system management and security technologies across desktops, laptops and mobile devices to provide a transparent, yet secure experience for users across a range of devices. These integrations allow us to seamlessly deliver identity, access, security and management use cases that previously required significant custom development to achieve.
Robust Security
Security is essential for us and for our customers. Our approach to security spans day-to-day operational practices, from the design and development of our software to how customer data is segmented and secured within our multi-tenant platform. The Okta Platform and its features are updated regularly, and along with continuous security testing, there are periodic security reviews that provide audited and verifiable security checkpoints to ensure the quality of our source code. A number of our Okta Platform product offerings have attained multiple certifications, including SOC 2 Type II Attestations, CSA Star Level 2 Certification, ISO/IEC 27001:2022, ISO/IEC
9

27017:2015, ISO/IEC 27018:2019 and comply with many other international security frameworks. Certain Okta Platform offerings maintain multiple agency Federal Risk and Authorization Management Program (“FedRAMP”) Authorities to Operate and are compliant to operate at Department of Defense Impact Level 4. Certain Okta Platform offerings maintain minimum security requirements in alignment with the Security Rule of the Health Insurance Portability and Accountability Act (“HIPAA”). The Okta Platform also supports FIPS 140-2 encryption requirements.
Additional information regarding our cybersecurity risk management strategy and governance is included in “ Cybersecurity ” under Part I, Item 1C of this Annual Report on Form 10-K. For additional information regarding the cybersecurity risks that we face, see “ Risk Factors ” included under Part I, Item 1A of this Annual Report on Form 10-K.
Scalability and Uptime
Our technical operations and engineering models are designed around the concept of an always-on, highly redundant and available platform that we seek to upgrade without customer disruption. Our product offerings and architecture were built entirely in and for the cloud with availability, resiliency and scalability at the center of the design. We have zero planned downtime, including during our maintenance windows.
Our proprietary architecture includes redundant, active-active-active availability zones with cross-continental disaster recovery regions, real-time database replication and geo-distributed storage. If one of our systems goes down, another is quickly promoted. Our architecture is designed to scale both vertically by increasing the size of the application tiers and horizontally by adding new geo-distributed cells.
The Okta Platform and Auth0 Platform are monitored not only at the infrastructure level, but also at the application and third-party integration level. Synthetic transaction monitoring allows our technical operations team to detect and resolve issues proactively.
Okta Integration Network and Auth0 Marketplace
The Okta Integration Network contains over 7,000 integrations with cloud, mobile and web applications, IoT devices and IT infrastructure providers, including AWS, Atlassian, DocuSign, Google, Microsoft 365, NetSuite, Oracle, Palo Alto Networks, Proofpoint, Salesforce, SAP, ServiceNow, Slack, Splunk, VMware, Workday, Zendesk and Zoom. Our patented technology allows our customers to seamlessly connect to any application or type of device that is already integrated into our network. In addition, customers can extend the benefits of the Okta Integration Network by creating their own integrations to both cloud and on-premises proprietary applications.
Similarly, the Auth0 Marketplace is a trusted catalog of integrations that enables application teams to easily assemble complete identity solutions. The Auth0 Marketplace connects customers with service providers and builders who solve integration use cases and implement integrations with the Auth0 Platform.
Commitment to Open Standards
We lead and contribute to several standards initiatives, including the Interoperability Profile for Secure Identity in the Enterprise (“IPSIE”) standard, which standardizes identity security functions like risk signal sharing and session termination across the SaaS ecosystem; XAA, which shifts authorization decisions from individual applications to an organization’s identity provider; and MCP, which we have extended with XAA capabilities. We believe these efforts support an open ecosystem that enables customer choice, interoperability and an improved security posture for the industry.
Our Customers
As of January 31, 2026, we had more than 20,000 customers, including 5,100 customers with an annual contract value greater than $100,000. Our customers span nearly all industry verticals and range from small organizations with fewer than 100 employees to companies in the Fortune 50, with up to hundreds of thousands of employees, some of which use our platforms to manage millions of their customers’ identities.
10

Sales and Marketing
Sales
We sell directly to customers through our direct inside and field sales force and also indirectly through our extensive ecosystem of channel partners. We also offer a self-service approach for developers to sign up for free trials, free plans, paid developer plans of our Auth0 Platform, which may transition to paid enterprise plans that include more fulsome offerings. We often leverage our expansion sales model to generate incremental revenue, often within the term of the initial agreement, through the addition of new users and the sale of additional product offerings. In many instances, we find that initial customer success with our platforms results in key internal decision-makers expanding their deployments, for example, from workforce identity to customer identity needs, or vice-versa. Furthermore, as our customers are successful in their businesses and increase headcount, the number of their customers or their monthly active users, we have the opportunity to share in their growth as the number of identities that we manage increases. Conversely, if our customers reduce the size of their workforce, then the number of identities that we manage, and therefore our revenue may potentially decrease.
Our sales organization operates under a unified leadership team and is structured to address the specific needs of our target markets. It is divided by geography and customer size, and in some cases by industry vertical. Our global go-to-market specialization strategy is intended to better align our sales team with the distinct needs of IT security buyers and application developers. We also employ other forms of specialization in our sales team when appropriate, such as our “hunter-farmer” sales model for certain regions and segments. Our direct sales force is supported by our sales engineers, security team, cloud architects, professional services team and other technical resources.
We benefit from an expansive partner ecosystem that helps drive additional sales. Nearly all of the leading cloud application providers are our partners, and many of them drive further customer acquisition for us through co-selling arrangements, building our offerings directly into their products and product demonstrations running on our technology. We also partner with several of the large technology companies that are driving the movement to the cloud. In addition to these technology partners, we leverage our channel partners, including system integrators, traditional value-added resellers (“VARs”) and Government VARs, to broaden the range of customers we reach.
Marketing
Our most valuable marketing features our customers and their successes and is informed by a deeply data-driven approach, giving us insights into the efficacy of our efforts. Our marketing efforts focus on promoting our industry-leading product lines, establishing our brand, generating awareness, creating sales leads and cultivating the Okta Community.
A centerpiece of our marketing strategy is our annual customer conference, Oktane, which features customers sharing their success stories, new product and feature announcements and hands-on product labs. We also host a number of other events where we engage with both existing customers and new prospects, as well as deliver product training.
Research and Development
Our research and development organization is responsible for the design, architecture, creation and quality of our platforms. The research and development organization also works closely with our technical operations team to ensure the successful deployment and monitoring of our platforms. We use test automation and application monitoring to support high availability and minimize service disruptions.
Customer Support and Professional Services
Our product offerings are designed for ease of use and fast deployments. As part of our customer-first strategy, we are focused on customer success and offer several programs to help our customers maximize their success with our product offerings. These programs leverage the expertise and best practices that we have built while helping thousands of customers adopt and deploy our product offerings.
Customer Support and Training Services
We offer three tiers of support, each of which builds upon the previous tier. We provide 24/7 support for the highest support tiers as well as access to Customer Success and Technical Account Managers. We also provide on-
11

demand access to a robust online digital community and customer success hub, where our customers can find answers to common use cases, information about product features, and interact with our experts and industry peers.
Professional Services
Our professional services team provides assistance to customers in the deployment of our Okta Platform and Auth0 Platform and includes identity and security experts, customized deployment plans, SmartStart, which provides a quick path to implementation, and Okta Expert Assist, in which we provide our customers with recommendations and best practices designed to improve their security posture.
Okta Community
We have created the Okta Community, an online community available to all of our customers that enables them to connect with other customers and partners to ask questions and find answers.
Intellectual Property
We protect our intellectual property through a combination of trademarks, domain names, copyrights, trade secrets and patents, as well as contractual provisions and restrictions on access to our proprietary technology.
As of January 31, 2026, we had 100 issued patents in the United States and 85 issued patents granted outside of the United States that expire between 2030 and 2044 and cover various aspects of our product offerings.
We have registered “Okta” and “Auth0” as trademarks in many jurisdictions throughout the world to protect our brands. We also have filed other trademark applications pending in various jurisdictions throughout the world. We also have registered other trademarks in the United States including “The World’s Identity Company” and “Oktane.”
We are the registered holder of a variety of domestic and international domain names that include “Okta,” “Auth0” and similar variations.
In addition to the protection provided by our intellectual property rights, we enter into confidentiality and proprietary rights or similar agreements with our employees, consultants and contractors. Our employees, consultants and contractors are also subject to invention assignment agreements. We further control the use of our proprietary technology and intellectual property through provisions in both general and product-specific terms of use.
Additional information regarding certain risks related to our intellectual property is included in “ Risk Factors ” under Part I, Item 1A of this Annual Report on Form 10-K.
Our Competitors
The markets for our product offerings are rapidly evolving, highly competitive and subject to shifting customer needs and frequent introductions of new competing technologies. As the markets in which we operate continue to mature and new technologies and competitors enter those markets, we expect competition to intensify. Our competitor categories include:
• Authentication providers;
• Identity governance providers;
• Multi-factor authentication providers;
• Infrastructure-as-a-service providers;
• Other customer identity and access management providers; and
• Solutions developed in-house by our potential customers.
We compete with both cloud-based and on-premises enterprise application software providers. We also compete against open-source technologies that customers can use to build their own identity solutions. Our competitors vary in size and in the breadth and scope of the products and services offered. However, certain of our
12

competitors have substantial competitive advantages, such as significantly greater financial, technical, sales and marketing, distribution, customer support or other resources, longer operating histories, greater resources to make strategic acquisitions, and greater name recognition than we have. Our principal competitor is Microsoft.
Due to the flexibility and breadth of our platforms, we can and often do co-exist alongside our competitors’ products within our customer base.
Principal competitive factors in our markets include flexibility, independence, product capabilities, total cost of ownership, time to value, scalability, user experience, number of pre-built integrations, customer satisfaction, global reach and ease of integration, management and use. We believe our product strategy, platform architecture, technology and independence as well as our company culture allow us to compete favorably on each of these factors.
We expect competition to increase as other established and emerging companies enter our markets, as customer requirements evolve, and as new products and technologies are introduced. We expect this to be particularly true as we are a cloud-based offering, and our competitors may also seek to acquire new offerings or repurpose their existing offerings to provide identity management solutions with subscription models. The ongoing trend of merger and acquisition activity in the technology industry, particularly transactions involving security or identity and access management technologies, may result in an environment where we increasingly compete with other large technology companies in the future in both the workforce identity and customer identity markets.
Additional information regarding our competition is included in “ Risk Factors ” under Part I, Item 1A of this Annual Report on Form 10-K.
Human Capital Resources
Our core values—love our customers, always secure and always on, build and own it, and drive what’s next—inform and guide our human capital initiatives and objectives. In order to continue to innovate and drive customer success, it is crucial that we continue to attract, develop and retain exceptional talent. To that end, we strive to make our workplace one in which employees feel like they have opportunities to grow and develop in their careers. We support our employees with fair and competitive compensation, benefits and wellness programs, and initiatives that foster connections between and among our employees and their communities.
As of January 31, 2026, we had 6,366 employees, of which approximately 56% were in the United States and 44% were in our international locations. We have not experienced any work stoppages, and we consider our relations with our employees to be good. Our employee engagement program helps us understand employee sentiment on a wide range of topics throughout the employee lifecycle, providing insights that inform our decisions about company initiatives, employee programs, talent risks, management opportunities and more. In fiscal 2026, 86% of our eligible employees participated in our annual employee engagement survey.
Builder and Owner Culture
“Build and own it” is one of our core values. Our goal is to create a shared sense of ownership in achieving our company vision where career growth, competitive rewards, and purpose empower our employees to do great work. We want every employee to feel ownership of Okta.
Growth and Development
We invest significant resources to develop talent and actively foster a learning culture where employees are empowered to drive their personal and professional growth. We provide our employees with a wide range of learning and development opportunities, including in-person, virtual, social and self-directed learning, mentoring, coaching and external development. Our extensive onboarding and training programs prepare our employees at all levels for career progression and individual development. Our employee onboarding program helps our new hires get off to the right start, our manager development program helps to build a solid foundation for our people managers, and our technical training program brings our new technical employees up to speed on our product offerings.
Compensation, Benefits and Wellness
We provide robust compensation, benefits and wellness programs that help support the varying needs of our employees. In addition to market-competitive base pay, short-term bonus incentives and long-term equity
13

incentives, our total rewards program offers comprehensive employee benefits that may vary by country or region, including an employee stock purchase plan, a 401(k) plan in the United States with company matching contributions, comprehensive medical, dental and vision insurance, life and disability insurance, health savings accounts, charitable donation matching, flexible time off, volunteer time off, gender-neutral paid parental leave, fertility and adoption support, family care resources, mobile and internet reimbursement, mental health and lifestyle support programs and a variety of other health and wellness resources.
We are committed to fair compensation and opportunity in our workplace. We conduct regular equal pay assessments to attempt to promote pay equity among all of our employees.
Community and Social Impact
The mission of our social impact arm, Okta for Good, is to build a safely connected world where everyone can belong and thrive. We mobilize our people, products and financial resources in service of our communities.
Our employees are passionate about many causes and Okta for Good connects them with numerous giving and volunteering opportunities in service of our communities. We believe this fosters a more meaningful, fulfilling and enjoyable workplace. In addition, through Okta for Good we donate and discount access to our service for non-profit organizations. These organizations use Okta to make their teams more efficient and secure, allowing them to focus on their important missions. We also engage in philanthropic grantmaking via the Okta for Good Fund, a donor-advised fund held at Tides Foundation.
We fund and support the operations of Okta for Good. Okta for Good is a part of our company and not a separate legal entity. Additional information can be found on the “Okta for Good” page of our website at www.okta.com.
Financial Information
The financial information required under this Item 1 is incorporated herein by reference to “ Financial Statements and Supplementary Data ” included in Part II, Item 8 of this Annual Report on Form 10-K. For financial information regarding our business, see “ Management’s Discussion and Analysis of Financial Condition and Results of Operations ” included in Part II, Item 7 of this Annual Report on Form 10-K and our consolidated audited financial statements and related notes included elsewhere in this Annual Report on Form 10-K.
Corporate Information
We incorporated in 2009 as Saasure Inc., a California corporation. In 2010, we reincorporated as Okta, Inc., a Delaware corporation. Our principal executive offices are located at 100 First Street, Suite 600, San Francisco, California 94105, and our telephone number is (888) 722-7871. Our website address is www.okta.com.
Additional Information
Our investor relations website address is investor.okta.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and Proxy Statements for our annual meetings of stockholders, including any exhibits and amendments to these filings, are available, free of charge, on our investor relations website after we file or furnish them with the SEC, and they are available on the SEC’s website at www.sec.gov.
We webcast our earnings calls and certain events we participate in or host with members of the investment community on our investor relations website. Supplemental financial and other information can be accessed through our investor relations website. We also use our investor.okta.com website and okta.com/blog websites (including the Security Blog, Okta Developer Blog and Auth0 Developer Blog) as a means of disclosing material non-public information, announcing upcoming investor conferences and complying with our disclosure obligations under Regulation FD. Accordingly, you should monitor our investor relations and okta.com/blog websites in addition to following our press releases, SEC filings and public conference calls and webcasts. Further corporate governance information, including our corporate governance guidelines and code of conduct, is also available on our investor relations website under the heading “Responsibility and Governance.” Information contained on, or that can be accessed through, our websites is not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only.
14

Item 1A. Risk Factors
A description of the risks and uncertainties associated with our business is set forth below. You should carefully consider the risks and uncertainties described below, as well as the other information in this Annual Report on Form 10-K, including our consolidated financial statements and the related notes and “Management’s Discussion and Analysis of Financial Condition and Results of Operations.” The occurrence of any of the events or developments described below, or of additional risks and uncertainties not presently known to us or that we currently deem immaterial, could materially and adversely affect our business, results of operations, financial condition and growth prospects. In such an event, the market price of our Class A common stock could decline, and you could lose all or part of your investment.
Risk Factor Summary
This risk factor summary contains a high-level summary of risks associated with our business. It does not contain all of the information that may be important to you, and you should read this risk factor summary together with the more detailed discussion of risks and uncertainties set forth following this summary. A summary of our risks includes, but is not limited to, the following:
• Adverse general economic, market and industry conditions and reductions in workforce identity and customer identity spending have, in the past and may, in the future, reduce demand for our solutions, which could harm our revenue, results of operations and cash flows.
• Our business depends on our ability to retain existing customers, and our revenues and results of operations could be adversely impacted if they do not renew their subscriptions or purchase additional licenses or subscriptions with us.
• If we are unable to grow our customer base, our revenue growth and profitability could be harmed.
• We face intense competition, especially from larger, well-established companies, and we may lack sufficient financial or other resources to maintain or improve our competitive position.
• We may experience quarterly fluctuations in our results of operations due to a number of factors that make our future results difficult to predict and could cause our results of operations to fall below analyst or investor expectations.
• Interruptions or performance problems that impact the functionality of our technology, systems or infrastructure could result in delays in the deployment of our platforms.
• In the past, we have experienced cybersecurity incidents that allowed unauthorized access to our systems or data or our customers’ data, harmed our reputation, created additional liability and adversely impacted our financial results. We and our third-party service providers may experience similar incidents in the future which may also include disabling access to our service.
• Any actual or perceived failure by us, our third-party service providers or our customers to comply with new or existing laws, regulations or other requirements relating to the privacy, security and processing of personal information could adversely affect our business, results of operations or financial condition.
• If we are unable to ensure that our solutions integrate or interoperate with a variety of operating systems, platforms, services, software applications devices, mobile phones and other hardware form factors that are developed by others, our platforms may become less competitive and our results of operations may be harmed.
• Real or perceived errors, failures, vulnerabilities or bugs in our solutions, including deployment complexity, have in the past and could, in the future, harm our business and results of operations.
• Issues with our use, development, adoption, deployment and maintenance of AI and machine learning technologies, combined with an uncertain regulatory environment, may result in reputational harm, liability or other adverse consequences to our business operations.
• Because we generally recognize revenue from our subscriptions and support services over the term of the relevant service period, a decrease in sales during a reporting period may not be immediately reflected in our results of operations for that period.
15

• The stock price of our Class A common stock may be volatile or may decline.
• The dual class structure of our common stock has the effect of concentrating voting control with those stockholders who held our capital stock prior to the completion of our IPO, including our directors, executive officers, and their affiliates, who held in the aggregate 32% of the voting power of our capital stock as of January 31, 2026. This will limit or preclude your ability to influence corporate matters, including the election of directors, amendments of our organizational documents, and any merger, consolidation, sale of all or substantially all of our assets or other major corporate transaction requiring stockholder approval.
• Transactions relating to our convertible notes may affect the value of our Class A common stock.
• We depend on our executive officers and other key employees, and the loss of one or more of these employees or an inability to attract and retain other highly skilled employees could harm our business.
Risks Related to Our Business and Industry
Adverse general economic, market and industry conditions and reductions in workforce identity and customer identity spending have, in the past and may, in the future, reduce demand for our solutions, which could harm our revenue, results of operations and cash flows.
Our revenue, results of operations and cash flows depend on the overall demand for our solutions. International and regional economic conditions, including instability or security concerns abroad, such as widespread downturns and recessions; geopolitical events; changes in trade policies, trade restrictions, economic sanctions or the threat of such actions; the instability of financial institutions; the availability and cost of credit; fluctuations in the inflation and interest rate environment; health epidemics; or energy costs have and could continue to lead to increased market volatility, decreased consumer confidence and diminished growth expectations in the U.S. economy and abroad, which in turn could result in reductions in spending on our platforms by our existing and prospective customers. These economic conditions can occur abruptly. Prolonged economic slowdowns may result in customers requesting us to renegotiate existing contracts on less advantageous terms to us than those currently in place or defaulting on payments due on existing contracts or not renewing at the end of the contract term. To the extent there is a sustained general economic downturn, and our platforms and services are perceived by customers or potential customers as costly, or too difficult to deploy or migrate to, our revenue may be disproportionately affected by delays or reductions in spending.
Our business depends on our ability to retain existing customers, and our revenues and results of operations could be adversely impacted if they do not renew their subscriptions or purchase additional licenses or subscriptions with us.
Our ability to increase and maintain revenue growth depends, in part, on our ability to retain and expand our commercial relationships with our existing customers. This requires that our existing customers continue to use our platforms, either by purchasing additional subscriptions or by renewing their subscriptions when existing contract terms expire. Our customers have no obligation to renew their subscriptions after the expiration of their subscription period. They may decide not to renew their subscriptions with a similar contract period, at the same prices and terms or with the same or a greater number of users. In the past, some of our customers have elected not to renew their agreements with us, and it is difficult to accurately predict long-term customer retention and expansion rates. Customer retention and expansion has, in the past and may, in the future, decline or fluctuate as a result of a number of factors, such as customers’ satisfaction with our solutions; our prices and pricing plans, including as compared to those of competing software solutions; unfavorable macroeconomic and geopolitical conditions; reductions in customer spending levels; negative sentiment stemming from cybersecurity incidents; customer utilization rates; new offerings; and changes to the packaging of our product offerings. If existing customers do not purchase additional subscriptions or renew their subscriptions, renew on less favorable terms or fail to add more users, our revenue may decline or grow less quickly than anticipated, which would harm our future results of operations.
If we are unable to grow our customer base, our revenue growth and profitability could be harmed.
We aim to increase our revenue and achieve and maintain profitability by growing our customer base, particularly through sales to larger organizations. As our market matures and product offerings evolve, we believe that competitors will introduce lower cost or differentiated solutions that compete, or are perceived to compete, with our solutions. If prospective customers view the cost or features of competitors’ solutions as preferable to ours, or do not perceive our solutions to be of sufficiently high value and quality, we could fail to attract the number and
16

types of new customers we are seeking. Prospective customers’ decisions to purchase our solutions depends on a variety of other factors, including those specified under the risk factor titled “ Our business depends on our ability to retain existing customers, and our revenues and results of operations could be adversely impacted if they do not renew their subscriptions or purchase additional licenses or subscriptions with us ,” and described elsewhere in these risk factors. Any failure to attract new customers could impede our success in selling new subscriptions and adversely impact our business, financial condition and results of operations.
We face intense competition, especially from larger, well-established companies, and we may lack sufficient financial or other resources to maintain or improve our competitive position.
The markets for our solutions are rapidly evolving, highly competitive and subject to shifting customer needs and frequent introductions of new technologies. As the markets in which we operate continue to mature and new technologies and competitors enter such markets, we expect competition to intensify. We compete with both cloud-based and on-premise enterprise application software providers including, but not limited to: authentication providers; identity governance providers; multi-factor authentication providers; infrastructure-as-a-service providers; other customer identity and access management providers; and solutions developed in-house by our potential customers. Our principal competitor is Microsoft.
Many of our competitors have significantly greater financial, technical, sales and marketing, distribution, customer support or other resources, larger intellectual property portfolios, longer operating histories, greater resources to make strategic acquisitions, more established relationships with third-party service providers and greater name recognition than we do. They may also have a larger customer base, many of which may prefer to purchase from the same competitor rather than replace their existing infrastructure with our solutions.
Some of our larger competitors have substantially broader product offerings, or greater resources to acquire new offerings or repurpose existing offerings to provide identity solutions with subscription models. As a result, they can leverage their relationships based on other solutions, or incorporate functionality into existing solutions, to gain business in a manner that discourages users from purchasing our solutions, including selling at zero or negative margins, bundling products or maintaining closed technology platforms. In addition, larger competitors, as well as new start-up companies that innovate, make significant investments in research and development and may invent similar or superior solutions that compete with our solutions. It is also possible that products and services developed by others, including, but not limited to, new technologies and offerings integrating AI, or products and services developed by competitors, could put us at a competitive disadvantage. These competitive pressures or our failure to compete effectively may result in price reductions, fewer orders, reduced revenue and gross margins, increased net losses and loss of market share, which could harm our business, results of operations and financial condition.
If we fail to adapt to rapid technological change, our ability to remain competitive could be impaired.
The industry in which we compete is characterized by rapid technological change, frequent introductions of new solutions and evolving industry standards. Our ability to attract new customers and increase revenue from existing customers will depend in significant part on our ability to anticipate industry standards and trends. We must continue to enhance existing solutions or introduce or acquire new solutions on a timely basis to keep pace with technological developments. The success of any enhancement or new solution depends on several factors, including the timely completion and market acceptance of the enhancement or new solution. Any new solution we develop or acquire might not be introduced in a timely or cost-effective manner and might not achieve the broad market acceptance necessary to generate significant revenue. If any of our competitors implements new technologies before we are able to implement them, those competitors may be able to provide more effective solutions than ours at lower prices. Any delay or failure in the introduction of new or enhanced solutions that gain market acceptance and meet customer requirements could harm our business, results of operations and financial condition.
Our ability to introduce new solutions is dependent on adequate research and development resources and, in part, on our ability to successfully complete acquisitions. If we do not adequately fund our research and development efforts or complete acquisitions successfully, we may not be able to compete effectively and our business and results of operations may be harmed.
To remain competitive, we must continue to develop new solutions, applications and enhancements to our existing portfolio. This is particularly true as we further expand and diversify our capabilities. Maintaining adequate research and development resources, such as the appropriate personnel and development technology, to meet the demands of the market is essential. If we elect not to or are unable to develop solutions internally, we may choose to expand into a certain market or strategy via an acquisition for which we could potentially pay too much or fail to
17

successfully integrate into our operations. Further, many of our competitors expend a considerably greater amount of funds on their respective research and development programs, and those that do not have, in some cases, been acquired by larger companies that allocate greater resources to our competitors’ research and development programs. Our failure to maintain adequate research and development resources or to compete effectively with the research and development programs of our competitors would give an advantage to such competitors and may harm our business, results of operations and financial condition.
Even if we maintain adequate research and development resources, we may be unable to monetize newly developed solutions or features such that we can recoup our research and development expenditures. For example, if we develop a new feature but our competitors give an equivalent feature away for free, we may need to also include our newly developed feature for free as part of an existing product offering to remain competitive in the marketplace. Such a loss of anticipated revenue to offset our research and development expenditures may harm our business, results of operations and financial condition.
We may experience quarterly fluctuations in our results of operations due to a number of factors that make our future results difficult to predict and could cause our results of operations to fall below analyst or investor expectations.
Our results of operations fluctuate from quarter to quarter as a result of a number of factors, many of which are outside of our control and may be difficult to predict, including, but not limited to:
• fluctuations in demand for, or pricing of, our platforms, including as a result of macroeconomic conditions or competition;
• our ability to retain and increase sales to existing customers, attract new customers or otherwise increase the use of our platforms;
• the timing and success of introductions of new solutions by us or our competitors, or any other change in the competitive landscape of our market;
• security breaches of, technical difficulties with, or interruptions to, the delivery and use of our solutions, and any negative market perception or customer reactions related to, or arising from the disclosure of, such breaches, difficulties or interruptions;
• seasonal buying patterns for IT spending;
• the mix of revenue attributable to larger transactions as opposed to smaller transactions, and the associated volatility and timing of our transactions;
• changes in remaining performance obligations due to seasonality, the timing of and compounding effects of renewals, invoice duration, size and timing, new business linearity between quarters and within a quarter, average contract term or fluctuations due to foreign currency movements, all of which may impact implied growth rates;
• errors in our forecasting of the demand for our solutions, which could lead to lower revenue, increased costs or both;
• increases in and timing of sales and marketing and other operating expenses that we may incur to grow our brand, expand our operations and remain competitive;
• our ability to comply with applicable laws and requirements, including data privacy and cybersecurity regimes;
• costs related to the acquisition of businesses, talent, technologies or intellectual property, including potentially significant amortization costs and possible write-downs;
• credit or other difficulties confronting our third-party service providers, including channel partners;
• costs related to litigation, including adverse judgments, settlements and other disputes;
• the impact of new accounting pronouncements and associated system implementations;
• changes in the legislative or regulatory environment;
18

• fluctuations in foreign currency exchange rates;
• expenses related to real estate, including our office leases and other fixed expenses;
• changes in government spending and budgetary priorities, workforce reduction and other policy shifts;
• general economic, market and industry conditions in domestic or international markets, including the inflation and interest rate environment, geopolitical uncertainty and instability; and
• changes in trade policies, trade restrictions or the threat of such actions.
Any one or more of the factors above may result in significant fluctuations in our results of operations. You should not rely on our past results as an indicator of our future performance.
The variability and unpredictability of our quarterly results of operations or other operating metrics could result in our failure to meet our expectations or those of analysts that cover us or investors with respect to revenue or other metrics for a particular period. If we fail to meet or exceed such expectations for these or any other reasons, the market price of our Class A common stock could fall substantially, and we could face costly lawsuits, including securities class action suits.
Our prior revenue growth rates may not be indicative of our future growth or performance.
Our revenue growth depends on several factors, including pricing our platforms to attract new and retain existing customers; managing demand for our solutions; competing against larger companies and new market entrants; capitalizing on new acquisitions, technologies or growth opportunities; and other conditions described in these risk factors. If we are unable to grow our revenue, it will be difficult to maintain our profitability, or maintain or increase our cash flow on a consistent basis. We expect our operating expenses to increase in future periods as we continue to expand our business. If our revenue growth does not increase to offset these anticipated increases in our operating expenses, our business, financial position and results of operations will be harmed, and we may not be able to consistently maintain profitability.
Our growth depends, in part, on the success of our strategic relationships with third parties.
To grow our business, we expect to continue to depend on relationships with third parties, such as channel partners. Identifying partners, negotiating and maintaining relationships with them requires significant time and resources.
Our ability to compete in the marketplace depends, in part, on whether third parties successfully market, resell, implement or support our solutions for their customers. For example, some of our channel partners sell or provide integration and administration services for our competitors’ solutions. They may choose to devote greater resources to our competitors that are more effective in incentivizing them to favor their solutions over ours. In addition, acquisitions of such partners by our competitors could result in a decrease in the number of our current and potential customers, as these partners may no longer facilitate the adoption of our applications by potential customers. Some of our partners compete with certain of our solutions and may elect to no longer integrate with our platforms or sell our solutions.
Our growth also depends on our ability to incentivize third-party developers to adopt and build their applications using our APIs and solutions. We believe that these applications facilitate greater usage and customization of our solutions. If these third-party developers stop developing on or supporting our platforms, we will lose the benefit of network effects that have contributed to the growth in our number of customers.
If we are unsuccessful in establishing or maintaining our relationships with third parties, our ability to grow our revenue could be impaired, and our results of operations may suffer. Even if we are successful, we cannot ensure that these relationships will result in increased customer usage of our applications or increased revenue.
19

Because our long-term success depends, in part, on our ability to expand the sales of our solutions to customers located outside of the United States, our business will be susceptible to risks associated with international operations.
We currently have sales personnel outside the United States and maintain offices outside the United States in the Americas, Asia-Pacific and Europe, and our international revenue was 21% and 20% of our total revenue in fiscal 2025 and fiscal 2026, respectively. Any international expansion efforts that we may undertake may not be successful. We may face challenges, including those not generally faced in the United States, such as managing and staffing international operations, and becoming familiar with varying technology standards, local laws and business practices. Conducting international operations also subjects us to, among other risks described in these risk factors:
• general political, economic and social uncertainties, including macroeconomic and geopolitical conditions and financial market conditions;
• unexpected changes in, or costs and liabilities related to, compliance with foreign legal and regulatory requirements, such as data privacy and cybersecurity regimes; intellectual property rights protections; and requirements relating to the localization of our solutions;
• restrictive governmental actions focusing on cross-border trade, including taxes, changes in trade policies, trade restrictions, import and export restrictions or quotas, barriers, sanctions, custom duties or the threat of such actions; and
• difficulties in managing systems integrators and technology partners.
Establishing operations in international markets also requires significant management attention and financial resources and we cannot guarantee that these investments will produce desired levels of revenue or profitability. If we fail to expand our operations successfully and in a timely manner, our business and results of operations will suffer.
Future acquisitions, investments, partnerships or alliances could be difficult to identify and integrate, divert the attention of management personnel, disrupt our business, dilute stockholder value and harm our results of operations and financial condition.
We have in the past acquired and we may, in the future, seek to acquire or invest in, businesses, products, teams or technologies that we believe could complement or expand our current platforms, enhance our technical capabilities or otherwise offer growth opportunities. The pursuit of potential acquisitions may divert the attention of management and cause us to incur various expenses in identifying, investigating and pursuing suitable acquisitions, whether or not they are consummated. If we acquire additional businesses, we may not be able to successfully integrate and retain the acquired personnel; integrate the acquired operations and technologies; adequately test and assimilate the internal control processes of the acquired business in accordance with the requirements of Section 404 of the Sarbanes-Oxley Act of 2002 (the “Sarbanes-Oxley Act”); or effectively manage the combined business. We may also be required to assume liabilities or incur unforeseen costs, such as those arising from the acquired company’s failure to comply with legal or regulatory requirements and litigation matters.
Any acquisition or strategic transaction we do consummate could fail to produce the benefits we hope to achieve, which could disrupt our own business or those of our partners and customers or result in future impairment charges. In particular, from time to time we invest in private growth stage companies for strategic reasons and to support key business initiatives. All of our venture investments are subject to a risk of partial or total loss of investment capital, and we may not realize a return on these investments.
In addition, we have limited experience in acquiring other businesses. We may not be able to identify desirable acquisition targets, or we may not be successful in entering into an agreement with any particular target. Acquisitions could also result in dilutive issuances of equity securities, use of our available cash or the incurrence of debt, or in adverse tax consequences or unfavorable accounting treatment. If an acquired business fails to meet our expectations, our business, results of operations and financial condition could suffer.
Our financial results may fluctuate due to increasing variability in our sales cycles.
We plan our expenses based on certain assumptions about the length and variability of our sales cycle. These assumptions are based upon historical trends for sales cycles and conversion rates associated with our existing customers. We are increasingly focused on sales to larger organizations, which often involve lengthy
20

purchasing approval processes and less predictable sales cycles. The length of sales cycles may be further impacted by the current macroeconomic and geopolitical environment and by the discretionary nature of customer spending. Customers may also take prolonged evaluation periods of our platforms, or their features or functionality, as well as those of our competitors. As a result, it is difficult to predict exactly when, or even if, we will make a sale. If we are unable to close one or more of expected significant transactions in a particular period, or if such an expected transaction is delayed until a subsequent period, our results of operations for that period and for any future periods in which revenue from such transaction would otherwise have been recognized, may be harmed.
Various factors may cause implementation of our solutions to be delayed, inefficient or otherwise unsuccessful.
Our business depends upon the successful implementation of our solutions by our customers. Increasingly, we, as well as our customers, rely on our network of partners to deliver implementation services, and there may not be enough qualified implementation partners available to meet customer demand. Various other factors may cause implementations to be delayed, inefficient or otherwise unsuccessful, including significant costs to purchase, implement and enable our solutions; changes in our customers’ functional requirements; timeline delays; or deviation from recommended best practices. These and other circumstances may delay our ability to sell additional solutions or result in customers canceling or failing to renew their subscriptions before our solutions have been fully implemented. Unsuccessful, lengthy or costly customer implementation and integration projects could result in claims from customers, harm to our reputation and opportunities for competitors to displace our solutions, each of which could have an adverse effect on our business and results of operations.
A portion of our revenues are generated by sales to public sector entities, which are subject to a number of challenges and risks.
We rely on partners to resell our services to public sector entities, and we have made and plan to continue to make investments to support future sales opportunities in the public sector. The sale of our services to public sector entities is tied to budget cycles and there are government requirements and authorizations that we may be required to meet. Changes in fiscal or contracting policies or reductions in government spending or workforce could adversely affect the funding for and purchases of our platforms and, in turn, could negatively impact our revenue and future growth. Further, we may be subject to audits and investigations regarding our role as a subcontractor in government contracts, and violations could result in penalties and sanctions, including contract termination, refunding or forfeiting payments, fines and suspension or debarment from future government business. Selling to these entities can be highly competitive, expensive and time consuming, often requiring significant upfront time and expense. Public sector entities often require contract terms that differ from our standard arrangements and impose additional compliance requirements, require increased attention to pricing practices or are otherwise time consuming and expensive to satisfy. For example, some of our public sector customers contract with us on the basis of our authorization under FedRAMP, which requires us to undertake additional actions and expenses to ensure compliance. Public sector entities may also have statutory, contractual or other legal rights to terminate contracts with our partners for convenience, for lack of funding or due to a default, and any such termination may adversely impact our future results of operations. If we represent that we meet certain standards, authorizations (such as FedRAMP) or requirements and do not meet them, or if such authorizations are suspended or revoked, we could be subject to increased liability from our customers, investigation by regulators or termination rights. Even if we do meet them, the additional costs associated with providing our service to public sector entities could harm our margins. Moreover, changes in underlying regulatory requirements could be an impediment to our ability to efficiently provide our service to government customers and to grow or maintain our customer base. Any of these risks related to contracting with, or as a subcontractor supporting, public sector entities could adversely impact our future sales and results of operations or make them more difficult to predict.
If we fail to enhance our brand cost-effectively, our ability to expand our customer base will be impaired and our business, results of operations and financial condition may suffer.
We believe that developing and maintaining awareness of our brand in a cost-effective manner is critical to achieving widespread acceptance of our existing and future solutions, and is an important element in attracting new customers and retaining existing customers. Furthermore, we believe that the importance of brand recognition is likely to increase as competition in our market increases. Successful promotion of our brand will depend largely on the effectiveness of our marketing and sales efforts and on our ability to provide reliable and useful solutions at competitive prices and that align with our customers’ needs. In the past, our efforts to build our brand have involved significant expenses and have not always attracted a sufficient number of new customers to be cost-effective.
21

In February 2025, we began further specializing our sales force to better align with our customers and evolving market demands, which has required us to invest significant financial and other resources. We may not achieve anticipated revenue growth if we are unable to hire and develop talented sales personnel or retain our existing sales personnel, or if our new sales personnel are unable to achieve desired productivity levels in a reasonable period of time. If our marketing and sales efforts are unsuccessful and we fail to enhance our brand we may fail to attract new customers or retain our existing customers to the extent necessary to realize a sufficient return on our brand-building efforts. As a result, our business, results of operations and financial condition could suffer.
We may not set optimal prices for our solutions.
In the past, we have at times adjusted our prices either for individual customers in connection with long-term agreements or for a particular solution. We expect that we may need to change our pricing in future periods and potentially in response to increased costs, including as a result of the inflation and interest rate environment, geopolitical considerations, as well as changes in trade policies, trade restrictions or the threat of such actions. Further, as competitors introduce new solutions that compete with ours, or if they reduce their prices or adopt preferable pricing models for evolving technologies, such as AI agents, we may be unable to attract new customers or retain existing customers based on our historical pricing. As we further expand internationally and into additional verticals, we also must determine the appropriate price to enable us to compete effectively. In addition, if our mix of solutions sold changes, then we may need to, or choose to, revise our pricing. As a result, we may be required or choose to reduce our prices or change our pricing model, which could harm our business, results of operations and financial condition.
If we are not able to consistently generate cash flows or raise additional capital necessary to expand our operations and invest in new technologies in the future could reduce our ability to compete successfully and harm our results of operations.
We may need to raise additional funds, and we may not be able to obtain additional debt or equity financing on favorable terms, if at all. If we raise additional equity or convertible debt financing, our security holders may experience significant dilution of their ownership interests. If we engage in additional debt financing, we may be required to accept terms that restrict our ability to incur additional indebtedness, force us to maintain specified liquidity or other ratios or restrict our ability to pay dividends or make acquisitions. If we need additional capital and cannot raise it on acceptable terms or at all, we may not be able to effectively grow our business or respond to competitive pressures, which could harm our business, results of operations and financial condition.
We may be subject to liability claims if we breach our contracts and our insurance may be inadequate to cover our losses.
We are subject to numerous obligations in our contracts with our customers and partners. Despite the procedures, systems and internal controls we have implemented to comply with our contracts, we may breach these commitments, whether through a weakness in these procedures, systems and internal controls, negligence or the willful act of an employee or contractor. Our insurance policies, including our errors and omissions insurance, may be inadequate to compensate us for the potentially significant losses that may result from claims arising from breaches of our contracts, disruptions in our service, including those caused by cybersecurity incidents, failures or disruptions to our infrastructure, catastrophic events and disasters or otherwise. In addition, such insurance may not be available to us in the future on economically reasonable terms or at all. Further, our insurance may not cover all claims made against us and defending a suit, regardless of its merit, could be costly and divert management’s attention.
Evolving and complex scrutiny of sustainability matters may require us to incur additional costs or otherwise adversely impact our reputation or business.
Investors, regulators, customers and other stakeholders, both in the United States and internationally, are increasingly attentive to, and have evolving expectations about, sustainability and social issues, initiatives and disclosures. We have undertaken certain sustainability-related initiatives, goals and commitments, which we have communicated on our website, in our SEC filings and elsewhere, and may undertake additional actions in the future. These actions, including establishing certain sustainability goals or targets to respond to stakeholder demands or requirements, may result in increased costs (including, but not limited to, increased costs related to compliance, stakeholder engagement and meeting our contractual commitments). Our ability to perform or carry out such actions may be subject to numerous conditions that are outside our control, and we cannot guarantee that any actions or
22

outcomes will have the desired effect. Our actual or perceived failure to achieve such goals or targets could negatively impact our reputation and otherwise affect our business performance.
Risks Related to Intellectual Property, Infrastructure Technology, Data Privacy and Security
Interruptions or performance problems that impact the functionality of our technology, systems or infrastructure could result in delays in the deployment of our platforms.
Our continued growth depends, in part, on the ability of our existing and potential customers to access our platforms 24 hours a day, seven days a week, without interruption or degradation of performance. System interruption and a lack of integration and redundancy in our information systems and infrastructure may adversely affect our ability to operate websites, process and fulfill transactions, respond to customer inquiries and generally maintain cost-efficient operations. We have experienced in the past and may experience in the future, disruptions, data loss or corruption, outages and other performance problems with our infrastructure or service due to a variety of factors. These factors include, for example, infrastructure and functionality changes, human or software errors, capacity constraints, ransomware attacks that encrypt our data and render it inaccessible or security-related incidents. In some instances, we may not be able to identify the cause or causes of these performance problems immediately, and it could take months, or even years, for such problems to become pronounced enough for us to detect or for our customers to detect and inform us. We may not be able to maintain the level of service uptime and performance required by our customers, especially during peak usage times and as our solutions become more complex and our user traffic increases. If our platforms are unavailable or if our customers are unable to access our solutions or deploy them within a reasonable amount of time, or at all, our business would be harmed. Since our customers rely on our service to access and complete their work, any outage on our platforms would impair the ability of our customers to perform their work, which would negatively impact our brand, reputation and customer satisfaction.
Our platforms are accessed by a large number of customers, often at the same time, and we continue to expand the number of our customers and solutions available to our customers. While we rely on third-party information technology systems, broadband and other communications systems and service providers to assist in providing access to our platforms, maintaining our infrastructure and distributing our solutions via the internet, we may not be able to scale our technology to accommodate increased capacity requirements, which may result in interruptions or delays in service. If a service provider fails to provide sufficient capacity to support our platforms or otherwise experiences service outages, including intentionally blocking our internet traffic or all internet traffic, for example at the request of a national government intending to isolate its country’s network, such failure could interrupt our customers’ access to our service, which could adversely affect their perception of our platforms’ reliability and our revenues. Any disruptions in these services, including as a result of actions outside of our control, would significantly impact the continued performance of our solutions. In the future, these services may not be available to us on commercially reasonable terms or at all. Any loss of the right to use any of these services could result in decreased functionality of our solutions until equivalent technology is either developed by us or, if available from another provider, is identified, obtained and integrated into our infrastructure. If we do not accurately predict our infrastructure capacity requirements, our customers could experience service shortfalls. We may also be unable to effectively address capacity constraints, upgrade our systems as needed and continually develop our technology and network architecture to accommodate actual and anticipated changes in technology.
Any of the above circumstances or events may harm our reputation, cause customers to terminate their agreements with us, impair our ability to obtain subscription renewals from existing customers, impair our ability to grow our customer base, result in the expenditure of significant financial, technical and engineering resources, subject us to financial penalties and liabilities under our service level agreements, and otherwise harm our business, results of operations and financial condition.
In the past, we have experienced cybersecurity incidents that allowed unauthorized access to our systems or data or our customers’ data, harmed our reputation, created additional liability and adversely impacted our financial results. We and our third-party service providers may experience similar incidents in the future which may also include disabling access to our service.
Our business relies on computer systems, hardware, software, technology infrastructure, and online sites and networks for operations that are critical to our business. Increasingly, we and other companies are subject to a wide variety of attacks on their systems and networks on an ongoing basis. In addition to threats from traditional computer “hackers,” malicious code (such as malware, viruses, worms and ransomware), employee or contractor
23

theft or misuse, password spraying, phishing and denial-of-service attacks, we and our third-party service providers now also face threats from sophisticated nation-state actors and organized crime groups who engage in attacks (including advanced persistent threat intrusions) that add to the risks to our systems (including those hosted on AWS’ or other cloud services providers’ systems), internal networks, our customers’ systems and the information that we and they store and process. For example, like other companies, we have experienced an increase in cybersecurity attacks and have had to expend increasing amounts of human and financial capital to respond. We expect that these cybersecurity attacks will continue and that the scope and sophistication of these efforts will increase in future periods. In particular, the use of AI, AI agents and NHIs to develop, conduct and/or enhance cyberattacks is expected to increase the frequency, severity and volume of such attacks. Despite significant efforts to create security barriers to such threats, it is virtually impossible for us to entirely mitigate these risks. As a provider of independent and neutral cloud-based identity solutions that form a part of our customers’ security software supply chain, we pose an attractive target for such attacks. The security measures we have integrated into our internal systems and platforms, which are designed to detect unauthorized activity and prevent or minimize security breaches, may not function as expected and have not in the past been, and may not in the future be, sufficient to protect our internal networks and platforms against certain attacks. Further, because we do not control our third-party service providers or the processing of data by our third-party service providers, we cannot ensure the integrity or security of the measures they take to protect customer information and prevent data loss. In addition, techniques used to sabotage or to obtain unauthorized access to networks in which data is stored or through which data is transmitted change frequently and become more complex over time. As a result, we and our third-party service providers have in the past been, and may in the future be, unable to anticipate these techniques or implement adequate preventative measures quickly enough to prevent either an electronic intrusion into our systems or services or a compromise of customer data, employee data or other protected information.
Our customers’ use of our technology to access business systems and store data concerning, among others, their employees, contractors, partners and customers is essential to their use of our platforms. As our platforms store, transmit and process customers’ proprietary information and users’ personal data, they have experienced and likely will in the future experience attacks targeting such customer data. When such breaches occur, and if the confidentiality, integrity or availability of our customers’ data or systems is disrupted, we could incur significant liability to our customers and to individuals or businesses whose information was being stored by our customers, and our platforms may be perceived as less desirable, which could negatively affect our business and damage our reputation.
In addition, security breaches impacting our platforms have in certain cases resulted in and could in the future result in a risk of loss or unauthorized disclosure or theft of this information, or the denial of access to this information, which, in turn, could lead to enforcement actions, litigation, regulatory or governmental audits, investigations and possible liability and increased requests by individuals regarding their personal data. Security breaches could also damage our relationships with and ability to attract customers and partners, as well as trigger service availability, indemnification and other contractual obligations. For example, our customers have in the past published public criticisms of our security practices in connection with security incidents, and these postings harm our reputation and brand. Security incidents may also cause us to incur significant investigation, mitigation, remediation, notification and other expenses. Furthermore, as a well-known provider of identity and security solutions that form a part of our customers’ security software supply chain, any such breach, including a breach of our customers’ systems, could compromise systems secured by our solutions, creating system disruptions or slowdowns and exploiting security vulnerabilities of our or our customers’ systems, and the information stored on our or our customers’ systems could be accessed, publicly disclosed, altered, lost or stolen, which could subject us to liability and cause us financial harm. While we have taken a number of remediation steps, there is no guarantee that our preventative and mitigation actions with respect to this incident and others like it will fully eliminate the risk of a malicious compromise of our or our customers’ systems.
We have experienced cybersecurity incidents resulting from our use of and oversight over third-party service providers and could experience such incidents in the future. These incidents have, in the past and may, in the future, result from our configuration of such providers’ products or from cybersecurity attacks on such providers of the same type that could affect our own systems. While we have implemented security measures and configuration policies that seek to protect data stored with our third-party service providers, such measures and policies have not in the past been and may not in the future be sufficient to protect our data or our customers’ data. For example, the January 2022 compromise of one of our third-party service providers by a threat actor, even though not material and not a breach of our platforms, nonetheless was widely publicized and focused attention on the security of our systems and the systems of our third-party service providers. In addition, in October 2023, a threat actor gained
24

unauthorized access to and stole information from inside our customer support system, which was hosted by a third-party service provider.
While we maintain cybersecurity insurance, our insurance may be insufficient to cover all liabilities incurred in these incidents and any incidents may result in loss of, or increased costs of, our cybersecurity insurance. These breaches, or any perceived breach, of our systems, our customers’ systems, our service providers’ systems or other systems or networks secured by our platforms, whether or not any such breach is due to a vulnerability in our platforms, may also undermine confidence in our platforms or our industry and result in damage to our reputation and brand, negative publicity, loss of ISVs and other channel partners, customers and sales, increased costs to remedy any problem, costly litigation and other liability. In addition, a breach of the security measures of one of our key ISVs or other channel partners or a security software supply chain attack even many levels removed could result in the exfiltration of confidential corporate information or other data that may provide additional avenues of attack. For example, an exploitation in an open source library that is imported and used in another framework that is used by a software product used by us could introduce an avenue of attack into our platforms. If a high profile security breach occurs with respect to a comparable cloud technology provider, our customers and potential customers may lose trust in the security of the cloud business model generally, which could adversely impact our ability to retain existing customers or attract new ones, potentially causing a negative impact on our business. Any of these negative outcomes could adversely impact market acceptance of our solutions and could harm our business, results of operations and financial condition.
Any actual or perceived failure by us, our third-party service providers or our customers to comply with new or existing laws, regulations or other requirements relating to the privacy, security and processing of personal information could adversely affect our business, results of operations or financial condition.
In connection with running our business, we receive, store, use and otherwise process personal data, including on behalf of our customers. Our customers’ storage and use of personal data concerning, among others, their employees, contractors, partners and customers is essential to their use of our platforms. We and our customers are therefore subject to global data protection laws and regulations, as well as other privacy-related requirements. For example, data protection laws, such as those applicable in the European Union, Canada and certain of its provinces, United Kingdom, Asia and certain states in the United States, have enhanced data protection obligations for companies that handle personal data. Obligations include, for example, expanded disclosures about how personal data is to be used, individual rights in relation to personal data, limitations on retention of personal data, mandatory data breach notification requirements and strict obligations on service providers, and restrictions on online marketing and the use of cookies and tracking technologies.
The costs of compliance with, and other burdens imposed by, such laws and regulations that are applicable to our business and the operations of our customers may limit the use and adoption of our service and reduce overall demand for it. These privacy and data security related laws and regulations are evolving and may result in increasing regulatory and public scrutiny and escalating levels of enforcement and sanctions. In addition, we are subject to certain contractual obligations regarding the collection, use, storage, transfer, disclosure and/or processing of personal data. Although we are working to comply with those federal, state and foreign laws and regulations, industry standards, contractual obligations and other legal obligations that apply to us, those laws, regulations, standards and obligations are evolving and may be modified, interpreted and applied in an inconsistent manner from one jurisdiction to another and may conflict with one another, other requirements or legal obligations, our practices or the features of our platforms. Additionally, while we have implemented various features intended to enable our customers to better comply with applicable privacy and security requirements in their collection and use of data within our platforms, these features have, in the past, not ensured and may, in the future, not ensure our customers’ compliance and may not be effective against all potential privacy or related regulatory concerns.
We also expect that there will continue to be new proposed laws, regulations, self-regulatory and industry standards concerning privacy, data protection, digital services and information security in the United States, the European Union and other jurisdictions, and we cannot yet determine the impact such future laws, regulations and standards may have on our business. In the United States, the Federal Trade Commission and state regulators enforce a variety of data privacy issues, such as promises made in privacy policies or failures to appropriately protect information about individuals, as unfair or deceptive acts or practices in or affecting commerce in violation of the Federal Trade Commission Act or similar state laws. Many U.S. states have also adopted new or modified privacy and security laws. These laws create a patchwork of legislation and regulation that impose heightened transparency obligations about data collection, use and sharing practices; add restrictions on the “sale” or “sharing” or transfer of personal information to third parties for purposes such as advertising or analytics; create new data privacy rights for consumers including the ability to limit the use of personal information for advertising; and carry
25

significant enforcement penalties for non-compliance, including monetary and injunctive relief. This patchwork may also give rise to conflicts or differing views of personal privacy rights. For example, certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to personal data than federal, international or other state laws, and such laws may differ from each other, all of which may complicate compliance efforts. We may expend significant resources attempting to comply with conflicting and overlapping state privacy regulations, and the cost and complexity of complying with such regulations could adversely affect our business or increase our potential liability if we fail to comply. This influx of state privacy regimes indicates a trend toward more stringent privacy legislation in the United States, including a potential federal privacy law, which could also increase our potential liability and adversely affect our business. In Europe, the General Data Protection Regulation 2016/679 (the “GDPR”) imposes a strict data protection compliance regime in relation to the collection and processing of personal data, and various European and other foreign laws also restrict the use of cookies, tracking technologies and certain marketing activities.
Future laws, regulations, standards and other obligations and changes in the interpretation of existing laws, regulations, standards and other obligations could impair our or our customers’ ability to collect, use or disclose information relating to consumers, which could decrease demand for our applications, restrict our business operations, or increase our costs and impair our ability to maintain and grow our customer base and increase our revenue. Such laws and regulations may require companies to implement privacy and security policies, permit users to exercise various data rights, inform individuals of security breaches that affect their personal data and, in some cases, obtain individuals’ consent to use personal data for certain purposes.
Any failure or perceived failure by us or our third-party service providers to comply with federal, state or foreign laws or regulations, industry standards, contractual obligations or other legal obligations, compliance frameworks with which we have contractually committed to comply, or any actual or suspected privacy or security incident, even if unfounded, whether or not resulting in unauthorized access to, or acquisition, release or transfer of personal data or other data, may result in investigations and enforcement actions and prosecutions, private litigation (including class action lawsuits), fines, penalties and censure, claims for damages by customers and other affected individuals or adverse publicity and could cause our customers to lose trust in us, which could have an adverse effect on our reputation and business. Additionally, plaintiffs have become increasingly active in bringing privacy-related claims against companies. Some of these claims allow for the recovery of statutory damages on a per violation basis and, if viable, carry the potential for significant statutory damages, depending on the volume of data and the number of violations.
We also publicly post our privacy policies and practices concerning our processing, use and disclosure of the personal data provided to us by our website visitors and by our customers and other individuals with whom we interact. Our publication of our privacy policies and other statements we publish that provide promises and assurances about privacy and security can subject us to potential state and federal action if they are found to be unfair, deceptive or misrepresentative of our practices.
Moreover, if our platforms are perceived to cause, or are otherwise unfavorably associated with, violations of privacy or data security requirements, it may subject us or our customers to public criticism and potential legal liability. Existing and potential privacy laws and regulations concerning privacy and data security and increasing sensitivity of consumers to unauthorized processing of personal data may create negative public reactions to technologies, solutions and services such as ours. Public concerns regarding personal data processing, privacy and security may cause some of our customers’ end users to be less likely to visit their websites or otherwise interact with them. If enough end users choose not to visit our customers’ websites or otherwise interact with them, our customers could stop using our platforms. This, in turn, may reduce the value of our service, slow or eliminate the growth of our business or cause our business to contract.
Privacy is a key issue for us and for our customers. We have attained multiple privacy certifications, such as the Data Privacy Network, Privacy Recognition for Processors and the European Union Cloud Code of Conduct, Level 2. If we fail to maintain our privacy certifications, or if we fail to seek expansion of their applicability to acquired and/or newly-developed solutions, we may fail to meet our contractual commitments and we may fail to retain our existing customers or attract new customers, and our business, results of operations and financial condition could suffer.
26

If we fail to maintain our security attestations and certifications, our business, results of operations and financial condition may suffer.
Security is essential for us and for our customers. A number of our Okta Platform product offerings have attained multiple certifications, including SOC 2 Type II Attestations, CSA Star Level 2 Certification, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019 and comply with many other international frameworks. Certain Okta Platform offerings maintain multiple agency FedRAMP Authorities to Operate and are compliant to operate at Department of Defense Impact Level 4. Certain Okta Platform offerings maintain minimum security requirements in alignment with the Security Rule of HIPAA. The Okta Platform also supports FIPS 140-2 encryption requirements. If we fail to maintain our security attestations and certifications, or if we fail to seek expansion of their applicability to acquired and/or newly-developed products, we may fail to meet our contractual commitments and we may fail to retain our existing customers or attract new customers, and our business, results of operations and financial condition could suffer.
We provide service level commitments under our customer contracts. If we fail to meet these contractual commitments, we could be obligated to provide credits for future service, which could harm our business, results of operations and financial condition.
Our customer agreements contain service level commitments, under which we guarantee specified availability of our platforms. Any failure of or disruption to our infrastructure could make our platforms unavailable to our customers. If we are unable to meet the stated service level commitments to our customers or suffer extended periods of unavailability of our platforms, we have been, and could in the future be, contractually obligated to provide affected customers with service credits for future subscriptions. Our revenue, other results of operations and financial condition could be harmed if we suffer unscheduled downtime that exceeds the service level commitments under our agreements with our customers, and any extended service outages could adversely affect our business and reputation as customers may elect not to renew and we could lose future sales.
If we are unable to ensure that our solutions integrate or interoperate with a variety of operating systems, platforms, services, software applications devices, mobile phones and other hardware form factors that are developed by others, our platforms may become less competitive and our results of operations may be harmed.
The number of people who access the internet through mobile devices and access cloud-based software applications through mobile devices, including smartphones and handheld tablets or laptop computers, has increased significantly in the past several years and is expected to continue to increase. While we have created mobile applications and mobile versions of our solutions that are accessible on third-party application stores, if these mobile applications and solutions do not perform well, our business may suffer. Third-party application stores may also impose new requirements, including, for example, updates to their terms of access or policies on how we or our channel partners must collect, use and share data. Compliance with any such requirements could be costly or burdensome, and could prevent us from timely updating our current mobile applications or distributing new mobile applications. If we fail to comply with these requirements, we could lose access to, or be required to remove our mobile applications from, third-party application stores.
In addition, our solutions interoperate with servers, mobile devices and software applications predominantly through the use of protocols, many of which are created and maintained by third parties. As a result, we depend on the interoperability of our solutions with such third-party services, mobile devices and mobile operating systems, as well as cloud-enabled hardware, software, networking, browsers, database technologies and protocols that we do not control. Past and future changes in such technologies that degrade the functionality of our solutions or give preferential treatment to competitive services have, in the past and could, in the future, adversely affect adoption and usage of our platforms. Any change in our customers’ preference for cloud-based identity management or any shift towards on-premises systems could also adversely affect adoption and usage of our platforms. Also, we may not be successful in developing or maintaining relationships with key participants in the mobile industry or in developing solutions that operate effectively with a range of operating systems, networks, devices, browsers, protocols and standards. In addition, we may face different fraud, security and regulatory risks from transactions sent from mobile devices than we do from personal computers. If we are unable to effectively anticipate and manage these risks, or if it is difficult for our customers to access and use our platforms, our business, results of operations and financial condition may be harmed.
Our success also depends on the willingness of third-party developers and technology providers to build applications and provide integrations that are complementary to our service. Without the development of these
27

applications and integrations, both current and potential customers may not find our service sufficiently attractive and our business, results of operations and financial condition could suffer.
Interruptions or delays in the services provided by third-party data centers or internet service providers have, in the past and could, in the future, impair the delivery of our platforms and our business could suffer.
We rely on a number of third-party service providers to operate our services. For example, we host our platforms using AWS data centers and other third-party cloud infrastructure services. Our operations depend on protecting the virtual cloud infrastructure hosted in AWS or other cloud services by maintaining its configuration, architecture and interconnection specifications, as well as the information stored in these virtual data centers and which third-party internet service providers transmit. Service interruptions from such infrastructure providers have caused and could in the future cause outages on our platforms. Our solutions use resources operated by us in these locations. Although we have disaster recovery plans that use multiple virtual data center locations, any incident affecting their infrastructure, including events beyond our control, could negatively affect our platforms, harm our reputation and expose us to liability. We may also incur significant costs for using alternative equipment or taking other actions in preparation for, or in reaction to, events that damage the third-party services we use.
We rely on software and services from other parties. Defects in or the loss of access to software or services from third parties could increase our costs and adversely affect the quality of our solutions.
We rely on technologies from third parties to operate critical functions of our business, including cloud infrastructure services and customer relationship management services. Our business would be disrupted if any of the third-party software or services we use, or functional equivalents, were unavailable due to defects in the software or services from those third parties, or because they are no longer available on commercially reasonable terms or prices. In each case, we would be required to either seek licenses to software or services from other parties and redesign our solutions to function with such software or services or develop substitutes ourselves, which would result in increased costs and could result in delays in launches or releases of new solutions until equivalent technology can be identified, licensed or developed and integrated into our solutions. Furthermore, we might be forced to limit the features available in our current or future solutions. These delays and feature limitations, if they occur, could harm our business, results of operations and financial condition.
Real or perceived errors, failures, vulnerabilities or bugs in our solutions, including deployment complexity, have in the past and could, in the future, harm our business and results of operations.
Errors, failures, vulnerabilities or bugs have, in the past and may, in the future, occur in our solutions, especially when updates are deployed or new solutions are rolled out, maintenance patches are applied or infrastructure, architectural or configuration changes are made. In the past, such issues have caused outages for our customers. Our platforms are often used in connection with large-scale computing environments with different operating systems, system management software, equipment and networking configurations, which may cause errors or failures of our solutions, or other aspects of the computing environment into which our solutions are deployed. In addition, deployment of our solutions into complicated, large-scale computing environments may expose errors, failures, vulnerabilities or bugs in our solutions. Any such errors, failures, vulnerabilities or bugs may not be found until after they are deployed to our customers.
We are committed to increasing our transparency with our customers and the public about our solutions and technology. This transparency, which may be more than is expected of companies in our industry, could lead to us publicly disclosing information that we would not otherwise be legally required to disclose, such as errors, failures, vulnerabilities or bugs in our solutions and technology. As a result, we could experience negative publicity that could harm our business. Any real or perceived errors, failures, vulnerabilities or bugs in our solutions or delays in or difficulties implementing our solutions, could also result in: loss, compromise, corruption or other unavailability of customer data; disruptions to our solutions or our customers’ products, systems, networks and operations; loss of business and new customers; loss of or delay in market acceptance of our solutions; a decrease in customer satisfaction or adoption rates; loss of competitive position; or claims by customers for losses sustained by them, all of which could harm our business, results of operations and financial condition.
28

Issues with our use, development, adoption, deployment and maintenance of AI Technologies, combined with an uncertain regulatory environment, may result in reputational harm, liability or other adverse consequences to our business operations.
We use internally developed and third-party developed machine learning and AI technologies (collectively, “AI Technologies”) in our offerings and business, and we are making investments in expanding our AI capabilities in our portfolio, including ongoing deployment and improvement of existing AI Technologies, as well as developing new product features using AI Technologies. We expect to rely on AI Technologies to help drive future growth and efficiency in our business. While our use of AI Technologies may become more important to our operations or to our future growth over time, we may not be able to realize the desired or anticipated benefits from AI in a timely or cost-effective manner.
AI Technologies are complex and rapidly evolving, and we face significant competition from other companies as well as an evolving regulatory landscape. For example, in the European Union, the EU Artificial Intelligence Act now establishes obligations on the use of AI based on the type of AI and its potential risks to society. Additionally, in the United States, legislation related to AI Technologies has been introduced at the federal level and is advancing at the state level. It is possible that further new laws and regulations will be adopted in the United States and in other non-U.S. jurisdictions, or that existing laws and regulations, including competition and antitrust laws, may be interpreted or challenged in ways that would limit our ability to use AI Technologies for our business, or require us to change the way we use AI Technologies in a manner that negatively affects the performance of our products, services, and business. We may need to expend resources to adjust our products or services in certain jurisdictions if the laws, regulations, or decisions are not consistent across jurisdictions. Further, the introduction of AI Technologies into new or existing solutions may result in new or enhanced governmental or regulatory scrutiny, litigation, confidentiality or security risks, ethical concerns or other complications that could adversely affect our business, reputation or financial results. For example, even if permitted by our privacy policy and contractual rights, our use of data in novel AI applications may, in time, expand beyond customer expectations. The intellectual property ownership and license rights, including copyright, surrounding AI Technologies has not been fully addressed by courts or national or local laws or regulations, and the use or adoption of third-party AI Technologies into our solutions may result in exposure to claims of copyright infringement or other intellectual property misappropriation.
In addition, we are working to incorporate generative AI Technologies (i.e., those that can produce and output new content, software code, data and information) into our offerings and internal business practices. Uncertainty around new and emerging AI Technologies, such as generative AI Technologies, may require additional investment in the development and maintenance of proprietary and third-party datasets and machine learning models, development of new approaches and processes to provide attribution or remuneration to creators of training data, and development of appropriate protections and safeguards for handling the use of customer data with AI Technologies, which may be costly and could impact our expenses as we continue to expand generative AI Technologies into our product offerings. If such investments do not deliver anticipated benefits or are not otherwise successful, our business and results of operations may be harmed. Furthermore, there is a risk that generative AI Technologies may create content that appears correct but is factually inaccurate or misleading, or that creates other discriminatory content or unexpected results or behaviors. Our customers or others may rely on or use this misleading content to their detriment, which may expose us to brand or reputational harm, competitive harm and/or legal liability. The use of AI Technologies presents emerging ethical and social issues, and if we enable or offer solutions that draw scrutiny or controversy due to their perceived or actual impact on customers or on society as a whole, we may experience brand or reputational harm, competitive harm and/or legal liability.
If we fail to adequately protect our proprietary rights, our competitive position could be impaired and we may lose valuable assets, generate less revenue and incur costly litigation to protect our rights.
Our success is dependent, in part, upon protecting our proprietary information and technology. We rely on a combination of patents, copyrights, trademarks, service marks, trade secret laws and contractual restrictions to establish and protect our proprietary rights. However, the steps we take to protect our intellectual property may be inadequate. We will not be able to protect our intellectual property if we are unable to enforce our rights or if we do not detect unauthorized use of our intellectual property. Despite our precautions, it may be possible for unauthorized third parties to copy our solutions and use information that we regard as proprietary to create solutions that compete with ours. Some contract provisions protecting against unauthorized use, copying, transfer and disclosure of our solutions may be unenforceable under the laws of certain jurisdictions and foreign countries. Further, the laws of some countries do not protect proprietary rights to the same extent as the laws of the United States, and mechanisms for enforcement of intellectual property rights in some foreign countries may be inadequate. To the
29

extent we expand our international activities, our exposure to unauthorized copying and use of our solutions and proprietary information may increase. Accordingly, despite our efforts, we may be unable to prevent third parties from infringing upon or misappropriating our technology and intellectual property.
We rely in part on trade secrets, proprietary know-how and other confidential information to maintain our competitive position. Although we enter into confidentiality and invention assignment agreements with our employees and consultants and enter into confidentiality agreements with the parties with whom we have strategic relationships and business alliances, no assurance can be given that these agreements will be effective in controlling access to and distribution of our solutions and proprietary information. Further, these agreements do not prevent our competitors from independently developing technologies that are substantially equivalent or superior to our solutions.
To protect our intellectual property rights, we may be required to spend significant resources to monitor and protect these rights. Litigation may be necessary in the future to enforce our intellectual property rights and to protect our trade secrets. Such litigation could be costly, time consuming and distracting to management and could result in the impairment or loss of portions of our intellectual property. Furthermore, our efforts to enforce our intellectual property rights may be met with defenses, counterclaims and countersuits attacking the validity and enforceability of our intellectual property rights. Our inability to protect our proprietary technology against unauthorized copying or use, as well as any costly litigation or diversion of our management’s attention and resources, could delay further sales or the implementation of our solutions, impair the functionality of our solutions, delay introductions of new solutions, result in our substituting inferior or more costly technologies into our solutions or injure our reputation. In addition, we may be required to license additional technology from third parties to develop and market new solutions, and we cannot ensure that we can license that technology on commercially reasonable terms or at all, and our inability to license this technology could harm our ability to compete.
We have in the past and may, in the future, be subject to infringement claims, which could result in significant damage awards that could harm our results of operations.
There is considerable patent and other intellectual property development activity in our industry, and we expect that software companies will increasingly be subject to infringement claims as the number of solutions and competitors grows, and the functionality of solutions in different industry segments overlaps. In addition, the patent portfolios of many of our competitors are larger than ours, and this disparity may increase the risk that our competitors may sue us for patent infringement and may limit our ability to counterclaim for patent infringement or settle through patent cross-licenses. Other companies have claimed in the past and may claim in the future, that we infringe upon their intellectual property rights. A claim may also be made relating to technology that we acquire or license from third parties. Further, we may be unaware of the intellectual property rights of others that may cover some or all of our technology.
Any claim of infringement, regardless of its merit or our defenses, could subject us to a number of risks described elsewhere in these risk factors, including those discussed under the title, “ If we fail to adequately protect our proprietary rights, our competitive position could be impaired and we may lose valuable assets, generate less revenue and incur costly litigation to protect our rights .”
We use open source software in our platforms, which could negatively affect our ability to offer our solutions and subject us to litigation or other actions.
We use open source software in our solutions and expect to use more open source software in the future. From time to time, there have been claims challenging the ownership of open source software against companies that incorporate open source software into their products. However, the terms of many open source licenses have not been interpreted by U.S. courts, and there is a risk that these licenses could be construed in a way that could impose unanticipated conditions or restrictions on our ability to commercialize our solutions. As a result, we could be subject to lawsuits by parties claiming ownership of what we believe to be open source software. Litigation could be costly for us to defend, have a negative effect on our results of operations and financial condition or require us to devote additional research and development resources to change our solutions. In addition, if we were to combine our proprietary software with open source software in a certain manner, we could, under certain of the open source licenses, be required to release the source code of our proprietary software to the public, which could open security risks as well as risks to exposing some of our trade secrets. This would allow our competitors to create similar solutions with less development effort and time. If we inappropriately use open source software, or if the license terms for open source software that we use change, we may be required to re-engineer our solutions, incur additional costs, discontinue the sale of some or all of our solutions or take other remedial actions. Some open
30

source software may include generative AI software or other software that incorporates or relies on generative AI or other AI technologies. The use of such software may expose us to risks as the intellectual property ownership and license rights, including copyright, of generative AI software and tools, has not been fully interpreted by U.S. courts or been fully addressed by federal or state regulation.
In addition to risks related to license requirements, usage of open source software can lead to greater risks than use of third-party commercial software, as open source licensors generally do not provide warranties or assurance of title or controls on origin of the software. In addition, many of the risks associated with usage of open source software, such as security issues, potential loss of trade secret protection and the lack of warranties or assurances of title, cannot be eliminated, and could, if not properly addressed, negatively affect our business. We have established processes to help alleviate these risks, including a review process for screening requests from our development organizations for the use of open source software, but we cannot be sure that all of our use of open source software is in a manner that is consistent with our current policies and procedures, or will not subject us to liability.
Indemnity provisions in various agreements potentially expose us to substantial liability for intellectual property infringement and other losses.
Our agreements with customers and other third parties include provisions under which we agree to indemnify or otherwise be liable to them for losses suffered or incurred as a result of claims of intellectual property infringement, damages caused by us to property or persons, or other liabilities relating to or arising from the use of our platforms or other acts or omissions. From time to time, customers also require us to indemnify or otherwise be liable to them for breach of confidentiality, violation of applicable law, or failure to implement adequate security measures with respect to their data stored, transmitted or accessed using our platforms. The term of these contractual provisions often survives termination or expiration of the applicable agreement. Although we normally contractually limit our liability with respect to such obligations, the existence of such a dispute may have adverse effects on our customer relationship and reputation and we may still incur substantial liability or large indemnity payments. This could significantly increase our operating expenses, require us to restrict our business activities and limit our ability to deliver certain solutions, all of which could require significant time, effort and expense, harm our reputation and customer relationships and negatively affect our business.
Risks Related to Legal, Accounting and Tax Matters

Because we generally recognize revenue from our subscriptions and support services over the term of the relevant service period, a decrease in sales during a reporting period may not be immediately reflected in our results of operations for that period.
We generally recognize revenue from subscriptions and related support services revenue ratably over the relevant service period. Net new revenue from new subscriptions, upsells and renewals entered into during a period can generally be expected to generate revenue for the duration of the service period. As a result, most of the revenue we report in each period is derived from the recognition of deferred revenue relating to subscriptions and support services contracts entered into during previous periods. Consequently, a decrease in new or renewed subscriptions in any single reporting period will have a limited impact on our revenue for that period, but will negatively affect our revenue in future periods. In addition, our ability to adjust our cost structure in the event of a decrease in new or renewed subscriptions may be limited.
Our subscription model also makes it difficult for us to rapidly increase our revenue through additional sales in any period, as revenue from customers is generally recognized over the applicable service period. Additionally, due to the complexity of certain of our customer contracts, the actual revenue recognition treatment required under relevant accounting principles generally accepted in the United States (“GAAP”) will depend on contract-specific terms and may result in greater variability in revenue from period to period.
In addition, a decrease in new subscriptions or renewals in a reporting period may not have an immediate impact on billings for that period.
We face exposure to foreign currency exchange rate fluctuations.
Today, a vast majority of our customer contracts are denominated in U.S. dollars. Over time, however, an increasing portion of our international customer contracts may be denominated in local currencies. In addition, the majority of our international costs are denominated in local currencies. As a result, fluctuations in the value of the
31

U.S. dollar and foreign currencies, including as a result of, for example, geopolitical events, changes in trade policies, trade restrictions and economic sanctions, or the threat of such actions, and market volatility, may affect our results of operations when translated into U.S. dollars. We do not currently engage in currency hedging activities to limit the risk of exchange rate fluctuations. However, in the future, we may use derivative instruments, such as foreign currency forward and option contracts, to hedge certain exposures to fluctuations in foreign currency exchange rates. The use of such hedging activities may not offset any or more than a portion of the adverse financial effects of unfavorable movements in foreign exchange rates over the limited time the hedges are in place. Moreover, the use of hedging instruments may introduce additional risks if we are unable to structure effective hedges with such instruments.
We are subject to anti-corruption, anti-bribery and similar laws, and non-compliance with such laws can subject us to criminal penalties or significant fines and harm our business and reputation.
We are subject to anti-corruption and anti-bribery and similar laws, such as the U.S. Foreign Corrupt Practices Act of 1977, as amended (the “FCPA”), the U.S. domestic bribery statute contained in 18 U.S.C. § 201, U.S. Travel Act, the USA PATRIOT Act, the U.K. Bribery Act 2010 and other anti-corruption, anti-bribery and anti-money laundering laws in countries in which we conduct activities. Anti-corruption and anti-bribery laws have been enforced aggressively in recent years and are interpreted broadly and prohibit companies and their employees and agents from promising, authorizing, making or offering improper payments or other benefits to government officials and others in the private sector. As we increase our international sales and business, our risks under these laws may increase.
In addition, we use channel partners to sell our solutions and conduct business on our behalf. We or such partners may have direct or indirect interactions with officials and employees of government agencies or state-owned or affiliated entities and under certain circumstances we could be held liable for the corrupt or other illegal activities of such partners and our employees, representatives, contractors, partners and agents, even if we do not explicitly authorize such activities.
Noncompliance with the FCPA, other applicable anti-corruption laws or anti-money laundering laws could subject us to investigations, whistleblower complaints, sanctions, settlements, prosecution and other enforcement actions within the U.S. and internationally, which could have a material adverse effect on our reputation, business, results of operations and financial condition.
We are subject to governmental export controls and economic sanctions laws that could impair our ability to compete in international markets and subject us to liability if we are not in full compliance with applicable laws.
Our business activities are subject to various restrictions under U.S. export controls and trade and economic sanctions laws, which include prohibitions on the sale or supply of certain products and services to U.S. embargoed or sanctioned countries, governments, persons and entities and also require authorization for the export of encryption items. In addition, various countries regulate the import of certain encryption technology, including through import and licensing requirements, and have enacted laws that could limit our ability to distribute our service or could limit our customers’ ability to implement our service in those countries. If we fail to comply with these laws and regulations, we and certain of our employees could be subject to civil or criminal penalties, including the possible loss of export privileges and monetary penalties. Obtaining the necessary authorizations, including any required license, for a particular transaction may be time-consuming, is not guaranteed and may result in the delay or loss of sales opportunities. Although we take precautions to prevent our solutions from being provided in violation of such laws, these laws are subject to change and interpretation over time. Our solutions may have been in the past, and could in the future be, provided inadvertently in violation of such laws, despite the precautions we take. This could result in negative consequences to us, including government investigations, penalties and harm to our reputation.
Our international operations may give rise to potentially adverse tax consequences.
We are expanding our international operations and staff to better support our growth into certain international markets. Our corporate structure and associated transfer pricing policies anticipate future growth into certain international markets. The amount of taxes we pay in different jurisdictions may depend on the application of the tax laws of the various jurisdictions, including the United States, to our international business activities, changes in tax rates, new or revised tax laws or interpretations of existing tax laws and policies and our ability to operate our business in a manner consistent with our corporate structure and intercompany arrangements. The taxing authorities of the jurisdictions in which we operate may challenge our methodologies for pricing intercompany
32

transactions, which are generally required to be computed on an arm’s-length basis pursuant to intercompany arrangements or disagree with our determinations as to the income and expenses attributable to specific jurisdictions. If such a challenge or disagreement were to occur and our position was not sustained, we could be required to pay additional taxes, interest and penalties, which could result in one-time tax charges, higher effective tax rates, reduced net cash flows and lower overall profitability of our operations. Our financial statements could fail to reflect adequate reserves to cover such a contingency.
Changes in tax laws or regulations in the various tax jurisdictions we are subject to that are applied adversely to us or our customers could increase the costs of our solutions and harm our business.
New income, sales, use, value-added or other transaction level taxes (including digital services taxes), tax laws, statutes, rules, regulations or ordinances could be enacted at any time. Those enactments could adversely impact our domestic and international business operations and our business and financial performance. Further, existing tax laws, statutes, rules, regulations or ordinances could be interpreted, changed, modified or applied adversely to us. These events could require us or our customers to pay additional tax amounts on a prospective or retroactive basis, as well as require us or our customers to pay fines and/or penalties and interest for past amounts deemed to be due. If we raise our prices to offset the costs of these additional taxes, existing and potential future customers may elect not to purchase our solutions in the future. Additionally, new, changed, modified or newly interpreted or applied tax laws could increase our compliance, operating and other costs, as well as the costs of our solutions to our customers. Further, these events could decrease the capital we have available to operate our business. Any or all of these events could harm our business and financial performance. For example, various legislative and regulatory actions and proposals, such as in the United States, the Organisation for Economic Co-operation and Development and the EU, have increasingly focused on future tax reform and contemplate changes to long-standing tax principles, which could adversely affect our liquidity and results of operations.
As a multinational organization, we may be subject to taxation in certain jurisdictions around the world with increasingly complex tax laws, the application of which can be uncertain. The amount of taxes we pay in these jurisdictions could increase substantially as a result of changes in the applicable tax principles, including increased tax rates, new tax laws or revised interpretations of existing tax laws and precedents, which could harm our liquidity and results of operations. In addition, the authorities in these jurisdictions could review our tax returns and impose additional tax, interest and penalties, and the authorities could claim that various withholding requirements apply to us or our subsidiaries or assert that benefits of tax treaties are not available to us or our subsidiaries, any of which could harm us and our results of operations.
Our business may be subject to additional obligations to collect and remit sales tax and other taxes, and we may be subject to tax liability for past sales. Any successful action by state, foreign or other authorities to collect additional or past sales tax could harm our business.
State, foreign and local taxing jurisdictions have differing rules and regulations governing sales, use and other indirect taxes (including digital services taxes), and these rules and regulations are subject to varying interpretations that may change over time. In particular, the applicability of certain sales, value-added and digital services taxes to our platforms in various jurisdictions is unclear. It is possible that we could face tax audits and that our liability for these taxes could exceed our estimates as tax authorities could still assert that we are obligated to collect additional amounts as taxes from our customers and remit those taxes to those authorities. We could also be subject to audits in states and international jurisdictions for which we have not accrued tax liabilities. A successful assertion that we should be collecting additional sales or other taxes on our solutions and services in jurisdictions where we have not historically done so and do not accrue for such taxes could result in substantial tax liabilities for past sales, discourage customers from purchasing our solutions or otherwise harm our business, results of operations and financial condition.
We file sales tax returns in certain state and local jurisdictions within the United States as required by law and certain customer contracts for a portion of the solutions that we provide. We do not collect sales or other similar taxes in other state and local jurisdictions and many of such jurisdictions do not apply sales or similar taxes to the vast majority of the solutions that we provide. However, one or more state, local or foreign authorities could seek to impose additional sales, use or other tax collection and record-keeping obligations on us or may determine that such taxes should have, but have not been, paid by us. Liability for past taxes may also include substantial interest and penalty charges. Any successful action by state, foreign or other authorities to compel us to collect and remit sales tax, use tax or other taxes, either retroactively, prospectively or both, could harm our business, results of operations and financial condition.
33

Our ability to use our U.S. net operating loss carry-forwards and certain other tax attributes may be limited.
Under Section 382 of the Internal Revenue Code of 1986, as amended, if a corporation undergoes an “ownership change,” generally defined as a greater than 50% change (by value) in its equity ownership over a three-year period, the corporation’s ability to use its pre-change net operating loss carry-forwards and other pre-change tax attributes, such as research tax credits and distributed interest deduction carryover, to offset its post-change income may be limited. We have experienced ownership changes in the past and any such ownership change in the future could result in increased future tax liability. In addition, we may experience ownership changes in the future as a result of subsequent shifts in our stock ownership. As a result, if we earn net taxable income, our ability to use our pre-change net operating loss carry-forwards to offset U.S. federal taxable income may be subject to limitations, which could potentially result in increased future tax liability to us.
If we fail to maintain an effective system of disclosure controls and internal control over financial reporting, our ability to produce timely and accurate financial statements or comply with applicable regulations could be impaired.
The Sarbanes-Oxley Act requires, among other things, that we maintain effective disclosure controls and procedures and internal control over financial reporting. To satisfy this obligation, we expend significant resources, including accounting-related costs and significant management oversight. If any of these controls and systems do not perform as expected, we may experience material weaknesses or significant deficiencies in our controls. Our controls may also become inadequate because of changes in conditions in our business. We may discover any such weaknesses or deficiencies in the future and be required to restate our financial statements for prior periods.
Ineffective internal controls over financial reporting could adversely affect the results of periodic management evaluations and annual independent registered public accounting firm attestation reports regarding the effectiveness of our internal control over financial reporting that we are required to include in our periodic reports that are filed with the SEC. For example, investors could lose confidence in our reported financial and other information; we could fail to satisfy our SEC, Nasdaq or other reporting obligations, or become subject to sanctions or investigations by regulators; and the price of our Class A common stock could decline.
Changes in existing financial accounting standards or practices, or taxation rules or practices, may harm our results of operations.
Changes in existing accounting or taxation rules or practices, new accounting pronouncements or taxation rules, or varying interpretations of current accounting pronouncements or taxation practice could harm our results of operations or the manner in which we conduct our business. Further, such changes could potentially affect our reporting of transactions completed before such changes are effective.
GAAP are subject to interpretation by the Financial Accounting Standards Board (“FASB”), the SEC and various bodies formed to promulgate and interpret appropriate accounting principles. A change in these principles or interpretations could have a significant effect on our reported financial results and could affect the reporting of transactions completed before the announcement of a change. Adoption of such new standards and any difficulties in implementation of changes in accounting principles, including the ability to modify our accounting systems, could cause us to fail to meet our financial reporting obligations, which could result in regulatory discipline and harm investors’ confidence in us.
If our estimates or judgments relating to our critical accounting policies prove to be incorrect, our results of operations could be adversely affected.
The preparation of financial statements in conformity with GAAP requires management to make estimates and assumptions that affect the amounts reported in our consolidated financial statements and accompanying notes. We base our estimates on historical experience and on various other assumptions that we believe to be reasonable under the circumstances, as provided in the section titled “Management’s Discussion and Analysis of Financial Condition and Results of Operations.” The results of these estimates form the basis for making judgments about the carrying values of assets, liabilities and equity and the amount of revenue and expenses that are not readily apparent from other sources. Significant assumptions and estimates used in preparing our consolidated financial statements include, but are not limited to those referenced in the section titled “Management’s Discussion and Analysis of Financial Condition and Results of Operations.” Our results of operations may be adversely affected if our assumptions change or if actual circumstances differ from those in our assumptions, which could cause our
34

results of operations to fall below the expectations of securities analysts and investors, resulting in a decline in the trading price of our Class A common stock.
Risks Related to Ownership of Our Class A Common Stock
The stock price of our Class A common stock may be volatile or may decline.
The trading price of our Class A common stock has been, and in the future may be, subject to substantial volatility and wide fluctuations. For example, from February 1, 2025 through January 31, 2026, the trading price of our Class A common stock has ranged from $75.05 per share to $127.57 per share. The market price of our Class A common stock fluctuates significantly in response to numerous factors, many of which are beyond our control, including, but not limited to, the factors described elsewhere in these risk factors as well as:
• overall performance of the equity markets and/or publicly-listed technology companies;
• volatility in the market prices and trading volumes of technology and high-growth companies generally, or those in our industry in particular;
• actual or anticipated fluctuations in our revenue or other financial or operating metrics;
• our ability to meet or exceed forward-looking guidance we have given, our ability to give forward-looking guidance consistent with past practices, and changes to or withdrawal of previous guidance or long-range targets;
• our inability to execute on our publicly announced stock repurchase program as planned, including failure to meet internal or external expectations around the timing or price of share repurchases, and any reductions or discontinuances of repurchases thereunder;
• failure of securities analysts to initiate or maintain coverage of us, changes in financial estimates and/or recommendations by any securities analysts who follow our company;
• our failure to meet the estimates or the expectations of securities analysts or investors;
• actions and investment positions taken by institutional and other stockholders, including activist investors;