SEC EDGAR · 10-K
10-K – 2025-09-11 – zs-20250731.htm
518297 tecken · 3 HTML-del(ar)
Automatiskt nyckeltalsindex
Detta är sökträffar och textkontext, inte verifierade eller normaliserade redovisningsvärden.
Omsättning
- • the impact of macroeconomic and geopolitical events, developments and conditions on our business; | • our future financial performance, including our expectations regarding our revenue, cost of revenue, gross profit or gross margin, operating expenses (including changes in sales and marketing, research and development and general and administrative expenses) and our ability to achieve, and maintain, future profitability; | • market acceptance of our cloud platform;
- Many of the largest enterprises and government agencies in the world rely on our solutions to help them accelerate their move to the cloud. We have over 9,400 customers across all major geographies, with an emphasis on larger organizations, and we currently count approximately 40% of the Forbes Global 2000 and over 45% of Fortune 500 companies as customers. Our customers span every major industry, including financial services, healthcare, insurance, manufacturing, automotive, airlines and transp | We have experienced significant growth, with revenue increasing from $1,617.0 million in fiscal 2023 to $2,167.8 million in fiscal 2024 to $2,673.1 million in fiscal 2025, representing year-over-year revenue growth of 34% and 23%, respectively. We experienced net losses of $41.5 million, $57.7 million and $202.3 million in fiscal 2025, fiscal 2024 and fiscal 2023, respectively. We expect we will continue to incur net losses for the foreseeable future. | We pioneered a cloud platform, the Zscaler Zero Trust Exchange TM platform, which represented a fundamental shift in the architectural design and approach to networking and security that allows companies to securely accelerate their digital transformation initiatives.
- The growing use of the internet and the increasing adoption of the cloud and mobility are driving network and application transformation. As a provider of a fully integrated, multi-tenant cloud security solution, we enable our customers to accelerate this secure transformation to the cloud and believe we are uniquely positioned to maximize value as they undertake these transitions. Key elements of our growth strategy include: | • Continue to win new customers. We believe that we have a significant opportunity to expand our customer base, both in the United States and internationally. We have invested significantly in our sales and marketing organization to execute against this opportunity. | • Expansion in existing customers. We leverage a land-and-expand approach with our existing customers to sell subscriptions for additional users, additional solutions and premium solution bundles that contain more functionality.
- • Expansion into additional market segments. We are targeting the expansion of our immediate addressable market into additional markets, segments and verticals. For example, we are targeting our expansion into new geographies in the Asia Pacific, Latin America and Middle East regions. | We sell to enterprises of all sizes. As of July 31, 2025, we had over 9,400 customers, including approximately 40% of the Forbes Global 2000 and over 45% of Fortune 500 companies. Many of our customers include major global enterprises that send virtually all of their internet traffic through our cloud security platform. Our customers operate in a variety of industries, including automotive, airlines and transportation, conglomerates, consumer goods and retail, energy, financial services, healthc | 14
- Sales and Marketing | Although we have a channel sales model, we use a joint sales approach in which our sales force develops relationships directly with our customers, and together with our channel account teams, works with our channel partners on account penetration, account coordination, sales and overall market development. Our customer care and success teams maintain high-touch relationships with our customers to deploy and manage our cloud platform, identify, analyze and resolve performance issues and respond t
- Sales and Marketing | Although we have a channel sales model, we use a joint sales approach in which our sales force develops relationships directly with our customers, and together with our channel account teams, works with our channel partners on account penetration, account coordination, sales and overall market development. Our customer care and success teams maintain high-touch relationships with our customers to deploy and manage our cloud platform, identify, analyze and resolve performance issues and respond t | Our channel partners consist of global telecommunications service providers, system integrators, value-added reseller partners and public cloud marketplaces, and we leverage their relationships to expand our reach, improve procurement and accelerate customer fulfillment.
- We enter into agreements with our channel partners in the ordinary course of business. The contracts typically have a one-year term and renew automatically, subject to cancellation by either party upon 90 days’ notice. These agreements contain standard commercial terms and conditions, including payment terms, billing frequency, warranties and indemnification. Our channel partners generally place purchase orders with us after receiving orders from customers. We generally maintain privity of contr | We expect to continue investing in our channel partners as we provide them with education, training and programs, including supporting their independent sales of our solutions. We believe that such investment, and investments in our sales force, will lead to significant expansion in our customer base, which will materially impact our business and results of operations. | Our marketing strategy is focused on platform and brand awareness, which drives our opportunity pipeline and customer demand. This strategy is account-based, enabling us to pursue targeted marketing activities across both digital and non-digital channels. We anticipate increasing our marketing team headcount and are investing in programs designed to elevate our brand in the market and engage new enterprise accounts. We also participate in a number of cloud and security industry events. In additi
- • brand awareness, reputation and trust in the provider’s services; | • strength of sales, marketing and channel partner relationships; and | 16
Återkommande intäkter
- • selling a subscription to a new solution or product, for example selling a ZPA subscription to a ZIA customer or a ZIA subscription to a ZPA customer. | These purchases increase the annual recurring revenue, or ARR, attributable to our customers over time. ARR refers to the next 12 months of revenue from subscription contracts as of the measurement date. To establish ARR for a customer, we assume that any contract expiring during the next 12 months will be renewed under the existing terms. | 64
- Dollar-Based Net Retention Rate | We believe that dollar-based net retention rate is an indicator to measure the long-term value of our customer relationships because it is driven by our ability to retain and expand the recurring revenue generated from our existing customers. Our dollar-based net retention rate compares the recurring revenue from a set of customers against the same metric for the prior 12-month period on a trailing basis. Because our customers have repeat buying patterns and the average term of our contracts is | We calculate our dollar-based net retention rate as follows:
- We calculate our dollar-based net retention rate as follows: | • Denominator: To calculate our dollar-based net retention rate as of the end of a reporting period, we first establish the ARR from all active subscriptions as of the last day of the same reporting period in the prior fiscal year. This effectively represents recurring dollars that we expect in the next 12-month period from the cohort of customers that existed on the last day of the same reporting period in the prior fiscal year. | • Numerator: We measure the ARR for that same cohort of customers representing all subscriptions based on confirmed customer orders booked by us as of the end of the reporting period.
- • Denominator: To calculate our dollar-based net retention rate as of the end of a reporting period, we first establish the ARR from all active subscriptions as of the last day of the same reporting period in the prior fiscal year. This effectively represents recurring dollars that we expect in the next 12-month period from the cohort of customers that existed on the last day of the same reporting period in the prior fiscal year. | • Numerator: We measure the ARR for that same cohort of customers representing all subscriptions based on confirmed customer orders booked by us as of the end of the reporting period. | Dollar-based net retention rate is obtained by dividing the numerator by the denominator. Our dollar-based net retention rate may fluctuate due to a number of factors, including the performance of our cloud platform, our success in selling bigger deals, including deals for all employees with our higher-end bundles, selling multiple-pillars from the start of our contract with new customers, faster upsells within a year, the timing and the rate of ARR expansion of our existing
- • Numerator: We measure the ARR for that same cohort of customers representing all subscriptions based on confirmed customer orders booked by us as of the end of the reporting period. | Dollar-based net retention rate is obtained by dividing the numerator by the denominator. Our dollar-based net retention rate may fluctuate due to a number of factors, including the performance of our cloud platform, our success in selling bigger deals, including deals for all employees with our higher-end bundles, selling multiple-pillars from the start of our contract with new customers, faster upsells within a year, the timing and the rate of ARR expansion of our existing | 65
- Calculated Billings | Calculated billings is a non-GAAP financial measure that we reported as a key metric to measure our periodic performance through July 31, 2025. However, starting in the first quarter of fiscal 2026, we will transition to ARR as one of | 67
Rörelseresultat
- useful lives of property and equipment, useful lives of acquired intangible assets, recoverability of goodwill, valuation of deferred tax assets and liabilities, loss contingencies related to litigation, fair value of the 2028 Notes and the discount rate used for operating leases. Our results of operations may be adversely affected if our assumptions change or if actual circumstances differ from those in our assumptions, which could cause our results of operations to fall below the expectations | Additionally, we regularly monitor our compliance with applicable financial reporting standards and review new pronouncements and drafts thereof that are relevant to us. As a result of new standards, changes to existing standards and changes in their interpretation, we might be required to change our accounting policies, alter our operational policies and implement new or enhance existing systems so that they reflect new or amended financial reporting standards, or we may be required to restate | We rely on third parties for certain essential financial and operational services, and a failure or disruption in these services could materially and adversely affect our ability to manage our business effectively.
Periodens resultat
- We are expanding our international operations and staff to support our business in international markets. Our corporate structure and associated transfer pricing policies contemplate the business flows and future growth into the international markets, and consider the functions, risks and assets of the various entities involved in the intercompany transactions. The amount of taxes we pay in different jurisdictions may depend on the application of the tax laws of the various jurisdictions, includ | Many countries are beginning to implement legislation and other guidance to align their international tax rules with the Organization for Economic Cooperation and Development’s, or OECD, Base Erosion and Profit Shifting recommendations and action plan that aim to standardize and modernize global corporate tax policy, including changes to cross-border tax, transfer pricing documentation rules and nexus-based tax incentive practices. The OECD is also continuing discussions surrounding fundamental | 48
- issuance costs incurred in connection with the issuance of convertible senior notes are reflected in the consolidated balance sheets as a direct deduction from the carrying amount of the outstanding convertible senior notes. These costs are amortized using the effective interest rate method over the terms of the convertible senior notes and are included within interest expense on the consolidated statements of operations. | We use the if-converted method to calculate the potentially diluted effect of the convertible senior notes. Accordingly, to account for the potentially diluted shares related to the convertible senior notes under a net income position, we are required to add back the related interest expense to the net income. Since we have reported net losses for all periods presented, the convertible senior notes were determined to be anti-dilutive and therefore had no impact to the diluted net loss per share | Research and Development
Resultat per aktie
- Basic net loss per share is computed by dividing the net loss by the weighted-average number of shares of common stock outstanding during the period, less shares subject to repurchase. | D iluted earnings per share adjusts basic earnings per share for all potentially dilutive common stock equivalents outstanding during the period. Potentially dilutive securities consist primarily of stock options, share purchase rights under the ESPP, unvested RSUs, unvested PSAs, unvested common stock and shares related to convertible senior notes. Since we have reported net losses for all periods presented, we have excluded all potentially dilutive securities from the calculation of the dilute | Recently Adopted Accounting Pronouncements
- In November 2023, the Financial Accounting Standards Board ("FASB") issued ASU No. 2023-07, Segment Reporting (Topic 280): Improvements to Reportable Segment Disclosures , which requires disclosure of incremental segment information on an annual and interim basis. We adopted this standard during the fiscal year ended July 31, 2025, refer to Note 17, Segment and Geographic Information for the additional required disclosures. | In June 2020, the FASB issued ASU No. 2020-06. This standard removes the separation model for convertible debt with a cash conversion feature and convertible instruments with a beneficial conversion feature. Such convertible debt will be accounted for as a single liability measured at its amortized cost, as long as no other features require bifurcation and recognition as derivatives. The update also requires the if-converted method to be used for convertible instruments and the effect of potenti | Recently Issued Accounting Pronouncements Not Yet Adopted
- Since we have reported net losses for all periods presented, we have excluded all potentially dilutive securities from the calculation of the diluted net loss per share as their effect is antidilutive and accordingly, the basic and diluted net loss per share is the same for all periods presented. | We calculate the potential dilutive effect of the convertible senior notes under the if-converted method. Under this method, diluted earnings per share are determined by assuming that outstanding convertible senior notes were converted into shares of our common stock at the beginning of the reporting period. | In connection with the issuance of the convertible senior notes, we entered into capped call transactions, which were not included for purposes of calculating the number of diluted shares outstanding, as their effect would have been anti-dilutive. The capped call transactions are expected to partially offset the potential dilution to our common stock upon any conversion of the convertible senior notes.
Kassaflöde
- • if we are unable to effectively manage certain risks and challenges related to our India operations, our business could be harmed; | • servicing our debt may require a significant amount of cash, and we may not have sufficient cash flow from our business or the ability to raise funds to pay our substantial debt; and | 20
- • general economic conditions in either domestic or international markets, including as a result of macroeconomic and geopolitical events, developments and conditions. | Any one or more of the factors above may result in significant fluctuations in our results of operations. We also intend to continue to invest significantly to grow our business in the near future rather than optimizing for profitability or cash flows. In addition, we generally experience seasonality in terms of when we enter into agreements with customers. We typically enter into a higher percentage of agreements with new customers, as well as renewal agreements with existing customers, in the | The variability and unpredictability of our quarterly results of operations or other operating metrics could result in our failure to meet our expectations or those of industry or financial analysts. If we fail to meet or exceed such expectations for these or any other reasons, the market price of our common stock could fall substantially, and we could face costly lawsuits, including securities class action suits.
- The vast majority of our sales contracts are denominated in U.S. dollars, and therefore, substantially all of our revenue is not subject to foreign currency risk. However, a strengthening of the U.S. dollar could increase the real cost of our solutions to our customers outside of the United States, which could adversely affect our financial condition and operating results. In addition, a portion of our operating expenses is incurred outside the United States and denominated in foreign currencies | We have a foreign currency risk management program, in which we enter into foreign currency forward contracts which we designate as cash flow hedges. We also use foreign currency forward contracts to mitigate variability in gains and losses generated from the remeasurement of certain monetary assets and liabilities denominated in foreign currencies. The use of | 47
- Non-GAAP Financial Measures | In addition to our results determined in accordance with GAAP, we believe the following non-GAAP measures are useful in evaluating our operating performance. We use the following non-GAAP financial information to evaluate our ongoing operations and for internal planning and forecasting purposes. We believe that non-GAAP financial information, when taken collectively, may be helpful to investors because it provides consistency and comparability with past financial performance. However, non-GAAP f | Non-GAAP Gross Profit and Non-GAAP Gross Margin
- Free Cash Flow and Free Cash Flow Margin | Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by operating activities less purchases of property, equipment and other assets and capitalized internal-use software. Free cash flow margin is calculated as free cash flow divided by revenue. We believe that free cash flow and free cash flow margin are useful indicators of liquidity that provide information to management and investors about the amount of cash generated from our operations that, after the invest
- Free Cash Flow and Free Cash Flow Margin | Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by operating activities less purchases of property, equipment and other assets and capitalized internal-use software. Free cash flow margin is calculated as free cash flow divided by revenue. We believe that free cash flow and free cash flow margin are useful indicators of liquidity that provide information to management and investors about the amount of cash generated from our operations that, after the invest | Free cash flow includes the cyclical impact of inflows and outflows resulting from contributions to our employee stock purchase plan for which the purchase period of approximately six months ends in each of our second and fourth fiscal quarters. Payroll contributions accrued as of July 31, 2025 will be used to purchase shares at the end of the current ESPP purchase period ending on December 15, 2025. Payroll contributions ultimately used to purchase shares are reclassified to stockholders' equit
- Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by operating activities less purchases of property, equipment and other assets and capitalized internal-use software. Free cash flow margin is calculated as free cash flow divided by revenue. We believe that free cash flow and free cash flow margin are useful indicators of liquidity that provide information to management and investors about the amount of cash generated from our operations that, after the invest | Free cash flow includes the cyclical impact of inflows and outflows resulting from contributions to our employee stock purchase plan for which the purchase period of approximately six months ends in each of our second and fourth fiscal quarters. Payroll contributions accrued as of July 31, 2025 will be used to purchase shares at the end of the current ESPP purchase period ending on December 15, 2025. Payroll contributions ultimately used to purchase shares are reclassified to stockholders' equit
- Capitalized internal-use software (81,508) (50,308) (31,527) | Free cash flow $ 726,693 $ 584,950 $ 333,619 | As a percentage of revenue:
Fritt kassaflöde
- Non-GAAP Financial Measures | In addition to our results determined in accordance with GAAP, we believe the following non-GAAP measures are useful in evaluating our operating performance. We use the following non-GAAP financial information to evaluate our ongoing operations and for internal planning and forecasting purposes. We believe that non-GAAP financial information, when taken collectively, may be helpful to investors because it provides consistency and comparability with past financial performance. However, non-GAAP f | Non-GAAP Gross Profit and Non-GAAP Gross Margin
- Free Cash Flow and Free Cash Flow Margin | Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by operating activities less purchases of property, equipment and other assets and capitalized internal-use software. Free cash flow margin is calculated as free cash flow divided by revenue. We believe that free cash flow and free cash flow margin are useful indicators of liquidity that provide information to management and investors about the amount of cash generated from our operations that, after the invest
- Free Cash Flow and Free Cash Flow Margin | Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by operating activities less purchases of property, equipment and other assets and capitalized internal-use software. Free cash flow margin is calculated as free cash flow divided by revenue. We believe that free cash flow and free cash flow margin are useful indicators of liquidity that provide information to management and investors about the amount of cash generated from our operations that, after the invest | Free cash flow includes the cyclical impact of inflows and outflows resulting from contributions to our employee stock purchase plan for which the purchase period of approximately six months ends in each of our second and fourth fiscal quarters. Payroll contributions accrued as of July 31, 2025 will be used to purchase shares at the end of the current ESPP purchase period ending on December 15, 2025. Payroll contributions ultimately used to purchase shares are reclassified to stockholders' equit
- Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by operating activities less purchases of property, equipment and other assets and capitalized internal-use software. Free cash flow margin is calculated as free cash flow divided by revenue. We believe that free cash flow and free cash flow margin are useful indicators of liquidity that provide information to management and investors about the amount of cash generated from our operations that, after the invest | Free cash flow includes the cyclical impact of inflows and outflows resulting from contributions to our employee stock purchase plan for which the purchase period of approximately six months ends in each of our second and fourth fiscal quarters. Payroll contributions accrued as of July 31, 2025 will be used to purchase shares at the end of the current ESPP purchase period ending on December 15, 2025. Payroll contributions ultimately used to purchase shares are reclassified to stockholders' equit
- Capitalized internal-use software (81,508) (50,308) (31,527) | Free cash flow $ 726,693 $ 584,950 $ 333,619 | As a percentage of revenue:
- Capitalized internal-use software (3) (2) (2) | Free cash flow margin 27 % 27 % 21 %
Likvida medel
- Current assets: | Cash and cash equivalents $ 2,389,023 $ 1,423,080 | Short-term investments 1,183,386 986,574
- Net cash provided by financing activities 420,512 64,208 45,990 | Net increase in cash and cash equivalents 965,943 160,874 248,996 | Cash and cash equivalents at beginning of period
- Net increase in cash and cash equivalents 965,943 160,874 248,996 | Cash and cash equivalents at beginning of period | 1,423,080 1,262,206 1,013,210
- 1,423,080 1,262,206 1,013,210 | Cash and cash equivalents at end of period | $ 2,389,023 $ 1,423,080 $ 1,262,206
Nettoskuld
- Free Cash Flow and Free Cash Flow Margin | Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by operating activities less purchases of property, equipment and other assets and capitalized internal-use software. Free cash flow margin is calculated as free cash flow divided by revenue. We believe that free cash flow and free cash flow margin are useful indicators of liquidity that provide information to management and investors about the amount of cash generated from our operations that, after the invest | Free cash flow includes the cyclical impact of inflows and outflows resulting from contributions to our employee stock purchase plan for which the purchase period of approximately six months ends in each of our second and fourth fiscal quarters. Payroll contributions accrued as of July 31, 2025 will be used to purchase shares at the end of the current ESPP purchase period ending on December 15, 2025. Payroll contributions ultimately used to purchase shares are reclassified to stockholders' equit
- (in thousands) | Net cash provided by operating activities $ 972,453 $ 779,846 $ 462,343 | Less:
- Net cash provided by operating activities 36 % 36 % 29 % | Less:
- (in thousands) | Net cash provided by operating activities $ 972,453 $ 779,846 $ 462,343 | Net cash used in investing activities $ (427,022) $ (683,180) $ (259,337)
- Net cash provided by operating activities $ 972,453 $ 779,846 $ 462,343 | Net cash used in investing activities $ (427,022) $ (683,180) $ (259,337) | Net cash provided by financing activities $ 420,512 $ 64,208 $ 45,990
- Net cash used in investing activities $ (427,022) $ (683,180) $ (259,337) | Net cash provided by financing activities $ 420,512 $ 64,208 $ 45,990
- Operating Activities | Net cash provided by operating activities during fiscal 2025 was $972.5 million, which resulted from a net loss of $41.5 million, adjusted for non-cash charges of $987.2 million and net cash inflows of $26.7 million from changes in operating assets and liabilities. Non-cash charges primarily consisted of $661.4 million for stock-based compensation expense, $166.3 million for amortization of deferred contract acquisition costs, $104.4 million for depreciation and amortization expense, $63.0 milli | Net cash inflows from changes in operating assets and liabilities were primarily the result of an increase of $573.1 million in deferred revenue from advance invoicing in accordance with our subscription contracts, an increase of $21.0 million in accrued compensation and an increase of $17.5 million in accounts payable. Net cash inflows were partially offset by cash outflows resulting from an increase of $230.5 million in deferred contract acquisition costs, as our sales commission payments incr
- Net cash provided by operating activities during fiscal 2025 was $972.5 million, which resulted from a net loss of $41.5 million, adjusted for non-cash charges of $987.2 million and net cash inflows of $26.7 million from changes in operating assets and liabilities. Non-cash charges primarily consisted of $661.4 million for stock-based compensation expense, $166.3 million for amortization of deferred contract acquisition costs, $104.4 million for depreciation and amortization expense, $63.0 milli | Net cash inflows from changes in operating assets and liabilities were primarily the result of an increase of $573.1 million in deferred revenue from advance invoicing in accordance with our subscription contracts, an increase of $21.0 million in accrued compensation and an increase of $17.5 million in accounts payable. Net cash inflows were partially offset by cash outflows resulting from an increase of $230.5 million in deferred contract acquisition costs, as our sales commission payments incr | Net cash provided by operating activities during fiscal 2024 was $779.8 million, which resulted from a net loss of $57.7 million, adjusted for non-cash charges of $771.5 million and net cash inflows of $66.1 million from changes in operating assets and liabilities. Non-cash charges primarily consisted of $527.7 million for stock-based compensation expense, $130.1 million for amortization of deferred contract acquisition costs, $66.3 million for depreciation and
Eget kapital
- Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by operating activities less purchases of property, equipment and other assets and capitalized internal-use software. Free cash flow margin is calculated as free cash flow divided by revenue. We believe that free cash flow and free cash flow margin are useful indicators of liquidity that provide information to management and investors about the amount of cash generated from our operations that, after the invest | Free cash flow includes the cyclical impact of inflows and outflows resulting from contributions to our employee stock purchase plan for which the purchase period of approximately six months ends in each of our second and fourth fiscal quarters. Payroll contributions accrued as of July 31, 2025 will be used to purchase shares at the end of the current ESPP purchase period ending on December 15, 2025. Payroll contributions ultimately used to purchase shares are reclassified to stockholders' equit
- Consolidated Statements of Stockholders' Equity for the years ended July 31, 2025 , 2024 and 2023 | 93
- Opinions on the Financial Statements and Internal Control over Financial Reporting | We have audited the accompanying consolidated balance sheets of Zscaler, Inc. and its subsidiaries (the "Company") as of July 31, 2025 and 2024, and the related consolidated statements of operations, of comprehensive loss, of stockholders' equity and of cash flows for each of the three years in the period ended July 31, 2025, including the related notes (collectively referred to as the "consolidated financial statements"). We also have audited the Company's internal control over financial report | In our opinion, the consolidated financial statements referred to above present fairly, in all material respects, the financial position of the Company as of July 31, 2025 and 2024, and the results of its operations and its cash flows for each of the three years in the period ended July 31, 2025 in conformity with accounting principles generally accepted in the United States of America. Also in our opinion, the Company maintained, in all material respects, effective internal control over financi
- Total assets $ 6,419,888 $ 4,704,968 | Liabilities and Stockholders’ Equity | Current liabilities:
- Stockholders’ Equity
- Accumulated deficit ( 1,189,558 ) ( 1,148,080 ) | Total stockholders’ equity 1,799,273 1,274,102 | Total liabilities and stockholders’ equity $ 6,419,888 $ 4,704,968
- Total stockholders’ equity 1,799,273 1,274,102 | Total liabilities and stockholders’ equity $ 6,419,888 $ 4,704,968
- ZSCALER, INC. | Consolidated Statements of Stockholders’ Equity | (in thousands)
Antal aktier
- The aggregate market value of the common stock held by non-affiliates of the registrant, based on the closing price of a share of the registrant's common stock on January 31, 2025 (the last business day of the registrant’s most recently completed second fiscal quarter) as reported by the Nasdaq Global Select Market on such date was approximately $ 17.9 billion. | As of August 29, 2025, the number of shares of registrant’s common stock outstanding was 158,300,823 . | DOCUMENTS INCORPORATED BY REFERENCE
- Sales of substantial amounts of our common stock in the public markets, or the perception that they might occur, as well as any issuances of our common stock in connection with the conversion of the 2028 Notes or other securities convertible into shares of our common stock, could reduce the price that our common stock might otherwise attain and may dilute your voting power and your ownership interest in us. | Sales of a substantial number of shares of our common stock in the public market, particularly sales by our directors, executive officers and significant stockholders, or the perception that these sales could occur, could adversely affect the market price of our common stock and may make it more difficult for you to sell your common stock at a time and price that you deem appropriate. We may also issue our shares of common stock or securities convertible into shares of our common stock from time | We do not intend to pay dividends in the foreseeable future. As a result, your ability to achieve a return on your investment will depend on appreciation in the price of our common stock.
- Stock-based compensation for restricted stock units ("RSUs") with only service conditions is measured based on the market closing price of our common stock on the grant date. Stock-based compensation expense is recognized on a straight-line basis over the requisite service period, generally four years . | Stock-based compensation for performance stock awards (“PSAs”), which have the same grant date and service inception date, and subject to both service and performance conditions, is measured based on the probable number of shares to be attained and the market closing price of our common stock at the grant date. The expense is recognized using the accelerated attribution method over the requisite service period. For PSAs where the service inception date of the awards precedes the grant date, stoc | We account for forfeitures as they occur for all stock-based awards.
- Net Loss Per Share | Basic net loss per share is computed by dividing the net loss by the weighted-average number of shares of common stock outstanding during the period, less shares subject to repurchase. | D iluted earnings per share adjusts basic earnings per share for all potentially dilutive common stock equivalents outstanding during the period. Potentially dilutive securities consist primarily of stock options, share purchase rights under the ESPP, unvested RSUs, unvested PSAs, unvested common stock and shares related to convertible senior notes. Since we have reported net losses for all periods presented, we have excluded all potentially dilutive securities from the calculation of the dilute
- Initial Conversion Rate per $1,000 Principal Initial Conversion Price Initial Number of Shares | (in thousands)
- Equity incentive awards which may be granted to eligible participants under our Amended and Restated FY2018 Equity Incentive Plan (the "2018 Plan") include restricted stock units, restricted stock, stock options, nonstatutory stock options, stock appreciation rights, performance units and performance shares. | As of July 31, 2025, a total of 60.8 million shares of common stock have been reserved for the issuance of equity awards under the 2018 Plan, of which 35.8 million shares remained available for grant. The number of shares of common stock available for issuance under the 2018 Plan also includes an annual increase on the first day of each fiscal year through August 1, 2027, pursuant to its automatic annual increase provision. | Stock Options
- Employee Stock Purchase Plan | In fiscal 2018, we adopted the Fiscal Year 2018 Employee Stock Purchase Plan (the "ESPP"). Through July 31, 2025, a total of 11.8 million shares of common stock have been reserved for issuance under the ESPP, out of which 7.3 million shares were available for future grant as of July 31, 2025. The number of shares reserved includes an annual increase on the first day of each fiscal year pursuant to the ESPP's automatic annual increase provision. The ESPP provides for consecutive offering periods | ESPP employee payroll contributions accrued as of July 31, 2025 and 2024, were $ 9.4 million and $ 8.8 million, respectively, and are included within accrued compensation in the consolidated balance sheets. Payroll contributions accrued
- Committed unvested PSAs, based on the target number of shares 607
Antal anställda
- • beliefs about the impacts of legal developments upon our business; | • the attraction and retention of qualified employees and key personnel; and | • the future trading prices of our common stock.
- • Reduce Attack Surface: Our architecture utilizes inside out connections that are outbound from users to the Zero Trust Exchange platform, which allows customers to deny all inbound connections. This reduces their attack surface by not exposing IP addresses of all devices, applications, appliances or workloads to the internet. Reduced attack surface results in lower exposure to zero-day application vulnerabilities and eliminates the need for DDoS mitigation. | • Browser Isolation: Our cloud browser isolation is used with our ZPA solution to provide isolated sessions to internal web applications without allowing data to transfer down to unmanaged devices or active content to be uploaded into sensitive internal applications. Combining cloud browser isolation with browser-based access provides a simplified, more cost-effective alternative to VDI for employees, contractors and B2B partners, by effectively keeping sensitive data off unmanaged devices. | The primary use cases for our ZPA solution include:
- • deliver user-to-application segmentation, thus eliminating the risk of lateral threat propagation enabled by legacy Firewall and VPN based security architecture; | • providing non-employees with secure access to internal applications; | • securely connecting B2B customers, service providers and supplier access to applications typically deployed as B2B portals in an extranet;
- • GenAI Security: Our GenAI security offerings provide enterprises with comprehensive visibility and control over generative AI tool usage to prevent data loss while enabling productivity benefits. Our solution allows organizations to create and enforce policies around which generative AI tools users can access and how they interact with them, including through secure browser isolation to protect sensitive data. The platform delivers granular controls including prompt-level visibility, AI/ML-bas | • Zscaler AI Guard for Users: Our Zscaler AI Guard for Users secures the prompts and responses between employees of our customers and public GenAI applications. AI Guard enforces policies on prompts and responses to protect against toxicity, prompt injection, code sharing, sensitive-data leakage and other adversarial attacks. In addition, AI Guard provides granular visibility into prompts, responses and log events, including the associated metadata, for consumption and analysis by security opera | 10
- Intellectual Property | Our success depends in part upon our ability to protect and use our core technology and intellectual property rights. We rely on a combination of patents, copyrights, trademarks, trade secret laws, contractual provisions and confidentiality procedures to protect our intellectual property rights. As of July 31, 2025, we had more than 725 issued patents and pending patent applications, including more than 325 issued patents in the United States and other countries. Our issued patents expire betwee | Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation based on allegations of patent infringement or other violations of intellectual property rights. We believe that competitors will try to develop products and services that are similar to ours and that may infringe our intellectual property rights. Our competitors or other third-parties may also claim that our platform infringes their intellectual property rights. In particular,
- Human Capital | As of July 31, 2025, we had a total of 7,923 employees in locations around the world. We have not experienced any work stoppages and we consider our relations with our employees to be positive and collaborative. | Zscaler's vision is to create a world in which the exchange of information is always secure and seamless. Specifically, ensuring that our people and culture are aligned with this vision is critical to our success. In order to continue to innovate and to execute our business strategy, we must attract, develop and retain skilled employees, particularly in the areas of product development, engineering, sales and customer success.
- As of July 31, 2025, we had a total of 7,923 employees in locations around the world. We have not experienced any work stoppages and we consider our relations with our employees to be positive and collaborative. | Zscaler's vision is to create a world in which the exchange of information is always secure and seamless. Specifically, ensuring that our people and culture are aligned with this vision is critical to our success. In order to continue to innovate and to execute our business strategy, we must attract, develop and retain skilled employees, particularly in the areas of product development, engineering, sales and customer success. | Our Culture
- • Customer Obsession | We build this culture through the feedback we receive from our employees through company-wide surveys as well as informal feedback channels throughout the year. We ultimately view and measure the success of our culture by our ability to sustain great business results. | Employee Development
Bruttomarginal
- • the impact of macroeconomic and geopolitical events, developments and conditions on our business; | • our future financial performance, including our expectations regarding our revenue, cost of revenue, gross profit or gross margin, operating expenses (including changes in sales and marketing, research and development and general and administrative expenses) and our ability to achieve, and maintain, future profitability; | • market acceptance of our cloud platform;
- In addition to our results determined in accordance with GAAP, we believe the following non-GAAP measures are useful in evaluating our operating performance. We use the following non-GAAP financial information to evaluate our ongoing operations and for internal planning and forecasting purposes. We believe that non-GAAP financial information, when taken collectively, may be helpful to investors because it provides consistency and comparability with past financial performance. However, non-GAAP f | Non-GAAP Gross Profit and Non-GAAP Gross Margin | We define non-GAAP gross profit as GAAP gross profit excluding stock-based compensation expense and related payroll taxes, amortization expense of acquired intangible assets and restructuring and other charges. We define non-GAAP gross margin as non-GAAP gross profit as a percentage of revenue.
- Non-GAAP Gross Profit and Non-GAAP Gross Margin | We define non-GAAP gross profit as GAAP gross profit excluding stock-based compensation expense and related payroll taxes, amortization expense of acquired intangible assets and restructuring and other charges. We define non-GAAP gross margin as non-GAAP gross profit as a percentage of revenue.
- Non-GAAP gross profit $ 2,141,048 $ 1,756,287 $ 1,303,991 | GAAP gross margin 77 % 78 % 78 % | Non-GAAP gross margin
- GAAP gross margin 77 % 78 % 78 % | Non-GAAP gross margin | 80 % 81 % 81 %
- As our customers expand and increase the use of our cloud platform driven by additional applications and connected devices, our cost of revenue will increase due to higher bandwidth and data center expenses. However, we expect to continue to benefit from economies of scale as our customers increase the use of our cloud platform. We intend to continue to invest additional resources in our cloud platform and our customer support organizations as we grow our business. The level and timing of invest | Gross Profit and Gross Margin | Gross profit, or revenue less cost of revenue, and gross margin, or gross profit as a percentage of revenue, have been and will continue to be affected by various factors, including the timing of our acquisition of new customers and our renewals of and follow-on sales to existing customers, the average sales price of our services, mix of services offered in our solutions, including new product introductions, the data center and bandwidth costs associated with operating our cloud platform, the ex
- Gross Profit and Gross Margin | Gross profit, or revenue less cost of revenue, and gross margin, or gross profit as a percentage of revenue, have been and will continue to be affected by various factors, including the timing of our acquisition of new customers and our renewals of and follow-on sales to existing customers, the average sales price of our services, mix of services offered in our solutions, including new product introductions, the data center and bandwidth costs associated with operating our cloud platform, the ex | Operating Expenses
- Cost of revenue 23 22 22 | Gross margin 77 78 78 | Operating expenses
Fulltext
Dokumentet är delat för att hålla varje sida lätt att hämta. Del 1 · Del 2 · Del 3
zs-20250731 0001713683 2025 FY false http://fasb.org/us-gaap/2025#AccountingStandardsUpdate202006Member P1Y P3Y P4Y P3Y P1Y P1M http://fasb.org/us-gaap/2025#CostOfRevenue http://fasb.org/us-gaap/2025#CostOfRevenue http://fasb.org/us-gaap/2025#SellingAndMarketingExpense http://fasb.org/us-gaap/2025#SellingAndMarketingExpense http://fasb.org/us-gaap/2025#ResearchAndDevelopmentExpense http://fasb.org/us-gaap/2025#ResearchAndDevelopmentExpense http://fasb.org/us-gaap/2025#GeneralAndAdministrativeExpense http://fasb.org/us-gaap/2025#GeneralAndAdministrativeExpense 0.0022 1 1 454 iso4217:USD xbrli:shares xbrli:pure iso4217:USD xbrli:shares zs:segment zs:trading_day utr:sqft zs:period zs:vote 0001713683 2024-08-01 2025-07-31 0001713683 2025-01-31 0001713683 2025-08-29 0001713683 zs:SubscriptionAndSupportMember us-gaap:ProductConcentrationRiskMember us-gaap:SalesRevenueNetMember us-gaap:TransferredOverTimeMember 2024-08-01 2025-07-31 0001713683 2025-07-31 0001713683 2024-07-31 0001713683 2023-08-01 2024-07-31 0001713683 2022-08-01 2023-07-31 0001713683 us-gaap:CommonStockMember 2022-07-31 0001713683 us-gaap:AdditionalPaidInCapitalMember 2022-07-31 0001713683 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2022-07-31 0001713683 us-gaap:RetainedEarningsMember 2022-07-31 0001713683 2022-07-31 0001713683 2021-08-01 2022-07-31 0001713683 srt:CumulativeEffectPeriodOfAdoptionAdjustmentMember us-gaap:AdditionalPaidInCapitalMember 2022-07-31 0001713683 srt:CumulativeEffectPeriodOfAdoptionAdjustmentMember us-gaap:RetainedEarningsMember 2022-07-31 0001713683 srt:CumulativeEffectPeriodOfAdoptionAdjustmentMember 2022-07-31 0001713683 us-gaap:CommonStockMember 2022-08-01 2023-07-31 0001713683 us-gaap:AdditionalPaidInCapitalMember 2022-08-01 2023-07-31 0001713683 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2022-08-01 2023-07-31 0001713683 us-gaap:RetainedEarningsMember 2022-08-01 2023-07-31 0001713683 us-gaap:CommonStockMember 2023-07-31 0001713683 us-gaap:AdditionalPaidInCapitalMember 2023-07-31 0001713683 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2023-07-31 0001713683 us-gaap:RetainedEarningsMember 2023-07-31 0001713683 2023-07-31 0001713683 us-gaap:CommonStockMember 2023-08-01 2024-07-31 0001713683 us-gaap:AdditionalPaidInCapitalMember 2023-08-01 2024-07-31 0001713683 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2023-08-01 2024-07-31 0001713683 us-gaap:RetainedEarningsMember 2023-08-01 2024-07-31 0001713683 us-gaap:CommonStockMember 2024-07-31 0001713683 us-gaap:AdditionalPaidInCapitalMember 2024-07-31 0001713683 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2024-07-31 0001713683 us-gaap:RetainedEarningsMember 2024-07-31 0001713683 us-gaap:CommonStockMember 2024-08-01 2025-07-31 0001713683 us-gaap:AdditionalPaidInCapitalMember 2024-08-01 2025-07-31 0001713683 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2024-08-01 2025-07-31 0001713683 us-gaap:RetainedEarningsMember 2024-08-01 2025-07-31 0001713683 us-gaap:CommonStockMember 2025-07-31 0001713683 us-gaap:AdditionalPaidInCapitalMember 2025-07-31 0001713683 us-gaap:AccumulatedOtherComprehensiveIncomeMember 2025-07-31 0001713683 us-gaap:RetainedEarningsMember 2025-07-31 0001713683 srt:MinimumMember 2024-08-01 2025-07-31 0001713683 srt:MaximumMember 2024-08-01 2025-07-31 0001713683 srt:MinimumMember 2025-07-31 0001713683 srt:MaximumMember 2025-07-31 0001713683 zs:ServersAndNetworkingEquipmentMember 2023-07-31 0001713683 zs:ServersAndNetworkingEquipmentMember 2023-10-31 0001713683 zs:LongLivedTangibleAssetsAmortizationPeriodMember zs:ServersAndNetworkingEquipmentMember 2023-08-01 2024-07-31 0001713683 srt:MinimumMember us-gaap:SoftwareDevelopmentMember 2025-07-31 0001713683 srt:MaximumMember us-gaap:SoftwareDevelopmentMember 2025-07-31 0001713683 zs:SubscriptionAndSupportMember us-gaap:ProductConcentrationRiskMember us-gaap:SalesRevenueNetMember us-gaap:TransferredOverTimeMember 2023-08-01 2024-07-31 0001713683 zs:SubscriptionAndSupportMember us-gaap:ProductConcentrationRiskMember us-gaap:SalesRevenueNetMember us-gaap:TransferredOverTimeMember 2022-08-01 2023-07-31 0001713683 country:US us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001713683 country:US us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2023-08-01 2024-07-31 0001713683 country:US us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2022-08-01 2023-07-31 0001713683 us-gaap:EMEAMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001713683 us-gaap:EMEAMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2023-08-01 2024-07-31 0001713683 us-gaap:EMEAMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2022-08-01 2023-07-31 0001713683 srt:AsiaPacificMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001713683 srt:AsiaPacificMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2023-08-01 2024-07-31 0001713683 srt:AsiaPacificMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2022-08-01 2023-07-31 0001713683 zs:OtherMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001713683 zs:OtherMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2023-08-01 2024-07-31 0001713683 zs:OtherMember us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2022-08-01 2023-07-31 0001713683 us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001713683 us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2023-08-01 2024-07-31 0001713683 us-gaap:GeographicConcentrationRiskMember us-gaap:SalesRevenueNetMember 2022-08-01 2023-07-31 0001713683 zs:ChannelPartnersMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001713683 zs:ChannelPartnersMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2023-08-01 2024-07-31 0001713683 zs:ChannelPartnersMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2022-08-01 2023-07-31 0001713683 zs:DirectCustomersMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001713683 zs:DirectCustomersMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2023-08-01 2024-07-31 0001713683 zs:DirectCustomersMember us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2022-08-01 2023-07-31 0001713683 us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2024-08-01 2025-07-31 0001713683 us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2023-08-01 2024-07-31 0001713683 us-gaap:CustomerConcentrationRiskMember us-gaap:SalesRevenueNetMember 2022-08-01 2023-07-31 0001713683 zs:ChannelPartnerAMember us-gaap:CustomerConcentrationRiskMember us-gaap:AccountsReceivableMember 2024-08-01 2025-07-31 0001713683 2025-08-01 2025-07-31 0001713683 2026-08-01 2025-07-31 0001713683 us-gaap:MoneyMarketFundsMember 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember 2025-07-31 0001713683 us-gaap:CertificatesOfDepositMember 2025-07-31 0001713683 us-gaap:USTreasurySecuritiesMember 2025-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember 2025-07-31 0001713683 us-gaap:MoneyMarketFundsMember 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember 2024-07-31 0001713683 us-gaap:CertificatesOfDepositMember 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember 2024-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember 2024-07-31 0001713683 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001713683 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001713683 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001713683 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001713683 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001713683 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001713683 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001713683 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001713683 us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001713683 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001713683 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001713683 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2025-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:DesignatedAsHedgingInstrumentMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member us-gaap:DesignatedAsHedgingInstrumentMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member us-gaap:DesignatedAsHedgingInstrumentMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member us-gaap:DesignatedAsHedgingInstrumentMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:NondesignatedMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member us-gaap:NondesignatedMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member us-gaap:NondesignatedMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member us-gaap:NondesignatedMember 2025-07-31 0001713683 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001713683 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001713683 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001713683 us-gaap:MoneyMarketFundsMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001713683 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001713683 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001713683 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001713683 us-gaap:CertificatesOfDepositMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001713683 us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001713683 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001713683 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001713683 us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001713683 us-gaap:USTreasurySecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001713683 us-gaap:USGovernmentAgenciesDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember 2024-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member 2024-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member 2024-07-31 0001713683 us-gaap:CorporateDebtSecuritiesMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:InterestRateContractMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:InterestRateContractMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:InterestRateContractMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:InterestRateContractMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:NondesignatedMember 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel1Member us-gaap:NondesignatedMember 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel2Member us-gaap:NondesignatedMember 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:FairValueMeasurementsRecurringMember us-gaap:FairValueInputsLevel3Member us-gaap:NondesignatedMember 2024-07-31 0001713683 srt:MinimumMember zs:HostingEquipmentMember 2025-07-31 0001713683 srt:MaximumMember zs:HostingEquipmentMember 2025-07-31 0001713683 zs:HostingEquipmentMember 2025-07-31 0001713683 zs:HostingEquipmentMember 2024-07-31 0001713683 us-gaap:SoftwareDevelopmentMember 2025-07-31 0001713683 us-gaap:SoftwareDevelopmentMember 2024-07-31 0001713683 srt:MinimumMember zs:ComputerandOfficeEquipmentMember 2025-07-31 0001713683 srt:MaximumMember zs:ComputerandOfficeEquipmentMember 2025-07-31 0001713683 zs:ComputerandOfficeEquipmentMember 2025-07-31 0001713683 zs:ComputerandOfficeEquipmentMember 2024-07-31 0001713683 us-gaap:SoftwareAndSoftwareDevelopmentCostsMember 2025-07-31 0001713683 us-gaap:SoftwareAndSoftwareDevelopmentCostsMember 2024-07-31 0001713683 us-gaap:FurnitureAndFixturesMember 2025-07-31 0001713683 us-gaap:FurnitureAndFixturesMember 2024-07-31 0001713683 us-gaap:LeaseholdImprovementsMember 2025-07-31 0001713683 us-gaap:LeaseholdImprovementsMember 2024-07-31 0001713683 zs:InternetProtocolAddressesMember 2025-07-31 0001713683 zs:InternetProtocolAddressesMember 2024-07-31 0001713683 us-gaap:SoftwareDevelopmentMember 2024-08-01 2025-07-31 0001713683 us-gaap:SoftwareDevelopmentMember 2023-08-01 2024-07-31 0001713683 us-gaap:SoftwareDevelopmentMember 2022-08-01 2023-07-31 0001713683 zs:AirgapNetworksInc.Member 2024-04-12 2024-04-12 0001713683 zs:AirgapNetworksInc.Member 2024-04-12 0001713683 zs:AirgapNetworksInc.Member us-gaap:DevelopedTechnologyRightsMember 2024-04-12 0001713683 zs:AirgapNetworksInc.Member us-gaap:CustomerRelationshipsMember 2024-04-12 0001713683 zs:AirgapNetworksInc.Member us-gaap:DevelopedTechnologyRightsMember 2024-04-12 2024-04-12 0001713683 zs:AirgapNetworksInc.Member us-gaap:CustomerRelationshipsMember 2024-04-12 2024-04-12 0001713683 zs:AvalorTechnologiesLtd.Member 2024-03-08 2024-03-08 0001713683 zs:AvalorTechnologiesLtd.Member 2024-03-08 0001713683 zs:AvalorTechnologiesLtd.Member us-gaap:DevelopedTechnologyRightsMember 2024-03-08 0001713683 zs:AvalorTechnologiesLtd.Member us-gaap:CustomerRelationshipsMember 2024-03-08 0001713683 zs:AvalorTechnologiesLtd.Member us-gaap:DevelopedTechnologyRightsMember 2024-03-08 2024-03-08 0001713683 zs:AvalorTechnologiesLtd.Member us-gaap:CustomerRelationshipsMember 2024-03-08 2024-03-08 0001713683 zs:CanonicSecurityTechnologiesLtdMember 2023-02-20 2023-02-20 0001713683 zs:CanonicSecurityTechnologiesLtdMember 2023-02-20 0001713683 zs:CanonicSecurityTechnologiesLtdMember us-gaap:DevelopedTechnologyRightsMember 2023-02-20 0001713683 zs:CanonicSecurityTechnologiesLtdMember us-gaap:DevelopedTechnologyRightsMember 2023-02-20 2023-02-20 0001713683 us-gaap:SeriesOfIndividuallyImmaterialBusinessAcquisitionsMember 2024-12-01 2024-12-31 0001713683 us-gaap:SeriesOfIndividuallyImmaterialBusinessAcquisitionsMember 2023-08-01 2023-08-31 0001713683 us-gaap:SeriesOfIndividuallyImmaterialBusinessAcquisitionsMember 2024-12-31 0001713683 us-gaap:SeriesOfIndividuallyImmaterialBusinessAcquisitionsMember 2023-08-31 0001713683 zs:FidentyB.V.Member us-gaap:DevelopedTechnologyRightsMember 2025-07-31 0001713683 zs:FidentyB.V.Member us-gaap:DevelopedTechnologyRightsMember 2024-08-01 2025-07-31 0001713683 us-gaap:DevelopedTechnologyRightsMember 2024-07-31 0001713683 us-gaap:DevelopedTechnologyRightsMember 2024-08-01 2025-07-31 0001713683 us-gaap:DevelopedTechnologyRightsMember 2025-07-31 0001713683 us-gaap:CustomerRelationshipsMember 2024-07-31 0001713683 us-gaap:CustomerRelationshipsMember 2024-08-01 2025-07-31 0001713683 us-gaap:CustomerRelationshipsMember 2025-07-31 0001713683 us-gaap:DevelopedTechnologyRightsMember 2023-08-01 2024-07-31 0001713683 us-gaap:CustomerRelationshipsMember 2023-08-01 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:NondesignatedMember srt:MinimumMember 2024-08-01 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:NondesignatedMember srt:MaximumMember 2024-08-01 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:DesignatedAsHedgingInstrumentMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:DesignatedAsHedgingInstrumentMember 2024-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:NondesignatedMember 2025-07-31 0001713683 us-gaap:ForeignExchangeForwardMember us-gaap:NondesignatedMember 2024-07-31 0001713683 us-gaap:AccumulatedGainLossNetCashFlowHedgeParentMember 2024-07-31 0001713683 us-gaap:AccumulatedGainLossNetCashFlowHedgeParentMember 2023-07-31 0001713683 us-gaap:AccumulatedGainLossNetCashFlowHedgeParentMember 2022-07-31 0001713683 us-gaap:AccumulatedGainLossNetCashFlowHedgeParentMember 2025-07-31 0001713683 us-gaap:CostOfSalesMember 2024-08-01 2025-07-31 0001713683 us-gaap:CostOfSalesMember 2023-08-01 2024-07-31 0001713683 us-gaap:CostOfSalesMember 2022-08-01 2023-07-31 0001713683 us-gaap:SellingAndMarketingExpenseMember 2024-08-01 2025-07-31 0001713683 us-gaap:SellingAndMarketingExpenseMember 2023-08-01 2024-07-31 0001713683 us-gaap:SellingAndMarketingExpenseMember 2022-08-01 2023-07-31 0001713683 us-gaap:ResearchAndDevelopmentExpenseMember 2024-08-01 2025-07-31 0001713683 us-gaap:ResearchAndDevelopmentExpenseMember 2023-08-01 2024-07-31 0001713683 us-gaap:ResearchAndDevelopmentExpenseMember 2022-08-01 2023-07-31 0001713683 us-gaap:GeneralAndAdministrativeExpenseMember 2024-08-01 2025-07-31 0001713683 us-gaap:GeneralAndAdministrativeExpenseMember 2023-08-01 2024-07-31 0001713683 us-gaap:GeneralAndAdministrativeExpenseMember 2022-08-01 2023-07-31 0001713683 us-gaap:LongTermDebtMember 2024-07-31 0001713683 us-gaap:InterestRateSwapMember 2024-07-31 0001713683 us-gaap:InterestRateContractMember 2024-08-01 2025-07-31 0001713683 us-gaap:InterestRateContractMember 2023-08-01 2024-07-31 0001713683 us-gaap:InterestRateContractMember 2022-08-01 2023-07-31 0001713683 zs:RestructuringPlan2023Member 2022-08-01 2023-07-31 0001713683 zs:ConvertibleSeniorNotesDue2028Member 2025-07-03 0001713683 zs:ConvertibleSeniorNotesTwoTwentyFiveMillionMember 2025-07-03 0001713683 zs:ConvertibleSeniorNotesDue2028Member 2025-07-03 2025-07-03 0001713683 zs:ConvertibleSeniorNotesDue2028Member 2025-07-31 0001713683 zs:ConvertibleSeniorNotesDue2025Member 2020-06-25 0001713683 zs:ConvertibleSeniorNotesOneHundredFiftyMillionMember 2020-06-25 0001713683 zs:ConvertibleSeniorNotesDue2025Member 2020-06-25 2020-06-25 0001713683 zs:ConvertibleSeniorNotesDue2025Member 2025-07-31 0001713683 zs:ConvertibleSeniorNotesDue2025Member 2024-07-31 0001713683 zs:ConvertibleSeniorNotesDue2028Member 2024-08-01 2025-07-31 0001713683 zs:ConvertibleSeniorNotesDue2025Member 2024-08-01 2025-07-31 0001713683 us-gaap:BuildingMember 2024-08-01 2025-07-31 0001713683 zs:CoLocationArrangementsMember 2024-08-01 2025-07-31 0001713683 us-gaap:BuildingMember 2023-08-01 2024-07-31 0001713683 zs:CoLocationArrangementsMember 2023-08-01 2024-07-31 0001713683 us-gaap:BuildingMember 2022-08-01 2023-07-31 0001713683 zs:CoLocationArrangementsMember 2022-08-01 2023-07-31 0001713683 us-gaap:BuildingMember 2025-07-31 0001713683 zs:CoLocationArrangementsMember 2025-07-31 0001713683 us-gaap:BuildingMember 2024-07-31 0001713683 zs:CoLocationArrangementsMember 2024-07-31 0001713683 us-gaap:BuildingMember 2023-07-31 0001713683 zs:CoLocationArrangementsMember 2023-07-31 0001713683 2025-04-29 0001713683 zs:FiscalYear2018EquityIncentivePlanMember us-gaap:CommonStockMember 2025-07-31 0001713683 srt:MinimumMember us-gaap:EmployeeStockOptionMember 2024-08-01 2025-07-31 0001713683 srt:MaximumMember us-gaap:EmployeeStockOptionMember 2024-08-01 2025-07-31 0001713683 us-gaap:EmployeeStockOptionMember 2023-08-01 2024-07-31 0001713683 us-gaap:EmployeeStockOptionMember 2022-08-01 2023-07-31 0001713683 us-gaap:EmployeeStockOptionMember 2024-08-01 2025-07-31 0001713683 us-gaap:RestrictedStockUnitsRSUMember 2024-08-01 2025-07-31 0001713683 us-gaap:PerformanceSharesMember 2025-07-31 0001713683 zs:RestrictedStockUnitsAndPerformanceStockAwardsMember 2024-07-31 0001713683 zs:RestrictedStockUnitsAndPerformanceStockAwardsMember 2024-08-01 2025-07-31 0001713683 zs:RestrictedStockUnitsAndPerformanceStockAwardsMember 2025-07-31 0001713683 zs:RestrictedStockUnitsAndPerformanceStockAwardsMember 2023-08-01 2024-07-31 0001713683 zs:RestrictedStockUnitsAndPerformanceStockAwardsMember 2022-08-01 2023-07-31 0001713683 zs:EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2025-07-31 0001713683 zs:EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2024-08-01 2025-07-31 0001713683 zs:EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2023-08-01 2024-07-31 0001713683 zs:EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2022-08-01 2023-07-31 0001713683 zs:EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2024-07-31 0001713683 zs:EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2023-07-31 0001713683 zs:EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2024-06-01 2024-06-30 0001713683 us-gaap:EmployeeStockMember srt:MaximumMember zs:EmployeeStockPurchasePlanMember 2024-06-01 2024-06-30 0001713683 zs:EmployeeStockPurchasePlanMember us-gaap:EmployeeStockMember 2022-12-01 2022-12-31 0001713683 us-gaap:EmployeeStockMember srt:MinimumMember zs:EmployeeStockPurchasePlanMember 2022-12-01 2022-12-31 0001713683 us-gaap:EmployeeStockMember srt:MaximumMember zs:EmployeeStockPurchasePlanMember 2022-12-01 2022-12-31 0001713683 srt:MinimumMember us-gaap:EmployeeStockMember 2024-08-01 2025-07-31 0001713683 srt:MaximumMember us-gaap:EmployeeStockMember 2024-08-01 2025-07-31 0001713683 srt:MinimumMember us-gaap:EmployeeStockMember 2023-08-01 2024-07-31 0001713683 srt:MaximumMember us-gaap:EmployeeStockMember 2023-08-01 2024-07-31 0001713683 srt:MinimumMember us-gaap:EmployeeStockMember 2022-08-01 2023-07-31 0001713683 srt:MaximumMember us-gaap:EmployeeStockMember 2022-08-01 2023-07-31 0001713683 us-gaap:EmployeeStockMember 2024-08-01 2025-07-31 0001713683 us-gaap:EmployeeStockMember 2023-08-01 2024-07-31 0001713683 us-gaap:EmployeeStockMember 2022-08-01 2023-07-31 0001713683 2025-05-01 2025-07-31 0001713683 us-gaap:ResearchAndDevelopmentExpenseMember 2025-05-01 2025-07-31 0001713683 us-gaap:SellingGeneralAndAdministrativeExpensesMember 2025-05-01 2025-07-31 0001713683 srt:ChiefExecutiveOfficerMember 2024-08-01 2025-07-31 0001713683 us-gaap:SellingAndMarketingExpenseMember srt:ChiefExecutiveOfficerMember 2024-08-01 2025-07-31 0001713683 us-gaap:ResearchAndDevelopmentExpenseMember srt:ChiefExecutiveOfficerMember 2024-08-01 2025-07-31 0001713683 us-gaap:SellingGeneralAndAdministrativeExpensesMember srt:ChiefExecutiveOfficerMember 2024-08-01 2025-07-31 0001713683 srt:ChiefOperatingOfficerMember 2024-02-01 2024-02-29 0001713683 srt:PresidentMember 2022-10-01 2022-10-31 0001713683 us-gaap:EmployeeStockOptionMember 2025-07-31 0001713683 us-gaap:RestrictedStockUnitsRSUMember 2025-07-31 0001713683 zs:CommittedPerformanceStockAwardsBasedOnTargetNumberOfSharesMember 2025-07-31 0001713683 us-gaap:EmployeeStockMember 2025-07-31 0001713683 us-gaap:StockCompensationPlanMember 2025-07-31 0001713683 us-gaap:ConvertibleDebtSecuritiesMember 2025-07-31 0001713683 zs:BusinessCombinationDeferredTaxesMember 2023-08-01 2024-07-31 0001713683 zs:BusinessCombinationDeferredTaxesMember 2022-08-01 2023-07-31 0001713683 us-gaap:DomesticCountryMember 2025-07-31 0001713683 us-gaap:StateAndLocalJurisdictionMember 2025-07-31 0001713683 us-gaap:ForeignCountryMember 2025-07-31 0001713683 us-gaap:DomesticCountryMember us-gaap:ResearchMember 2025-07-31 0001713683 us-gaap:StateAndLocalJurisdictionMember us-gaap:ResearchMember 2025-07-31 0001713683 us-gaap:ForeignCountryMember us-gaap:ResearchMember 2025-07-31 0001713683 us-gaap:RestrictedStockUnitsRSUMember 2024-08-01 2025-07-31 0001713683 us-gaap:RestrictedStockUnitsRSUMember 2023-08-01 2024-07-31 0001713683 us-gaap:RestrictedStockUnitsRSUMember 2022-08-01 2023-07-31 0001713683 us-gaap:EmployeeStockOptionMember 2024-08-01 2025-07-31 0001713683 us-gaap:EmployeeStockOptionMember 2023-08-01 2024-07-31 0001713683 us-gaap:EmployeeStockOptionMember 2022-08-01 2023-07-31 0001713683 us-gaap:PerformanceSharesMember 2024-08-01 2025-07-31 0001713683 us-gaap:PerformanceSharesMember 2023-08-01 2024-07-31 0001713683 us-gaap:PerformanceSharesMember 2022-08-01 2023-07-31 0001713683 us-gaap:StockCompensationPlanMember 2024-08-01 2025-07-31 0001713683 us-gaap:StockCompensationPlanMember 2023-08-01 2024-07-31 0001713683 us-gaap:StockCompensationPlanMember 2022-08-01 2023-07-31 0001713683 us-gaap:ConvertibleDebtSecuritiesMember zs:ConvertibleSeniorNotesDue2028Member 2024-08-01 2025-07-31 0001713683 us-gaap:ConvertibleDebtSecuritiesMember zs:ConvertibleSeniorNotesDue2028Member 2023-08-01 2024-07-31 0001713683 us-gaap:ConvertibleDebtSecuritiesMember zs:ConvertibleSeniorNotesDue2028Member 2022-08-01 2023-07-31 0001713683 us-gaap:ConvertibleDebtSecuritiesMember zs:ConvertibleSeniorNotesDue2025Member 2024-08-01 2025-07-31 0001713683 us-gaap:ConvertibleDebtSecuritiesMember zs:ConvertibleSeniorNotesDue2025Member 2023-08-01 2024-07-31 0001713683 us-gaap:ConvertibleDebtSecuritiesMember zs:ConvertibleSeniorNotesDue2025Member 2022-08-01 2023-07-31 0001713683 us-gaap:PerformanceSharesMember 2025-07-31 0001713683 zs:ReportableSegmentMember 2024-08-01 2025-07-31 0001713683 zs:ReportableSegmentMember 2023-08-01 2024-07-31 0001713683 zs:ReportableSegmentMember 2022-08-01 2023-07-31 0001713683 country:US 2025-07-31 0001713683 country:US 2024-07-31 0001713683 us-gaap:NonUsMember 2025-07-31 0001713683 us-gaap:NonUsMember 2024-07-31 0001713683 srt:ScenarioForecastMember zs:RedCanaryIncMember 2025-08-01 2025-10-31 0001713683 zs:RobertSchlossmanMember 2025-05-01 2025-07-31 0001713683 zs:RobertSchlossmanMember 2025-07-31 UNITED STATES SECURITIES AND EXCHANGE COMMISSION WASHINGTON, D.C. 20549 _____________________________________ FORM 10-K _____________________________________ (Mark One) ☒ ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 For the fiscal year ended July 31 , 2025 OR ☐ TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 For the transition period from _ to _ Commission File Number: 001-38413 _____________________________________ ZSCALER, INC. (Exact Name of Registrant as Specified in Its Charter) _____________________________________ Delaware (State or other jurisdiction of incorporation or organization) 26-1173892 (I.R.S. Employer Identification Number) 120 Holger Way San Jose , California 95134 (Address of principal executive offices) Registrant’s telephone number, including area code: ( 408 ) 533-0288 Securities registered pursuant to Section 12(b) of the Act: Title of each class Trading Symbol(s) Name of each exchange on which registered Common Stock, $0.001 Par Value ZS The Nasdaq Stock Market LLC Securities registered pursuant to Section 12(g) of the Act: None ___________________________________________________ Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act of 1933, as amended. Yes ☒ No ☐ Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒ Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐ Indicate by check mark whether the registrant has submitted electronically, every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files) Yes ☒ No ☐ Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of "large accelerated filer," "accelerated filer," "smaller reporting company" and "emerging growth company" in Rule 12b-2 of the Exchange Act. Large accelerated filer ☒ Accelerated filer ☐ Non-accelerated filer ☐ Smaller reporting company ☐ Emerging growth company ☐ If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐ Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒ If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐ Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant's executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐ Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒ The aggregate market value of the common stock held by non-affiliates of the registrant, based on the closing price of a share of the registrant's common stock on January 31, 2025 (the last business day of the registrant’s most recently completed second fiscal quarter) as reported by the Nasdaq Global Select Market on such date was approximately $ 17.9 billion. As of August 29, 2025, the number of shares of registrant’s common stock outstanding was 158,300,823 . DOCUMENTS INCORPORATED BY REFERENCE Portions of the registrant’s definitive Proxy Statement relating to its fiscal year 2025 Annual Meeting of Stockholders are incorporated by reference into Part III of this Form 10-K where indicated. Such Proxy Statement will be filed with the United States Securities and Exchange Commission within 120 days after the end of the fiscal year to which this Annual Report on Form 10-K relates. ZSCALER, INC. TABLE OF CONTENTS Page PART I Item 1. Business 3 Item 1A. Risk Factors 20 Item 1B. Unresolved Staff Comments 58 Item 1C. Cybersecurity 58 Item 2. Properties 59 Item 3. Legal Proceedings 59 Item 4. Mine Safety Disclosures 59 PART II Item 5. Market for Registrant's Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities 60 Item 6. Reserved 62 Item 7. Management's Discussion and Analysis of Financial Condition and Results of Operations 63 Item 7A. Quantitative and Qualitative Disclosures about Market Risk 85 Item 8. Financial Statements and Supplementary Data 86 Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure 139 Item 9A. Controls and Procedures 139 Item 9B. Other Information 140 Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 140 PART III Item 10. Directors, Executive Officers and Corporate Governance 141 Item 11. Executive Compensation 141 Item 12. Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters 141 Item 13. Certain Relationships and Related Transactions and Director Independence 141 Item 14. Principal Accountant Fees and Services 141 PART IV Item 15. Exhibits, Financial Statement Schedules 142 Item 16. Form 10-K Summary 144 Signatures Table of Contents SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS This Annual Report on Form 10-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including but not limited to, statements regarding our financial outlook and market positioning. These forward-looking statements are made as of the date they were first issued and were based on current expectations, estimates, forecasts and projections as well as the beliefs and assumptions of management. The words "believe," "may," "will," "potentially," "estimate," "continue," "anticipate," "intend," "could," "would," "project," "plan," "expect" and similar expressions that convey uncertainty of future events or outcomes are intended to identify forward-looking statements. These forward-looking statements include, but are not limited to, statements concerning the following: • the impact of macroeconomic and geopolitical events, developments and conditions on our business; • our future financial performance, including our expectations regarding our revenue, cost of revenue, gross profit or gross margin, operating expenses (including changes in sales and marketing, research and development and general and administrative expenses) and our ability to achieve, and maintain, future profitability; • market acceptance of our cloud platform; • the effects of increased competition in our markets and our ability to compete effectively; • our ability to maintain the security and availability of our cloud platform; • our ability to maintain and expand our customer base, including by attracting new customers; • our ability to develop new solutions or enhancements to our existing solutions, including artificial intelligence and machine learning capabilities, and bring them to market in a timely manner; • market acceptance of any new solutions or enhancements to our existing solutions; • anticipated trends, growth rates and challenges in our business and in the markets in which we operate; • our business plan and our ability to effectively manage our growth and associated investments; • beliefs about and objectives for future operations; • beliefs about and objectives for future acquisitions, strategic investments, partnerships and alliances and our ability to successfully integrate completed acquisitions; • our relationships with third parties, including channel partners; • our ability to maintain, protect and enhance our intellectual property rights; • our ability to successfully defend litigation brought against us; • our ability to successfully expand in our existing markets and into new markets; • sufficiency of cash to meet cash needs for at least the next 12 months and service our outstanding debt; • our need and ability to raise additional capital in future debt or equity financings; • our expectations regarding settlement of the 2028 Notes (as defined in Note 10, Convertible Senior Notes to the consolidated financial statements included elsewhere in this Annual Report on Form 10-K ); 1 Table of Contents • our ability to comply with laws and regulations, including tariffs and trade regulations, that currently apply or become applicable to our business both in the United States and internationally; • beliefs about the impacts of legal developments upon our business; • the attraction and retention of qualified employees and key personnel; and • the future trading prices of our common stock. These forward-looking statements are subject to a number of risks, uncertainties and assumptions, including those described in "Risk Factors" elsewhere in this Annual Report on Form 10-K. Moreover, we operate in a very competitive and rapidly changing environment, and new risks emerge from time to time. It is not possible for our management to predict all risks, nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ materially from those contained in any forward-looking statements we may make. In light of these risks, uncertainties and assumptions, the forward-looking events and circumstances discussed in this Annual Report on Form 10-K may not occur and actual results could differ materially and adversely from those anticipated or implied in the forward-looking statements and you should not place undue reliance on our forward-looking statements. The forward-looking statements made in this Annual Report on Form 10-K relate only to events as of the date on which the statements are made. We undertake no obligation to update any forward-looking statements made in this Annual Report on Form 10-K to reflect events or circumstances after the date of this Annual Report on Form 10-K or to reflect new information or the occurrence of unanticipated events, except as required by law. 2 Table of Contents PART I Item 1. Business Overview We enable our customers to succeed in a digital world where technology decisions not only impact growth and competitiveness, but also directly impact enterprise risk. We were incorporated in 2007, during the early stages of cloud adoption and mobility, based on a vision that the internet would become the new corporate network, as the cloud became the new data center. We correctly predicted that with rapid cloud adoption and increasing workforce mobility, traditional perimeter security approaches would fail to protect users and data, become prohibitively expensive and deliver poor user experience. Enterprises now rely on external software as a service, or SaaS, applications for critical business functions and have moved, or are moving, their internally managed applications to the public cloud infrastructure. As a result, users now expect to be able to seamlessly access applications and data, wherever they are hosted, from any device, anywhere in the world. The emergence and rapid adoption of artificial intelligence, or AI, is revolutionizing the transformational impact of cloud adoption and mobility. AI is fundamentally changing how organizations operate, creating new cybersecurity threats and IT challenges. Our cloud native, multitenant architecture is distributed across more than 160 public exchanges globally and thousands of private exchanges at the edge, which brings security and business policy close to users and devices in over 185 countries and provides fast, secure and reliable access. Each day, we block over 225 million threats and perform over 250,000 unique security updates. Our customers benefit from the cloud security effect of our ever-expanding ecosystem, enhanced by our advanced AI and ML capabilities, because once a new threat is detected, it can be blocked across our customer base within minutes. Many of the largest enterprises and government agencies in the world rely on our solutions to help them accelerate their move to the cloud. We have over 9,400 customers across all major geographies, with an emphasis on larger organizations, and we currently count approximately 40% of the Forbes Global 2000 and over 45% of Fortune 500 companies as customers. Our customers span every major industry, including financial services, healthcare, insurance, manufacturing, automotive, airlines and transportation, conglomerates, consumer goods and retail, media and communications, public sector and education, energy, technology and telecommunications services. We have experienced significant growth, with revenue increasing from $1,617.0 million in fiscal 2023 to $2,167.8 million in fiscal 2024 to $2,673.1 million in fiscal 2025, representing year-over-year revenue growth of 34% and 23%, respectively. We experienced net losses of $41.5 million, $57.7 million and $202.3 million in fiscal 2025, fiscal 2024 and fiscal 2023, respectively. We expect we will continue to incur net losses for the foreseeable future. We pioneered a cloud platform, the Zscaler Zero Trust Exchange TM platform, which represented a fundamental shift in the architectural design and approach to networking and security that allows companies to securely accelerate their digital transformation initiatives. The Zscaler Zero Trust Exchange is a cloud-native platform, which implements Zero Trust principles to securely connect users, devices, applications and workloads, including AI agents, without relying on traditional hub-and-spoke network architecture and firewall-centric security. These technologies have become a roadblock to transformation for organizations that want to compete in today’s digital world. Firewalls and virtual private networks, or VPNs, create a perimeter around the corporate network and everything inside the perimeter is implicitly trusted. This is one of the root causes of ransomware attacks. Zscaler’s Zero Trust model operates on the principle that users, workloads, devices and AI 3 Table of Contents Agents are untrusted by default, irrespective of the network they are connected to. This approach reduces the attack surface and prevents lateral threat movement, while improving business resilience. We believe that Zero Trust combined with AI is rapidly becoming the new foundation for enterprise security architectures. Zscaler is pioneering this convergence of Zero Trust + AI, enabling enterprises to embrace technologies in a manner that is more secure, more scalable, more resilient and increasingly adaptable to the modern world. Our ever-evolving platform provides our customers with a flexible and scalable approach to better secure their operations, optimize user experience, eliminate complexity, reduce costs and respond to the challenges and opportunities of AI and future new technologies. As the threat landscape evolves and companies look to further embrace AI and the cloud, our platform has evolved to focus on four core solutions: Zero Trust Everywhere, Data Security Everywhere, Security for AI and Agentic Operations. • Zero Trust Everywhere – extends the principles of Zero Trust across all locations – branches, campuses, cloud, factories, entities, users, workloads, IoT/OT systems and autonomous AI agents. • Data Security Everywhere – is Zscaler’s approach to safeguarding sensitive information across its entire lifecycle, from creation to storage, transmission and access, regardless of location, device or application. • Security for AI – allows organizations to securely embrace public and private AI applications. • Agentic Operations – refers to the integration of advanced AI technologies to empower both Security Operations, or SecOps, and IT Operations, or ITOps, teams with increased efficiency and actionable insights. Zero Trust Everywhere Our Zero Trust Exchange cloud security platform delivers our core Zero Trust Everywhere products through the deployment of our comprehensive and integrated solutions, each built natively in the cloud to power digital transformation. Zero Trust Everywhere spans three core domains: Zero Trust Users, where users are never placed on the corporate network; Zero Trust Cloud, where workloads communicate only through the Exchange; and Zero Trust Branch, where branches, factories, warehouses, IoT/OT devices and autonomous AI agents are secured as independent entities and connected solely through policy-based access. Together, these capabilities deliver a unified Zero Trust architecture that replaces legacy firewalls, VPNs and SD-WANs with a model purpose-built for the modern enterprise. Zero Trust Users People remain the weakest link in enterprise security. Compromised credentials, unmanaged devices and phishing attacks continue to be the entry point for many breaches. Zero Trust Users is designed to protect the workforce, third parties, business-to-business, or B2B, partners and suppliers by assuming no user is trusted by default. Every user – internal or external, on any device, from any location – must prove their identity, demonstrate a secure posture and meet policy requirements before being granted access to an application. This approach eliminates the risks of putting users on a corporate network. Instead, users connect only to the specific applications they are authorized to use – whether SaaS, internet, AI applications or private applications hosted in data centers, clouds or factories. By removing the network path, threats cannot move laterally if a user is compromised. By treating every user as untrusted, continuously analyzing risk and enforcing adaptive, per-session policies, Zero Trust Users reduces the likelihood of breaches, protects sensitive data and ensures a secure, reliable experience for everyone 4 Table of Contents accessing enterprise applications and services. Zscaler delivers this functionality via the following core services: Zscaler Internet Access TM , or ZIA TM , Zscaler Private Access TM , or ZPA TM , and Zscaler Digital Experience TM , or ZDX TM . Zscaler Internet Access ZIA provides secure access to externally managed applications, including SaaS applications and internet destinations regardless of device, location or network. ZIA provides inline content inspection and firewall access controls across all ports and protocols to protect organizations and users from external threats, secure data in motion and prevent data from leaking out to unauthorized sites. Policies follow the user to provide identical protection on any device, regardless of location; any policy changes are enforced for users worldwide. Our inline cloud security platform assesses and correlates the risk of the content to protect against sophisticated attacks, including ransomware and phishing. The cloud platform applies AI and machine learning, or ML, across over 500 billion daily transactions to quickly identify and block unknown threats and to identify and categorize unknown destinations. ZIA enables the following capabilities: Cyberthreat Capabilities – Our holistic, future-ready threat defense functionality enables protection against threats using a range of approaches and techniques. Our threat prevention capabilities provide multiple layers of protection to prevent sophisticated ransomware, phishing and zero-day cyber attacks. Built on the principle of least privilege, our proxy architecture enables full Transport Layer Security, or TLS,/Secure Sockets Layer inspection at scale, with connections brokered between users and applications based on identity, context and business policies. We provide functionality that traditionally has been offered by disparate, stand-alone products. Our core cloud platform threat prevention capabilities include: • Advanced Threat Protection: Our advanced threat protection functionality uses techniques including AI/ML, advanced heuristics, signatures and reputation to deliver real-time protection from malicious internet content like browser exploits, scripts, zero-pixel iFrames, malware and botnet callbacks. Over 250,000 unique security updates are performed every day to the Zscaler cloud to keep organizations protected. Once we detect a new threat to a user, we block it for all users across all customers. We call this the “cloud security effect.” • Sandbox: Our cloud sandbox enables enterprises to block zero-day exploits and advanced persistent threats by analyzing unknown files for malicious behavior, and it can scale to every user regardless of location. Our cloud sandbox was designed and built to be multi-tenant and allows customers, using AI, among other analytics, to determine which traffic should be sent for detonation. As an integrated cloud security platform, customers can set policies by users and destinations to prevent patient-zero scenarios and to analyze, hold and detonate suspicious files in the cloud sandbox before they are sent to a user. • Browser Isolation: Our cloud browser isolation functionality creates an isolated browsing session that enables users to access any webpage on the internet without downloading any of the web content served by the webpage onto a local device or the corporate network. With cloud browser isolation, users are not directly accessing active web content; instead, only a safe rendering of pixels is delivered to the user. Malicious code that may be hidden in the web content is kept at bay. Customers can select and isolate traffic based on specific policies and/or automatically based on our AI enabled risk determination. The combination of cloud browser isolation and cloud sandbox enables administrators to perform content disarm and reconstruction to flatten, sanitize and securely deliver files free of active content. 5 Table of Contents Zscaler Private Access ZPA provides Zero Trust Network Access to secure access to internally managed applications, either hosted internally in data centers or hosted in private or public clouds. ZPA is designed around four key tenets that fundamentally change the way users access internal applications: • connect users to applications without bringing users on the network, preventing lateral movement; • never expose applications to the internet; • segment access to applications without relying on the traditional approach of network segmentation; and • provide remote access over the internet without VPNs. ZPA leverages a global policy engine that governs access to internally managed applications regardless of location. If access is granted to a user, our ZPA solution connects the user’s device only to the authorized application without exposing the identity or location of the application. As a result, applications are not exposed to the internet, further limiting the external attack surface. This results in reduced cost and complexity, while offering better security and an improved user experience. Our ZPA solution includes broad functionality, which we categorize by the following areas: • Cyberthreat Protection and Data Protection: Our ZPA solution delivers the same cyberthreat protection and data protection functionality that is applied to internet traffic via our ZIA solution. • Application Discovery: Similar to cloud access security broker, or CASB, application discovery reports for internet hosted SaaS applications, our ZPA solution provides granular discovery of internally managed applications to aid in the creation and oversight of segmentation policies. Because our ZPA solution sits on the application layer and is name-based or domain-based, organizations can quickly and seamlessly identify their internally-managed applications and then easily provision appropriate policies. • Secure Application Access: Since our ZPA solution delivers seamless connectivity to internally managed applications and assets whether they are in the cloud, enterprise data center or both, administrators can set global policies from a single console, enabling policy-driven access that is agnostic to the network the users are on. By creating seamless access to applications regardless of a user’s network, our ZPA solution eliminates the need for traditional remote access VPNs, reverse proxies and other similar products. • Application Segmentation: Our architecture provides capabilities that enable user and application level segmentation, a vast improvement over traditional network segmentation. As each user-to-application connection is segmented with microtunnels, each of which is a temporary session between a specific user and a specific application, lateral movement across the network is prevented, significantly reducing security risk. Since users are granted access only to applications for which they have permission and are not granted full access to the network, microtunnels eliminate the need for an internal firewall. • Application Protection: Our ZPA solution initiates outbound-only connections between authenticated users and internally managed applications using microtunnels. Access is provided to users without bringing them onto the corporate network and without exposing applications to the internet. Internally managed applications are not discoverable or identifiable. With no inbound connections and no public IP addresses, there is no inbound attack surface and therefore no threat of distributed denial-of-service, or DDoS, attacks. For allowed connections, our ZPA solution also provides Web Application Firewall functionality, including OWASP Top 10 protections for threats, such as Structured Query Language injection and cross-site scripting, to block common attack vectors. 6 Table of Contents • Reduce Attack Surface: Our architecture utilizes inside out connections that are outbound from users to the Zero Trust Exchange platform, which allows customers to deny all inbound connections. This reduces their attack surface by not exposing IP addresses of all devices, applications, appliances or workloads to the internet. Reduced attack surface results in lower exposure to zero-day application vulnerabilities and eliminates the need for DDoS mitigation. • Browser Isolation: Our cloud browser isolation is used with our ZPA solution to provide isolated sessions to internal web applications without allowing data to transfer down to unmanaged devices or active content to be uploaded into sensitive internal applications. Combining cloud browser isolation with browser-based access provides a simplified, more cost-effective alternative to VDI for employees, contractors and B2B partners, by effectively keeping sensitive data off unmanaged devices. The primary use cases for our ZPA solution include: • remote workforce access to private applications without legacy VPN, providing Zero Trust from office to data center; • deliver user-to-application segmentation, thus eliminating the risk of lateral threat propagation enabled by legacy Firewall and VPN based security architecture; • providing non-employees with secure access to internal applications; • securely connecting B2B customers, service providers and supplier access to applications typically deployed as B2B portals in an extranet; • direct-to-cloud access to internally managed applications hosted in public cloud environments, such as Azure, AWS and GCP; and • access to applications following a merger or acquisition by providing named users with access to named applications, without the need to merge networks. Zscaler Digital Experience ZDX is designed to measure end-to-end user experience across key business applications, providing an easy-to-understand digital experience score for each user, application and location within an enterprise. As users have become mobile and applications have moved to the cloud, traditional network performance monitoring tools have become increasingly irrelevant. Enterprises can no longer reliably collect performance metrics or indicators along the traditional network path as they could when they owned the network and applications ran in their own data centers. ZDX leverages advanced AI-enabled root cause analysis to proactively pinpoint issues in the network path, providing detailed insights into whether disruptions stem from a user’s device, WiFi connection, local internet, service provider or the destination application itself. With ZDX's expanded functionality, enterprises can now utilize predictive analytics to identify potential performance degradations before they impact end users, enabling faster remediation and minimizing downtime. Additionally, ZDX can easily differentiate localized issues – such as problems affecting a single user, application or location – from broader systemic issues impacting multiple users or locations, ensuring quicker and more focused responses. Administrators benefit from enhanced real-time monitoring and seamless integration into existing IT workflows, all via a simple visual interface that eliminates the need for additional hardware or software. Zero Trust Cloud Our Zero Trust Cloud offers a comprehensive solution for securing customer workloads across hybrid environments, encompassing both public clouds and private data centers. This platform is built on a Zero Trust architecture, utilizing our 7 Table of Contents Zero Trust Exchange for centralized security policy enforcement and robust data protection. Zero Trust Cloud is designed to securely connect workloads and inspect all traffic, enabling the detection and mitigation of cyber threats like ransomware, preventing data loss and facilitating workload segmentation to halt the lateral movement of threats. This strategy aims to provide customers with consistent threat and data protection, eliminate the attack surface, reduce operational complexity and lower overall costs. Our Zero Trust Cloud solution includes broad functionality, which we categorize by the following ideas: • Secure Workload to Internet: Our Zero Trust Cloud provides a solution for securing outbound communications from customer workloads to the internet. This capability is designed to protect workloads hosted in public clouds, private data centers or hybrid environments when they connect to external resources such as application programming interfaces, or APIs, SaaS platforms, third-party services or AI agents. Rather than trusting the underlying network, our Zero Trust model is founded on verifying the identity of the workload itself and enforcing granular access policies for any internet-bound request. To protect against cyber threats and data loss, the solution performs cloud-scale TLS inspection, which is designed to identify and block malicious attacks and prevent the unauthorized exfiltration of sensitive data from our customers' cloud workloads. • Zero Trust Gateway: Zero Trust Gateway is a new deployment model for Zero Trust Cloud that dramatically improves operational efficiency. Customers can now rapidly deploy Zero Trust Cloud. Zero Trust Gateway, a fully managed Zscaler service available in the cloud service provider, allows customers to route traffic to Zscaler via an endpoint service using the most optimized path. This enables real-time inspection and filtering of traffic, preventing unauthorized access and mitigating threats. Zero Trust Cloud, deployed via Zero Trust Gateway, secures workload-to-internet and workload-to-workload traffic across multi-cloud environments, eliminating the need for traditional cloud firewalls, VPNs, express routes or direct connects. • Workload Microsegmentation: Our Workload Microsegmentation solution secures mission critical applications inside public clouds and data centers to stop lateral threat movement, preventing application compromise and reducing the risk of data breaches. Our agent-based offering solution utilizes an innovative, AI-enabled approach that is simpler to deploy and operate than traditional segmentation solutions, and improves the security of east-west communication by verifying the identity of the communicating application software, services and processes to achieve a Zero Trust environment. This reduces the attack surface, resulting in lower risk of application compromise and data breaches. Zero Trust Branch Our Zero Trust Branch solution brings Zero Trust principles to secure communications between and within branches, factories, data centers and campuses. It reimagines branches as independent “café-like” environments, connecting directly to our Zero Trust Exchange over broadband, 5G or satellite. The network becomes pure transport, while business policies determine who can access what, when and where. With this model, branches become like islands and are invisible to the internet, dramatically reducing the attack surface and eliminating lateral threat movement. This eliminates the need for north-south firewalls, VPNs, network access control, or NAC, systems and costly routing infrastructure, sharply lowering complexity, risk and cost. Legacy branch architectures built on MPLS or legacy SD-WAN solutions inherently enable lateral movement, allowing compromised devices in one location to infect applications and systems across the corporate network. This model creates unnecessary cyber risk and adds costly complexity. Zero Trust Branch neutralizes that risk by eliminating implicit trust and lateral movement, stopping ransomware and malware spread. 8 Table of Contents Our Zero Trust Branch solution includes broad functionality, which we categorize by the following ideas: • Zero Trust SD-WAN: Our Zero Trust SD-WAN solution provides branches and data centers with fast, reliable access to the internet and private applications with our Direct-to-Cloud TM architecture that provides strong security and operational simplicity, with the ability to deploy locally by virtual machine or by purchasing a plug-and-play appliance. Our Zero Trust SD-WAN solution eliminates lateral threat movement by connecting users and IoT/OT devices to applications through our Zero Trust Exchange platform. Branch traffic can be securely forwarded directly to the Zero Trust Exchange, where ZIA or ZPA policies can be applied for full security inspection and access identity-based control of branch and data center communications. • Zero Trust Device Segmentation: Our Zero Trust Device Segmentation solution provides agentless segmentation for enterprise IT and OT environments, creating a "network of one" where even devices on the same network can only communicate with each other if authorized. The combination of Zero Trust SD-WAN with Zero Trust Device Segmentation extends the Zero Trust Exchange platform to protect east-west traffic in branch offices, campuses, factories and plants with critical OT infrastructure, eliminating the need for east-west firewalls, NACs and traditional microsegmentation solutions, while simultaneously delivering operational simplicity. Data Security Everywhere Our data security functionality enables enterprises to prevent unauthorized sharing or exfiltration of confidential information by users, devices, servers, workloads and AI agents, thereby reducing business and compliance risks for our customers. We provide inline monitoring of data flows between users and applications, workload to workload, API to API and applications to LLMs with AI-powered auto data discovery, reducing the risk of inadvertently transmitting sensitive data and intellectual property. We also provide out-of-band discovery and remediation of data risks across a wide range of data stores, including SaaS, IaaS/PaaS, cloud data lakes and warehouses and on-prem systems. Core cloud platform data security services include: • Advanced AI-Powered Data Classification: Our data classification engines leverage a variety of technologies and techniques to identify customer sensitive data. Predefined, custom dictionaries and automated AI discovery tools identify sensitive customer data by leveraging efficient pattern-matching algorithms, regular expressions, AI-based training models and keywords. Additional advanced classification techniques, including exact data match, indexed document matching and ML-based optical character recognition, enable our customers to identify and secure sensitive data across billions of unique structured data fields. • Enterprise Data Loss Prevention: Our data loss prevention, or DLP, technology enables enterprises to alert and/or block transmission or sharing of sensitive data across exfiltration channels. This includes inline data in motion to external internet destinations and unmanaged endpoints, data at rest in SaaS environments through out-of-band API integrations, securing public cloud infrastructure data in Azure, AWS and GCP and protecting endpoints by preventing printing or copying to local storage, including USB devices. Additionally, our Email DLP solutions secure corporate email traffic, including Microsoft Exchange and Gmail. • Unified SaaS Security: Our CASB, SaaS security posture management, or SSPM, and our SaaS supply chain security combine to discover and control known and unknown applications, identify SaaS misconfigurations, find and mitigate potentially risky third-party connections into those SaaS applications and scan data residing in those applications for threats and data protection violations. By doing TLS inspection at scale, we provide malware protection, DLP and CASB functions that can be performed both inline and out-of-band, for specific sanctioned and unsanctioned applications. Business policies can be defined with granular access control for specified cloud applications, such as the ability to upload or download files or post comments on videos based on different user or group identity. 9 Table of Contents • Email Security: Our email security solution leverages advanced cloud-delivered protections to secure inbound and outbound email traffic against sophisticated threats, such as phishing, malware and ransomware. Integrated with our Zero Trust Exchange platform, it ensures comprehensive inspection and policy enforcement without relying on traditional email gateways. The solution employs AI and ML to detect and block malicious payloads, suspicious links and compromised accounts in real time. Additionally, this solution enhances DLP by identifying and mitigating risks associated with sensitive information being shared via email. • Data Security Posture Management: Our Data Security Posture Management, or DSPM, technology enables enterprises to discover and mitigate risk across their vast range of data stores – including public cloud, SaaS, data lakes and warehouses and on-premise data systems. Advanced classification and contextual analysis enables enterprises to understand where sensitive data resides, and to uncover risks related to posture configuration, access entitlements or compliance. Automated workflows enable organizations to remediate these risks, integrating with mainstream IT Service Management tools such as Service Now and Jira. The solution empowers organizations to proactively remediate data risks and avoid sensitive data exposures or compliance violations. Security for AI The emergence of generative AI models is fundamentally transforming businesses, as enterprises and their stakeholders have rapidly embraced this new technology. Enterprises are adopting public GenAI SaaS applications, such as ChatGPT, Microsoft Copilot, Gemini and others, and are also investing to develop their private AI applications, such as customer-facing, employee-facing or supplier-facing chatbots and agents. This growing adoption of AI is leading to an emergence of a new category of risks that go beyond traditional cyber and data risks, including prompt injection, toxicity, training data leakage, model poisoning, tool poisoning and other risks. To enable our customers to safely and securely adopt these public and private AI applications, we are expanding our Security for AI Applications portfolio. Security for Public AI Applications – Public GenAI SaaS applications can improve employee productivity, however they also present new risks for organizations, such as data loss and unauthorized access to classified or sensitive information. Zscaler’s Public AI security solutions give visibility, provide access control, protect sensitive information leakage and defend against emerging adversarial attacks. Our solutions for public AI applications include: • GenAI Security: Our GenAI security offerings provide enterprises with comprehensive visibility and control over generative AI tool usage to prevent data loss while enabling productivity benefits. Our solution allows organizations to create and enforce policies around which generative AI tools users can access and how they interact with them, including through secure browser isolation to protect sensitive data. The platform delivers granular controls including prompt-level visibility, AI/ML-based URL filtering, DLP enforcement and the ability to restrict data upload methods while allowing productive AI interactions. In addition to inline controls, our solution offers proactive discovery and analysis of AI systems in cloud environments. This solution helps organizations deal with model sprawl, identify new AI attack vectors and govern data connected to AI systems. Our solutions also help safeguard the use of AI embedded in SaaS applications, such as Microsoft Copilot, to help ensure that data being used by Copilot is properly protected. This comprehensive approach enables organizations to harness the innovation and efficiency benefits of generative AI while maintaining robust data security and regulatory compliance. • Zscaler AI Guard for Users: Our Zscaler AI Guard for Users secures the prompts and responses between employees of our customers and public GenAI applications. AI Guard enforces policies on prompts and responses to protect against toxicity, prompt injection, code sharing, sensitive-data leakage and other adversarial attacks. In addition, AI Guard provides granular visibility into prompts, responses and log events, including the associated metadata, for consumption and analysis by security operations center, or SOC, teams. 10 Table of Contents Security for Private AI Applications – Enterprises are developing private AI applications, such as chatbots and AI-agents, using large language models, or LLMs, such as ChatGPT, Anthropic, Gemini, Llama, DeepSeek and more. Our private AI security solutions provide visibility and policy enforcement. Our solutions for private AI applications include: • AI-SPM: Zscaler AI-SPM provides deep visibility into all AI services, agents and models deployed in a customers’ environment. Leveraging advanced LLM classification, Zscaler AI-SPM discovers, classifies and assesses risks of sensitive data that maps to any AI services, providing a 360-degree view of all of data and its correlated risks. • AI Guard for Private LLMs: Zscaler’s AI Guard provides guardrails with purpose-built detectors sitting inline between LLMs and private AI apps. With continuous monitoring, secure deployment and advanced protection, AI Guard enables organizations to harness the power of AI while keeping their models and data safe from exploitation. • AI Decoys for LLMs: AI Decoys for LLMs is designed to prevent sensitive data leakages and unauthorized access in environments leveraging LLMs, extending our existing deception capabilities. It uses AI-generated decoy information to mislead and neutralize potential threats, safeguarding critical organizational assets. Agentic Operations Security Operations Reducing cyber risk is a priority for all enterprises, especially at the executive and board of directors level, making holistic security operations a key area of focus for our customers. Our security operations solutions include both proactive security initiatives, focused on identifying security gaps before they can be exploited, and reactive security programs, centered on finding and containing incidents after they happen. These solutions include broad and differentiated capabilities in both domains and are categorized into the following areas: Proactive Security Operations Exposure Management – Zscaler’s exposure management platform ingests and analyzes a wide range of exposure intelligence sources to deliver a comprehensive view of organizational risk. It integrates data from Zscaler systems, such as our Zero Trust Exchange platform, and third-party data from more than 150 sources including: vulnerability scans; misconfigurations; shadow IT discovery and unmanaged devices (including IoT/OT); security information and event management, or SIEMs; security orchestration, automation and response systems; endpoint protection platforms; and global threat intelligence feeds. It also integrates contextual data such as asset criticality, business impact and user behavior. Our Data Fabric for Security ingests, synthesizes and enriches this data to yield compelling insights for exposure management by security teams. Our exposure management platform includes: • Unified Vulnerability Management: Our unified vulnerability management solution provides dynamic and customizable prioritization, streamlined reporting, automated workflows for remediation and contextualized risk-based assessments of a customer’s risk landscape. This solution leverages our Data Fabric for Security to deliver actionable insights, prioritized risk analysis and operational efficiencies. Our customers gain significantly enhanced and automated analytics and decision-making in real-time without the need for manual data aggregation and collection. • Asset Exposure Management: Our asset exposure management capabilities provide organizations with deep visibility into their digital attack surface, enabling them to identify, assess and remediate asset vulnerabilities before they can be exploited. By continuously monitoring all assets – whether hosted on-premises, in the cloud or within hybrid environments – our solution helps uncover shadow IT, misconfigurations, unpatched systems and other hidden risks. This solution leverages our Data Fabric for Security to provide advanced analytics and automation, 11 Table of Contents prioritize critical exposures based on business impact and threat likelihood and empower organizations to proactively reduce their attack surface and strengthen their overall security posture. This approach aligns with our commitment to providing comprehensive, scalable solutions that help customers minimize risk in a rapidly evolving threat landscape. Reactive Security Operations Threat Management – Zscaler delivers advanced capabilities including deception technologies, identity threat detection and managed detection and response. Our acquisition of Red Canary, Inc, or Red Canary, strengthens this portfolio with its agentic AI-driven threat detection that autonomously reduces alert fatigue, hunts threats and delivers faster, more accurate incident containment. We will integrate these advanced SOC capabilities with our Data Fabric for Security, enabling more robust SOC capabilities over time and helping customers reduce or eliminate their dependence on costly legacy SIEM systems. Our threat management offerings include: • Deception: Our deception solution augments our customers’ ability to detect the presence of an adversary in their network by deploying decoys. These decoys disrupt adversaries by detecting their presence in the network and initiating mitigation using automatic orchestration via the Zscaler platform and other third-party solutions. Customers can quickly deploy these capabilities by leveraging a diverse library of built-in decoys including various types of applications, network components and IoT services. The high-fidelity low-volume alerts allow customers to implement meaningful automation workflows to prevent lateral spread. • Red Canary Managed Detection and Response: Our Managed Detection and Response (MDR) service offering, added through our acquisition of Red Canary, provides threat detection and on-demand incident response services to augment our customers’ security operations capabilities and reduce reliance on extensive internal resources or specialized expertise. This capability leverages advanced technologies including agentic workflows, AI-supported threat intelligence, expert analysis and automated runbooks to identify and address complex cybersecurity threats. • Identity Protection: Attackers commonly target users and identities as the point of entry and use that access to escalate privileges and move laterally. Our Identity Protection capability provides continuous visibility into identity misconfigurations and at-risk permissions by scanning common identity providers. Identity Protection augments this visibility with guidance in the form of scripts, commands and tutorials to remediate identity risk and reduce customers’ internal attack surface. In addition to preventive capabilities, Identity Protection also provides high-fidelity detection for identity-based attacks like stolen credentials, multi-factor authentication bypasses and privilege escalation techniques that typically pass through existing defenses in cases of identity compromise. Agentic IT Operations Zscaler is also extending Agentic Operations to IT through our ZDX product. Traditional IT operations depend on siloed monitoring tools that provide limited visibility and require manual troubleshooting across networks, devices and applications. These limitations result in long ticket resolution times, frustrated users and higher operating costs. With ZDX's expanded functionality, enterprises can now utilize predictive analytics to identify potential performance degradations before they impact end users, enabling faster remediation and minimizing downtime. ZDX leverages advanced AI-enabled root cause analysis to proactively pinpoint issues in the network path, providing detailed insights into whether disruptions stem from a user’s device, WiFi connection, local internet, service provider or the destination application itself. It also leverages AI-driven automation to deliver end-to-end visibility into user experience, network performance and application health. With agentic remediation capabilities, ZDX can detect endpoint issues, resolve tickets and proactively improve performance without human intervention. For example, ZDX can identify device misconfigurations, degraded application paths or network bottlenecks, and automatically correct them, reducing resolution time, avoiding downtime and creating a better user experience. 12 Table of Contents By transforming IT operations from reactive to proactive, ZDX enables enterprises to improve user productivity and satisfaction, reduce IT operations cost and deliver consistent digital experiences at global scale. Our Technology and Architecture We are driven by technology and innovation. We developed a highly scalable, multi-tenant, globally distributed cloud capable of providing inline inspection of internet and SasS traffic, securing access to private applications, protecting cloud applications, managing digital experience and scanning for exposures and misconfigurations. We designed a purpose-built three-tier architecture starting with our core operating system and adding layers of security and networking innovations over time. Our cloud platform is protected by more than 725 issued and pending patents in the United States and other countries. Our cloud is distributed across more than 160 public exchanges globally and thousands of private exchanges at the edge, and processes over 500 billion requests per day from users across over 185 countries. Our platform is designed to be resilient, redundant and high-performing. It is built as software modules that run on standard x86 platforms without dependency on custom hardware. The platform modules are split into the control plane (Zscaler Central Authority), the enforcement plane (Zscaler Enforcement Nodes) and the logging and statistics plane (Zscaler Log Servers) as described below: • Zscaler Central Authority: The Zscaler Central Authority monitors our entire security cloud and provides a central location for software and database updates, policy and configuration settings and threat intelligence. The collection of Zscaler Central Authority instances together act like the brain of the cloud, and they are geographically distributed for redundancy and performance. • Zscaler Enforcement Nodes: Customer traffic is directed to the nearest Zscaler Enforcement Node, where security, management and compliance policies served by the Zscaler Central Authority are enforced. The Zscaler Enforcement Node also incorporates our differentiated authentication and policy distribution mechanism that enables any user to connect to any Zscaler Enforcement Node at any time to ensure full policy enforcement. The Zscaler Enforcement Node utilizes a full proxy architecture and is built to ensure data is not written to disk to maintain the highest level of data security. Data is scanned in random-access memory only and then erased. Logs are continuously created in memory and forwarded to our logging module. • Zscaler Log Servers: Our technology is built into the Zscaler Enforcement Node to perform lossless compression of logs, enabling our platform to collect over 130 terabytes of unique raw log data every day. We do not collect customer data other than logs, and those logs are encrypted and transmitted to our log server at a destination of choice selected by the customer without ever writing to disk at the enforcement nodes. Logs are transmitted to our logging servers over secure connections and multicast to multiple servers for redundancy. Our dashboards provide our customers visibility into their traffic to enable troubleshooting, policy changes and other administrative actions. Our analytics capabilities allow customers to interactively mine billions of transaction logs to generate reports that provide insight on network utilization and traffic. We do not rely on batch reporting; we continuously update our dashboards and reporting and can stream logs to a third-party SIEM service as they arrive. Regardless of where users are located, customers can choose to have logs stored in the United States or the European Union/Switzerland. Customer data is isolated as part of our multi-tenant architecture. • Data Fabric for Security: Our Data Fabric for Security capabilities empower organizations to seamlessly integrate, analyze and act on security data across distributed environments. By unifying data from user activity, applications, devices and workloads across on-premises, cloud and hybrid networks, our platform provides real-time visibility into potential threats and vulnerabilities. This interconnected “fabric” enables security teams to break down silos, correlate insights from multiple sources and make proactive, data-driven decisions to mitigate risks. With advanced automation and AI-driven analytics, our Data Fabric for Security transforms raw security data into actionable 13 Table of Contents intelligence, helping organizations respond faster to incidents, comply with regulatory requirements and maintain a robust security posture across their increasingly complex IT ecosystems. Our platform is a critical integration point positioned in the data path providing secure access to the internet, cloud and internal applications. We complement and interoperate with key technology and cloud vendors across major market segments, including identity and access management device and endpoint management, as well as SIEM for reporting and analytics. Many of these vendors, like us, were developed in the cloud and together provide a foundation for a modern access and security architecture. Growth Strategies The growing use of the internet and the increasing adoption of the cloud and mobility are driving network and application transformation. As a provider of a fully integrated, multi-tenant cloud security solution, we enable our customers to accelerate this secure transformation to the cloud and believe we are uniquely positioned to maximize value as they undertake these transitions. Key elements of our growth strategy include: • Continue to win new customers. We believe that we have a significant opportunity to expand our customer base, both in the United States and internationally. We have invested significantly in our sales and marketing organization to execute against this opportunity. • Expansion in existing customers. We leverage a land-and-expand approach with our existing customers to sell subscriptions for additional users, additional solutions and premium solution bundles that contain more functionality. • Leverage channel partners to participate in cloud transformation initiatives. We have invested in establishing long-standing relationships with global telecommunications service providers and are expanding our network of global system integrators and regional telecommunications service providers and cloud-centric value-added resellers and public cloud marketplaces. • Expansion and innovation of services. We continue to invest in research and development and acquire new technologies and products to add new and differentiated solutions to our existing product portfolio and to improve the overall functionality, reliability, availability and scalability of our cloud security platform. • Expansion into additional market segments. We are targeting the expansion of our immediate addressable market into additional markets, segments and verticals. For example, we are targeting our expansion into new geographies in the Asia Pacific, Latin America and Middle East regions. We sell to enterprises of all sizes. As of July 31, 2025, we had over 9,400 customers, including approximately 40% of the Forbes Global 2000 and over 45% of Fortune 500 companies. Many of our customers include major global enterprises that send virtually all of their internet traffic through our cloud security platform. Our customers operate in a variety of industries, including automotive, airlines and transportation, conglomerates, consumer goods and retail, energy, financial services, healthcare, insurance, manufacturing, media and communications, public sector and education, technology and telecommunications services. Approximately 49% of our revenue was from customers outside the United States for all periods presented. No end customer contributed more than 10% of our revenue in fiscal 2025, fiscal 2024 and fiscal 2023. 14 Table of Contents Sales and Marketing Although we have a channel sales model, we use a joint sales approach in which our sales force develops relationships directly with our customers, and together with our channel account teams, works with our channel partners on account penetration, account coordination, sales and overall market development. Our customer care and success teams maintain high-touch relationships with our customers to deploy and manage our cloud platform, identify, analyze and resolve performance issues and respond to security threats. We believe customer service touchpoints are opportunities to further develop our relationship with our customers and potentially generate incremental revenue through the addition of new users and services. Our channel partners consist of global telecommunications service providers, system integrators, value-added reseller partners and public cloud marketplaces, and we leverage their relationships to expand our reach, improve procurement and accelerate customer fulfillment. We enter into agreements with our channel partners in the ordinary course of business. The contracts typically have a one-year term and renew automatically, subject to cancellation by either party upon 90 days’ notice. These agreements contain standard commercial terms and conditions, including payment terms, billing frequency, warranties and indemnification. Our channel partners generally place purchase orders with us after receiving orders from customers. We generally maintain privity of contract with customers through end user subscription agreements. We expect to continue investing in our channel partners as we provide them with education, training and programs, including supporting their independent sales of our solutions. We believe that such investment, and investments in our sales force, will lead to significant expansion in our customer base, which will materially impact our business and results of operations. Our marketing strategy is focused on platform and brand awareness, which drives our opportunity pipeline and customer demand. This strategy is account-based, enabling us to pursue targeted marketing activities across both digital and non-digital channels. We anticipate increasing our marketing team headcount and are investing in programs designed to elevate our brand in the market and engage new enterprise accounts. We also participate in a number of cloud and security industry events. In addition, we have a deeply integrated ecosystem of channel partners, with whom we engage in joint marketing activities. Data Center Operations We have expanded the Zero Trust Exchange over 160 public exchanges and thousands of private exchanges at the edge, which are built to be highly resilient, have multiple levels of redundancy and provide failover to other data centers in our network. Our data centers are co-located within top-tier internet interconnection hubs that have direct connectivity, known as peering, to major telecommunication service providers, SaaS providers, public cloud providers, internet content providers and popular internet destinations. A number of our data centers are also located with our service provider partners. Compliance Our platform has received numerous industry standard and internationally recognized certifications upon successful completion of further independent third-party assessments, including ISO 27001, ISO 27701, ISO 27018, ISO 27017, SOC2, SOC 3 CSA-STAR and HIPAA. We also built a leading U.S. and international government compliance portfolio. We are authorized at the FedRAMP Moderate and High levels and Impact Level 5 with the DOD for ZPA. In addition, in the U.S. we are authorized at both the FedRAMP Moderate and High levels for ZIA, among others. We also hold CMMC Level 2 certification, ITAR, FIPS, CJIS 15 Table of Contents and VPAT 508 in our U.S. Government portfolio. We also became the first cloud-based SaaS security company to achieve StateRamp for state and local governments. Internationally, we are IRAP Protected and APRA in Australia, Cyber Essentials and G-Cloud in the UK, C5 in Germany, ITSG-33 Prob B in Canada, ISMAP in Japan, MTCS in Singapore and, most recently, Spain Gov CPSTIC catalog listing and ENS-High. Research and Development Our research and development organization is responsible for the design, architecture, operation and quality of our cloud platform. In addition to improving on our features and functionality, this organization works closely with our cloud operations team to ensure that our platform is reliable, available and scalable. ThreatLabZ, our internal team of security experts, researchers and network engineers, analyzes the global threat landscape, works to eliminate threats across our cloud platform and reports on emerging security issues. Research and development expense was $672.5 million, $499.8 million and $350.8 million for fiscal 2025, fiscal 2024 and fiscal 2023, respectively. Our research and development leadership team is predominantly located in San Jose, California, and we also maintain research and development centers internationally, including in India, Canada, Israel and Spain. Competition The market for security solutions is defined by changing technologies, an evolving threat landscape and complex enterprise needs. Our competitors and potential competitors include legacy on-premises appliance vendors and other vendors across a number of categories: • independent IT security vendors, which offer a broad mix of network and endpoint security products; • large networking and other vendors, which offer security appliances and/or incorporate security capabilities in their networking products and other services; • companies with point solutions that compete with some of the features of our cloud platform, such as proxy, firewall, CASB, sandboxing and advanced threat protection, AI security, data loss prevention, encryption, load balancing and VPN; and • other providers of IT security services that offer, or may leverage related technologies to introduce, products that compete with or are alternatives to our cloud platform. The principal competitive factors in the markets in which we operate include: • delivering security from the cloud regardless of location of the user; • platform features, effectiveness and extensibility; • platform reliability, availability and scalability; • rapid development and delivery of new capabilities and services; • ability to integrate with other participants in the security and networking ecosystem; • price, total cost of ownership and network cost savings; • brand awareness, reputation and trust in the provider’s services; • strength of sales, marketing and channel partner relationships; and 16 Table of Contents • quality of customer support. We believe we are positioned favorably against our competitors based on these factors. Our cloud platform integrates many of the point products offered by our competitors and potential competitors, which is a key differentiator. However, many of our competitors have substantially greater financial, technical and other resources, greater brand recognition, larger sales forces and marketing budgets, broader distribution networks, more diverse product and services offerings and larger and more mature intellectual property portfolios. They may be able to leverage these resources to gain business in a manner that discourages users from purchasing our services, including through selling at zero or negative margins, offering concessions, product bundling or maintaining closed technology platforms. Further, many organizations have invested substantial personnel and financial resources to design and operate their appliance-based network security architecture and may not be willing or ready to abandon those historical investments. As our market grows and rapidly changes, we expect it will continue to attract new companies, including smaller emerging companies, which could introduce new products and services. In addition, we may expand into new markets and encounter additional competitors in such markets. Intellectual Property Our success depends in part upon our ability to protect and use our core technology and intellectual property rights. We rely on a combination of patents, copyrights, trademarks, trade secret laws, contractual provisions and confidentiality procedures to protect our intellectual property rights. As of July 31, 2025, we had more than 725 issued patents and pending patent applications, including more than 325 issued patents in the United States and other countries. Our issued patents expire between 2028 and 2044 and cover various aspects of our cloud platform. In addition, we have registered “Zscaler” as a trademark in the United States and other jurisdictions, and we have registered other trademarks and filed other trademark applications in the United States. We are also the registered holder of a variety of domestic and international domain names that include “Zscaler” and similar variations. In addition to the protection provided by our intellectual property rights, we enter into confidentiality and invention assignment or similar agreements with our employees, consultants and contractors. We further control the use of our proprietary technology and intellectual property rights through provisions in our subscription and license agreements. Despite our efforts to protect our trade secrets and proprietary rights through intellectual property rights, licenses and confidentiality agreements, unauthorized parties may still copy or otherwise obtain and use our software and technology. In addition to our internally developed technology, we also license software, including open source software, from third parties that we integrate into or bundle with our cloud platform. Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation based on allegations of patent infringement or other violations of intellectual property rights. We believe that competitors will try to develop products and services that are similar to ours and that may infringe our intellectual property rights. Our competitors or other third-parties may also claim that our platform infringes their intellectual property rights. In particular, companies in our industry have extensive patent portfolios. From time to time, third parties, including certain of these companies and non-practicing entities, have in the past and may in the future, assert claims of infringement, misappropriation and other violations of intellectual property rights against us or our customers or channel partners, with whom our license or other agreements may obligate us to indemnify against these claims. Successful claims of infringement by a third-party could prevent us from offering certain services or features, require us to develop alternate, non-infringing technology, which could require significant time and during which we could be unable to continue to offer our affected subscriptions or services, require us to obtain a license, which may not be available on reasonable terms or at all, or force us to pay substantial damages, royalties or other fees. As we face increasing competition and gain an increasingly higher profile, the possibility of intellectual property rights claims against us grows. We cannot assure you that we do not currently infringe, or that we will not in the future infringe, upon any third-party patents or other proprietary rights. See “Risk Factors—Risks Related to Our Business—Claims by others that we infringe their proprietary technology or other rights, or other lawsuits asserted against us, could result in significant costs and substantially harm our business, financial condition, results of operations and prospects” for additional information. 17 Table of Contents Government Regulation Our business activities are subject to various federal, state, local and foreign laws, rules and regulations. Compliance with these laws, rules and regulations has not had, and is not expected to have, a material effect on our capital expenditures, results of operations and competitive position as compared to prior periods. Nevertheless, compliance with existing or future governmental regulations, including, but not limited to, those pertaining to global trade, business acquisitions, consumer and data protection, privacy, employment, labor and taxes, could have a material impact on our business in subsequent periods. For more information on the potential impacts of government regulations affecting our business, see “Item 1A - Risk Factors.” Human Capital As of July 31, 2025, we had a total of 7,923 employees in locations around the world. We have not experienced any work stoppages and we consider our relations with our employees to be positive and collaborative. Zscaler's vision is to create a world in which the exchange of information is always secure and seamless. Specifically, ensuring that our people and culture are aligned with this vision is critical to our success. In order to continue to innovate and to execute our business strategy, we must attract, develop and retain skilled employees, particularly in the areas of product development, engineering, sales and customer success. Our Culture Our culture is about creating an environment where our global workforce can contribute their best work to help our customers and our business succeed. Zscaler's cultural values are: • Teamwork • Ownership • Passion • Innovation • Customer Obsession We build this culture through the feedback we receive from our employees through company-wide surveys as well as informal feedback channels throughout the year. We ultimately view and measure the success of our culture by our ability to sustain great business results. Employee Development We invest in our employees through a suite of programs from their first day of employment to develop their talent and skills as our business grows. Our leadership approach establishes clear expectations, enables measurement and actionable feedback and ensures that our people managers have access to learning and resources that help them to embody our leadership principles. In addition, new employees in our customer care and success teams are enrolled in structured sales and product training to build their knowledge. Our technical teams have access to live and online training resources and participate in frequent company tech talks where training on best practices and latest developments are shared. We build the skills and capabilities of our senior leaders through intentional investment in their development and opportunities for them to network, collaborate and problem solve together. To supplement our internal resources, we work with external experts to offer focused development for our leaders, as well as targeted offerings on topics that are critical to enhancing the capabilities of our talent. We offer tuition reimbursement for eligible employees to further enhance their career growth through higher education. 18 Table of Contents Compensation and Benefits We provide competitive compensation and benefits packages to attract and retain our talent. In addition to base pay, employees may be eligible for performance based bonuses that are tied to our financial performance and long-term equity incentives that vest subject to continued service. Certain employees may also need to achieve defined performance metrics for parts of their long-term incentives to vest. Our employee performance management program aligns individual achievement and corporate goal attainment with compensation. Employees are assessed on both what was achieved and how they achieved it to help build a high-performance culture that delivers for our customers and is aligned to our cultural values. We offer an employee stock purchase plan, which allows employees to contribute a percentage of their wages to purchase our stock at a discount. In addition to cash and equity compensation, we offer our employees a robust portfolio of benefits, such as health, well-being, parental leave and retirement programs, to meet their individual and family needs. Health, Safety and Well-being The health and safety of our employees is our top priority. We recognize the need to create a flexible working environment that balances collaboration, innovation and connectivity with personal preferences for employees to do their best work. Our employee wellness programs support employees across four pillars: physical, emotional, social and financial. These programs are designed to meet the needs of our employees through connection and support, with flexibility for local and targeted approaches. We will continue to review and invest in programs to provide for the health, safety and well-being of our employees. Corporate Information We were incorporated in the state of Delaware in September 2007 as SafeChannel, Inc., and in August 2008, we changed our name to Zscaler, Inc. Our principal executive offices are located at 120 Holger Way, San Jose, CA 95134, and our telephone number is (408) 533-0288 . Our website address is www.zscaler.com. Information contained on, or that can be accessed through, our website does not constitute part of this Annual Report on Form 10-K. Available Information Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, proxy statement, and all amendments to these filings, are available free of charge from our investor relations website ( https://ir.zscaler.com/financial-information/sec-filings ) as soon as reasonably practicable following our filing with or furnishing to the SEC of any of these reports. The SEC’s website (https:// www.sec.gov ) contains reports, proxy and information statements and other information regarding issuers that file electronically with the SEC. Zscaler investors and others should note that we announce material information to the public about our company, products and services and other issues through a variety of means, including our website (https://www.zscaler.com), our investor relations website (https://ir.zscaler.com), our blogs (https://www.zscaler.com/blogs), press releases, SEC filings, public conference calls and social media, in order to achieve broad, non-exclusionary distribution of information to the public. We encourage our investors and others to review the information we make public in these locations as such information could be deemed to be material information. Please note that this list may be updated from time to time. The contents of any website referred to in this Form 10-K are not intended to be incorporated into this Annual Report on Form 10-K or in any other report or document we file. 19 Table of Contents Item 1A. Risk Factors A description of the risks and uncertainties associated with our business is set forth below. You should carefully consider the risks and uncertainties described below, as well as the other information in this Annual Report on Form 10-K, including the consolidated financial statements and the related notes and "Management’s Discussion and Analysis of Financial Condition and Results of Operations." The occurrence of any of the events or developments described below, or of additional risks and uncertainties not presently known to us or that we currently deem immaterial, could materially and adversely affect our business, results of operations, financial condition and growth prospects. In such an event, the market price of our common stock could decline, and you could lose all or part of your investment. Summary of Risk Factors Investing in our common stock involves a high degree of risk because our business is subject to numerous risks and uncertainties, as more fully described in this section below this summary. The principal factors and uncertainties that make investing in our common stock risky include, among others: • we have a history of annual net losses and may not be able to achieve or sustain profitability in the future; • if organizations do not adopt our cloud platform, our ability to grow our business and operating results may be adversely affected; • if we are unable to attract new customers or our customers do not renew their subscriptions for our services and add additional users and services to their subscriptions, our future results of operations could be harmed; • we face intense and increasing competition and could lose market share to our competitors; • we have experienced rapid revenue and other growth in recent periods, which may not be indicative of our future performance; • our operating results may fluctuate significantly, which could make our future results difficult to predict and could cause our operating results to fall below expectations; • if the delivery of our services to our customers is interrupted or delayed for any reason, our business would suffer; • the actual or perceived failure of our cloud platform to block malware or prevent a security breach or incident could harm our reputation and adversely impact our business; • our business and growth depend in part on the success of our relationships with our channel partners; • if our cloud platform or internal networks, systems or data are or are perceived to have been breached, our solution may be perceived as insecure, our reputation may be damaged and our financial results may be negatively impacted; • we rely on our key technical, sales and management personnel to grow our business, and the loss of one or more key employees or the inability to attract and retain qualified personnel could harm our business; • claims by others that we infringe their proprietary technology or other rights, or other lawsuits asserted against us, could result in significant costs and substantially harm our business; • if we are unable to effectively manage certain risks and challenges related to our India operations, our business could be harmed; • servicing our debt may require a significant amount of cash, and we may not have sufficient cash flow from our business or the ability to raise funds to pay our substantial debt; and 20 Table of Contents • the impact of global economic disruptions and changing macroeconomic and geopolitical conditions remains uncertain and may have a material adverse impact on our business. Risks Related to Our Business Risks Related to Our Growth We have a history of annual net losses and may not be able to achieve or sustain profitability in the future. We have incurred net losses in all annual periods since our inception, and we expect we will continue to incur annual net losses for the foreseeable future. We experienced net losses of $41.5 million, $57.7 million and $202.3 million for fiscal 2025, fiscal 2024 and fiscal 2023, respectively. As of July 31, 2025, we had an accumulated deficit of $1,189.6 million. Because the market for our cloud platform is rapidly evolving and cloud-based security solutions have not yet reached widespread adoption, it is difficult for us to predict our future results of operations. We expect our operating expenses to increase significantly over the next several years as we continue to hire additional personnel, particularly in research and development and sales and marketing, expand our operations and infrastructure, both domestically and internationally, and continue to develop our platform. If we fail to increase our revenue to offset the increases in our operating expenses, we may not achieve or sustain profitability in the future. Additionally, our business strategy continues to focus primarily on long-term growth. As we execute on this strategy, we may ultimately be unable to achieve or sustain profitability at the level contemplated by industry or financial analysts and our stockholders, or at all, and as a result, our stock price may decline. If organizations do not adopt our cloud platform, our ability to grow our business and operating results may be adversely affected. Cloud security technologies are still evolving, and it remains difficult to predict customer demand and adoption rates for our solutions. We believe that our cloud platform offers superior protection to our customers, who are moving their applications and data to the cloud and embracing AI applications and agents. We also believe that our cloud platform represents a major shift from on-premises appliance-based security solutions. While cloud-based security solutions have seen increased adoption, traditional on-premises security appliances continue to be entrenched in the infrastructure of many of our potential customers, particularly large enterprises, because of their prior investment in and the familiarity of their IT personnel with on-premises appliance-based solutions. As a result, our sales process often involves extensive efforts to educate our customers on the benefits and capabilities of our cloud platform, particularly as we continue to pursue customer relationships with large organizations. Even with these efforts, we cannot predict long-term market acceptance of our cloud platform, or the adoption of competing products, services or technologies. If we fail to achieve broad market acceptance of our cloud platform or are unable to keep pace with industry changes, our ability to grow our business and our operating results will be materially and adversely affected. If we are unable to attract new customers, our future results of operations could be harmed. To increase our revenue and achieve and maintain profitability, we must add new customers. To add new customers, we must successfully convince IT decision makers that security delivered through our cloud platform provides significant advantages over legacy on-premises appliance-based security products and competing cloud-based products. Additionally, many of our customers broadly deploy our products, which requires a significant commitment of resources from our customers. These factors significantly impact our ability to add new customers and increase the time, resources and sophistication required to do so. 21 Table of Contents In addition, numerous other factors, many of which are out of our control, have impacted and may in the future impact our ability to add new customers, including: • potential customers’ commitments to legacy IT security vendors and products; • real or perceived switching costs; • the current or potential implementation of tariffs or retaliatory measures due to tariffs on the sales of our products in countries where our customers or potential paying customers are located; • competition from hybrid or cloud security products; • our failure to expand, retain and motivate our sales and marketing personnel; • our failure to develop or expand relationships with our channel partners or to attract new channel partners; • failure by us or our partners to help our customers to successfully deploy our cloud platform; • negative media or industry or financial analyst commentary regarding us or our solutions, or similar solutions offered by other vendors; • litigation; and • general economic conditions. As a result of challenging or uncertain macroeconomic conditions, we have experienced and may experience in the future increased scrutiny and a longer approval process for initial purchases by new customers, particularly for larger transactions. We cannot predict how challenging or uncertain macroeconomic conditions will impact potential customers' purchasing decisions and whether potential customers may decide to delay purchases, decrease the size of purchases or entirely forego purchasing our services. If our efforts to attract new customers are not successful, our revenue and rate of revenue growth may decline, we may not achieve profitability and our future results of operations could be materially harmed. If our customers do not renew their subscriptions for our services and add additional users and services to their subscriptions, our future results of operations could be harmed. In order for us to maintain or improve our results of operations, it is important that our customers renew their subscriptions for our services when existing contract terms expire, and that we expand our commercial relationships with our existing customers. Our customers have no obligation to renew their subscriptions for our services after the expiration of their contractual subscription period, which is typically one to three years, and in the normal course of business, some customers have elected not to renew. In addition, in certain cases, including under the new EU Data Act, customers may cancel their subscriptions without cause either at any time or upon advance written notice (commonly ranging from 30 days to 60 days), typically subject to an early termination penalty for unused services. In addition, our customers may renew for fewer users, renew for shorter contract lengths or switch to a lower-cost product suite. If our customers do not renew their subscription services, we could incur impairment losses related to our deferred contract acquisition costs. It is difficult to accurately predict long-term customer retention because of our varied customer base and given the length of our subscription contracts. Our customer retention and expansion may decline or fluctuate as a result of a number of factors, including our customers’ satisfaction with our services, our prices and pricing plans, our customers’ spending levels, decreases in the number of users to which our customers deploy our solutions, new laws and regulations impacting service contract terms, mergers and 22 Table of Contents acquisitions involving our customers, competition and deteriorating or uncertain general economic conditions, which may result in reductions in IT budgets and lower employee headcounts. Our future success also depends in part on the rate at which our current customers add additional users or services to their subscriptions, which is driven by a number of factors, including customer satisfaction with our services, customer security and networking issues and requirements, general economic conditions and customer reaction to the price per additional user or of additional services. If our efforts to expand our relationships with our existing customers are not successful, our business may materially suffer. We have experienced rapid revenue and other growth in recent periods, which may not be indicative of our future performance. We have experienced rapid growth in revenue, operations and employee headcount in recent periods. In addition, the number of customers, users and internet traffic on our cloud platform has increased rapidly in recent years. Our growth may not be sustainable and may not be sufficient to achieve and sustain profitability, as we also expect our costs to increase in future periods as we expand our operations and significantly increase our headcount. In addition, we expect our recent revenue growth rates will decline in the future as the size of our revenue base increases. As a result, we believe that historical comparisons of our revenue may not be meaningful and should not be relied upon as an indication of future performance. Accordingly, you should not rely on our revenue and other growth for any prior quarter or fiscal year as an indication of our future revenue or revenue growth. If we fail to effectively manage our growth, we may be unable to execute our business plan, maintain high levels of service, adequately address competitive challenges or maintain our corporate culture, and our business, financial condition and results of operations would be harmed. Our growth has placed, and future growth will continue to place, a significant strain on our management and our administrative, operational and financial infrastructure. Our success will depend in part on our ability to manage this growth effectively, which will require that we continue to improve our administrative, operational, financial and management systems and controls by, among other things: • effectively attracting, retaining, training and integrating, including collaborating with, a large number of new employees; • further improving our key business applications, processes and IT infrastructure, including through the use of AI, to support our business needs; • enhancing our information and communication systems to ensure that our employees and offices around the world are well coordinated and can effectively communicate with each other and our growing base of channel partners, customers and users; and • appropriately documenting and testing our IT systems and business processes. These and other improvements in our systems and controls will require significant capital expenditures and the allocation of valuable management and employee resources. If we fail to implement these improvements effectively, our ability to manage our expected growth, ensure uninterrupted operation of our cloud platform and key business systems and comply with the rules and regulations applicable to public companies could be impaired, the quality of our platform and services could suffer and we may not be able to adequately address competitive challenges. In addition, we believe that our corporate culture has been a contributor to our success, which we believe fosters innovation, teamwork and an emphasis on customer-focused results. We also believe that our culture creates an environment 23 Table of Contents that drives and perpetuates our strategy and cost-effective distribution approach. In the past we have, and in the future we may, restructure or reduce our workforce to align people, roles and projects to our strategic priorities. Any restructuring, reduction or realignment in the workforce has the potential to negatively impact employee morale or make it more difficult to attract and retain talent. As we continue to grow, we may find it difficult to maintain our corporate culture. Preservation of our corporate culture is also made more difficult following the implementation of our hybrid work environment, and many of our employees continue to work from home on a full time or part time basis. Any failure to preserve our culture could harm our future success, including our ability to retain and recruit personnel, innovate and operate effectively and execute on our business strategy. If we experience any of these effects in connection with future growth, it could materially impair our ability to attract new customers, support and retain existing customers and expand their use of our platform, all of which would materially and adversely affect our business, financial condition and results of operations. Our operating results may fluctuate significantly, which could make our future results difficult to predict and could cause our operating results to fall below expectations. Our operating results may fluctuate from quarter to quarter as a result of a number of factors, many of which are outside of our control and may be difficult to predict. Some of the factors that may cause our results of operations to fluctuate from quarter to quarter include: • broad market acceptance and the level of demand for our cloud platform; • our ability to attract new customers, particularly large enterprises; • our ability to retain customers and expand their usage of our platform, particularly our largest customers; • our ability to successfully expand internationally and penetrate key markets; • the effectiveness of our sales and marketing programs; • the length of our sales cycle; • the timing and availability of renewals; • the mix of billings among monthly in advance, quarterly in advance, annually in advance and multi-year in advance; • technological changes and the timing and success of new service introductions by us or our competitors or any other change in the competitive landscape of our market; • increases in and timing of operating expenses that we may incur to grow and expand our operations and to remain competitive; • pricing pressure as a result of competition or otherwise; • seasonal buying patterns for IT spending, including the possible slowdown in IT spending due to the current macroeconomic and geopolitical environment; • the quality and level of our execution of our business strategy and operating plan; • reputational harm as a result of actual, perceived or purported technological failure or disruption; • adverse litigation judgments, settlements or other litigation-related costs; • changes in the legislative or regulatory environment; • the impact and costs related to the acquisition of businesses, talent, technologies or intellectual property rights; 24 Table of Contents • fluctuations in currency exchange rates and changes in the proportion of our revenue and expenses denominated in foreign currencies; • changes in U.S. generally accepted accounting principles; and • general economic conditions in either domestic or international markets, including as a result of macroeconomic and geopolitical events, developments and conditions. Any one or more of the factors above may result in significant fluctuations in our results of operations. We also intend to continue to invest significantly to grow our business in the near future rather than optimizing for profitability or cash flows. In addition, we generally experience seasonality in terms of when we enter into agreements with customers. We typically enter into a higher percentage of agreements with new customers, as well as renewal agreements with existing customers, in the second half of our fiscal year. This seasonality is reflected to a much lesser extent, and sometimes is not immediately apparent, in revenue, due to the fact that we recognize subscription revenue ratably over the term of the subscription, which is generally one to three years. We expect that seasonality will continue to affect our operating results in the future and may reduce our ability to predict cash flow and optimize the timing of our operating expenses. The variability and unpredictability of our quarterly results of operations or other operating metrics could result in our failure to meet our expectations or those of industry or financial analysts. If we fail to meet or exceed such expectations for these or any other reasons, the market price of our common stock could fall substantially, and we could face costly lawsuits, including securities class action suits. Our business and growth depend in part on the success of our relationships with our channel partners. We currently derive most of our revenue from sales through our channel partner network, and we expect for the foreseeable future most of our future revenue growth will also be driven through this network. Not only does our joint sales approach require additional investment to grow and train our sales force, but we believe that continued growth in our business is dependent upon identifying, developing and maintaining strategic relationships with our existing and potential channel partners, including global systems integrators and regional telecommunications service providers that will in turn drive substantial revenue and provide additional value-added services to our customers. Our agreements with our channel partners are generally non-exclusive, meaning our channel partners may offer customers the products of several different companies, including products that compete with our cloud platform. Our channel partners may also cease marketing or reselling our platform with limited or no notice and without penalty. If our channel partners do not effectively market and sell subscriptions to our cloud platform, choose to promote our competitors’ products or fail to meet the needs of our customers, our ability to grow our business and sell subscriptions to our cloud platform may be adversely affected. For example, sales through our top five channel partners and their affiliates, in aggregate, represented 28% of our revenue for fiscal 2025, 25% of our revenue for fiscal 2024 and 26% of our revenue for fiscal 2023. In addition, our channel partner structure could subject us to lawsuits or reputational harm if, for example, a channel partner misrepresents the functionality of our cloud platform to customers or violates applicable laws or our corporate policies. Moreover, our channel partners' operations may be negatively impacted by events including pandemics, international conflicts, trade regulations including tariffs, inflation and other events affecting the global economy in general. For example, these events could increase credit risk of end customers and create uncertainty in credit markets. Our ability to achieve revenue growth in the future will depend in large part on our success in maintaining successful relationships with our channel partners, identifying additional channel partners and training our channel partners to independently sell and deploy our platform. If we are unable to maintain our relationships with our existing channel partners or develop successful relationships with new channel partners or if our channel partners fail to perform, our business, financial position and results of operations could be materially and adversely affected. 25 Table of Contents Risks Related to Our Products and Services We face intense and increasing competition and could lose market share to our competitors, which could adversely affect our business, financial condition and results of operations. The market for network security solutions is intensely competitive and characterized by rapid changes in technology, customer requirements, industry standards and frequent introductions of new products and services and improvements of existing products and services. We compete with many established network and security vendors who are aggressively competing against us with their legacy appliance-based solutions and have also introduced cloud-based services that purport to have functionality similar to our cloud platform. We are also experiencing increased competition as other established and emerging companies enter the cloud-based security solutions market and introduce new products, services and technologies to address evolving customer requirements. If we are unable to anticipate or effectively react to these competitive challenges, our competitive position could weaken, and we could experience a decline in revenue or our growth rate that could materially and adversely affect our business and results of operations. Our competitors and potential competitors include: • independent IT security vendors, which offer a broad mix of network and endpoint security products; • large networking and other vendors, which offer security appliances and/or incorporate security capabilities in their networking products and other services; • companies with point solutions that compete with some of the features of our cloud platform, such as proxy, firewall, CASB, sandboxing and advanced threat protection, AI security, data loss prevention, encryption, load balancing and VPN; and • other providers of IT security services that offer, or may leverage related technologies to introduce, products that compete with or are alternatives to our cloud platform. Many of our existing competitors have, and some of our potential competitors could have, substantial competitive advantages such as: • greater name recognition, longer operating histories and larger customer bases; • larger sales and marketing budgets and resources; • broader distribution and established relationships with channel partners and customers; • greater customer support resources; • greater resources to make acquisitions and enter into strategic partnerships; • lower labor and research and development costs; • larger and more mature intellectual property rights portfolios; and • substantially greater financial, technical and other resources. Our competitors may be successful in convincing IT decision makers that legacy appliance-based security products or hybrid security cloud solutions based on legacy technology are sufficient to meet their security needs and provide security performance that competes with our cloud platform. In addition, our competitors have and may develop cloud-based solutions with architectures similar to our products. Further, many organizations have invested substantial personnel and financial resources to design and operate their appliance-based networks and have established deep relationships with appliance 26 Table of Contents vendors. As a result, these organizations may prefer to purchase from their existing suppliers rather than add or switch to a new supplier. Our larger competitors have substantially broader and more diverse product and services offerings, which may allow them to leverage their relationships based on other products or incorporate functionality into existing products to gain business in a manner that discourages users from purchasing our services, including through selling at zero or negative margins, offering free services and other concessions, bundling products or maintaining closed technology platforms. Many competitors that specialize in providing protection from a single type of security threat may be able to deliver these targeted security products to the market more quickly than we can or to convince organizations that these limited products meet their needs. Conditions in our market change rapidly and significantly as a result of technological advancements, partnering or acquisitions by our competitors or continuing market consolidation. Start-up companies that innovate and large competitors that are making significant investments in research and development may introduce similar or superior products, services and technologies that compete with our cloud platform. In addition, large companies with substantial communications infrastructure, such as global telecommunications services provider partners or public cloud providers, have entered or could choose to enter the security solutions market. Some of our current or potential competitors have made or could make acquisitions of businesses or establish cooperative relationships that may allow them to offer more directly competitive and comprehensive solutions than were previously offered and adapt more quickly to new technologies and customer needs. These competitive pressures in our market or our failure to compete effectively may result in price reductions, fewer orders, reduced revenue and gross margins, increased net losses and loss of market share. Any failure to meet and address these factors could materially harm our business and operating results. If the delivery of our services to our customers is interrupted or delayed for any reason, our business would suffer. Any interruption or delay in the delivery of our services will negatively impact our customers. Our solutions enable secure connections to cloud-based applications and other destinations via the internet, by directing our customers’ internet traffic through our cloud platform. Our customers depend on the continuous availability of our cloud platform to access the internet, and our services are designed to operate without interruption in accordance with our service level commitments. However, our platform is complex and may contain defects or errors that are not detected until after deployment. If we fail to timely detect defects or errors before deployment, or if our entire platform were to fail, customers and users could lose access to critical services and applications until the disruption is resolved or customers deploy our disaster recovery solution that allows them to bypass our cloud platform to access the internet. The adverse effects of any service interruptions on our reputation and financial condition may be disproportionately heightened due to the nature of our business and the fact that our customers expect continuous and uninterrupted internet access and have a low tolerance for interruptions of any duration. While we do not consider them to have been material, we have experienced, and may in the future experience, service disruptions and other performance problems due to a variety of factors. The following factors, many of which are beyond our control, can affect the delivery and availability of our services and the performance of our cloud: • the development and maintenance of the infrastructure of the internet; • the performance and availability of third-party telecommunications services with the necessary speed, data capacity and security for providing reliable internet access and services; • decisions by the owners and operators of the data centers where our cloud infrastructure is deployed or by global telecommunications service provider partners who provide us with network bandwidth to terminate our contracts, 27 Table of Contents discontinue services to us, shut down operations or facilities, increase prices, change service levels, limit bandwidth, declare bankruptcy or prioritize the traffic of other parties; • the occurrence of earthquakes, floods, fires, pandemics, power loss, system failures, physical or electronic break-ins, acts of war, international conflicts (such as the current conflicts between Russia and Ukraine and in the Middle East) or terrorism, human error or interference (including by disgruntled or negligent, current or former employees or contractors) and other catastrophic events; • cyberattacks, including denial of service attacks, targeted at us, our data centers, our global telecommunications service provider partners or the infrastructure of the internet; • government action to limit access to the internet; • failure by us to maintain and update our cloud infrastructure to meet our traffic capacity requirements; • errors, defects or performance problems in our software, including those potentially introduced by our software updates and third-party software incorporated in our software, which we use to operate our cloud platform; • improper classification of websites by our vendors who provide us with lists of malicious websites; • improper deployment or configuration of our services by our customers; • the failure of our redundancy systems, in the event of a service disruption at one of our data centers, to provide failover to other data centers in our data center network; • the failure of our disaster recovery and business continuity arrangements; and • the potential implementation of export controls, tariffs or retaliatory measures on the sales of our products in countries where our customers or potential customers are located. The occurrence of any of these factors, or if we are unable to efficiently and cost-effectively fix such errors or other problems that may be identified, could damage our reputation, negatively impact our relationship with our customers or otherwise materially harm our business, results of operations and financial condition. In addition, we provide our services through a cloud-based inline proxy, and some governments, third-party products, websites or services may block proxy-based traffic under certain circumstances. For example, vendors may attempt to block traffic from our cloud platform or blacklist our IP addresses because they cannot identify the source of the proxy-based traffic. Our competitors may use this as an excuse to block traffic from their solutions or blacklist our IP addresses, which may result in our customers’ traffic being blocked from our platform. If our customers experience significant instances of traffic blockages, they will experience reduced functionality or other inefficiencies, which would reduce customer satisfaction with our services and likelihood of renewal. If we fail to develop or introduce new enhancements to our cloud platform on a timely basis, our ability to attract and retain customers, remain competitive and grow our business could be impaired. The industry in which we compete is characterized by rapid technological change, frequent introductions of new products and services, evolving industry standards and changing regulations, as well as changing customer needs, requirements and preferences. Our ability to attract new customers and increase revenue from existing customers will depend in significant part on our ability to anticipate and respond effectively to these changes on a timely basis and continue to introduce enhancements to our cloud platform. For example, advancements in technology, such as AI and ML, are changing the way our industry identifies and responds to cyber threats, and businesses that are slow to adopt or fail to adopt these new 28 Table of Contents technologies may face a competitive disadvantage. The success of our cloud platform depends on our continued investment in our research and development organization to increase the reliability, availability and scalability of our existing solutions. The success of any enhancement depends on several factors, and any new service that we develop or acquire might not be introduced in a timely or cost-effective manner and might not achieve the broad market acceptance necessary to generate significant revenue. If new technologies, including AI-enabled technologies, emerge that deliver competitive products and services at lower prices, more efficiently, more conveniently or more securely, these technologies could adversely impact our ability to compete effectively. Any delay or failure in the introduction of enhancements could materially harm our business, results of operations and financial condition. If our global network of data centers, which deliver our services, was damaged or otherwise failed to meet the requirements of our business, our ability to provide services to our customers and maintain the performance of our cloud platform could be negatively impacted, which could cause our business to suffer. We currently host our cloud platform and serve our customers from a global network of over 160 public exchanges globally and thousands of private exchanges at the edge. While we have electronic access to the components and infrastructure of our cloud platform that are hosted by third parties, we do not control the operation of these facilities. Consequently, we may be subject to service disruptions as well as a lack of adequate support for our data center operations due to reasons that are outside of our control. Our data centers are vulnerable to damage and connections to our data centers may be interrupted by a variety of sources, including earthquakes, floods, fires, power loss, system or infrastructure failures, computer viruses, physical or electronic break-ins, human error or interference (including by disgruntled or negligent, current or former employees or contractors) and other catastrophic events. Our data centers may also be subject to national or local administrative actions, changes in government regulations, including, for example, the impact of global economic and other sanctions like those levied in response to the current conflict between Russia and Ukraine, changes to legal or permitting requirements and litigation to stop, limit or delay operations. Despite precautions taken at these facilities, a decision to close the facilities without adequate notice or other unanticipated problems at these facilities could result in interruptions or delays in our services, impede our ability to scale our operations or have other adverse impacts upon our business. In addition, if we do not accurately plan for our infrastructure capacity requirements or experience significant strains on our data center capacity, we may experience delays and additional expenses in arranging new data centers, and our customers could experience performance degradation or service outages that may subject us to financial liabilities, result in customer losses and materially harm our business. If our cloud platform or internal networks, systems or data are or are perceived to have been breached, our solution may be perceived as insecure, our reputation may be damaged and our financial results may be negatively impacted. It is virtually impossible for us to entirely mitigate the risk of breaches of our cloud platform or other security incidents affecting our cloud platform or our internal systems, networks or data. In addition, the functionality of our platform may be disrupted, either intentionally or due to negligence, including by disgruntled or negligent, current or former employees or contractors. The security measures we use internally and have integrated into our cloud platform, which are designed to detect unauthorized activity and prevent or minimize security breaches, may not function as expected or may not be sufficient to identify or protect against certain attacks. Enterprises are subject to a wide variety of attacks on their networks and systems, and techniques used to sabotage or to obtain unauthorized access to networks in which data is stored or through which data is transmitted change frequently and generally are not recognized until launched against a target. The growth in state sponsored cyber activity, including those actions taken in connection with the current conflict between Russia and Ukraine, showcase the increasing sophistication of cyber threats. As a result, we may be unable to anticipate these techniques or implement adequate measures to prevent an electronic intrusion into our customers through our cloud platform or to prevent breaches and other security incidents affecting our cloud platform, internal networks, systems or data. Further, once identified, we may be unable to remediate or otherwise respond to a breach or other incident in a timely manner. Actual, 29 Table of Contents perceived or purported security breaches of our cloud platform could result in actual, perceived or purported breaches of our customers’ networks and systems. Our internal systems are exposed to the same cybersecurity risks and consequences of a breach as our customers and other enterprises. However, since our business is focused on providing reliable security services to our customers, we believe that an actual, perceived or purported breach of, or security incident affecting, our internal networks, systems or data, could be especially detrimental to our reputation, customer confidence in our solution and our business. Additionally, many of our personnel work remotely on a hybrid or permanent basis, which may pose additional data security risks. Further, our vendors and service providers have been, and may in the future be, the targets of cyberattacks, and their systems and networks have been, and may in the future be, breached or may contain exploitable defects or bugs that could result in a breach of or disruption to their or our systems and networks. Our ability to monitor our vendors’ and service providers’ data security is limited, and, in any event, third parties may be able to circumvent their security measures, resulting in the unauthorized access to, misuse, disclosure, loss, alteration, or destruction of our data, including confidential, sensitive, and other information about individuals. Geo-political factors including international conflicts, such as between Russia and Ukraine and in the Middle East, may increase the risk of such cyberattacks. Any actual, perceived or purported security breaches or other security incidents that we suffer with regard to our platform, systems, networks or data, including any such actual, perceived or purported security breaches or security incidents that result, or are believed to result, in actual, perceived or purported breaches of our customers’ networks or systems, could result in: • the expenditure of significant financial resources in efforts to analyze, correct, eliminate, remediate or work around errors or defects, to address and eliminate vulnerabilities and to address any applicable legal or contractual obligations relating to any actual, perceived or purported security breach or other security incident; • negative publicity and damage to our reputation, brand, and market position; • harm to our relationships with, and a loss of, existing or potential customers or channel partners; • delayed or lost sales and harm to our financial condition and results of operations; • a delay in attaining, or the failure to attain, market acceptance; and • legal claims and demands (including for stolen assets or information, repair of system damages and compensation to customers, customers of customers and business partners), litigation (including stockholder claims), regulatory inquiries or investigations and other liability. Any of the above could materially and adversely affect our business, financial condition and results of operations. While we maintain insurance, our insurance may be insufficient to cover all liabilities incurred in relation to actual, perceived or purported security breaches or other security incidents. We also cannot be certain that our insurance coverage will be adequate for liabilities actually incurred, that insurance will continue to be available to us on economically reasonable terms, or at all, or that any insurer will not deny coverage as to any future claim. The successful assertion of one or more large claims against us that exceed available insurance coverage, or the occurrence of changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, could have a material adverse effect on our business, including our financial condition, operating results and reputation. 30 Table of Contents If our cloud platform does not interoperate with our customers’ network and security infrastructure or with third-party products, websites or services, our cloud platform may become less competitive and our results of operations may be harmed. Our cloud platform must interoperate with our customers’ existing network and security infrastructure. These complex systems are developed, delivered and maintained by the customer and a myriad of vendors and service providers. As a result, the components of our customers’ infrastructure have different specifications, rapidly evolve, utilize multiple protocol standards, include multiple versions and generations of products and may be highly customized. We must be able to interoperate and provide our security services to customers with highly complex and customized networks, which requires careful planning and execution between our customers, our customer support teams and our channel partners. Further, when new or updated elements of our customers’ infrastructure or new industry standards or protocols are introduced, we may have to update or enhance our cloud platform to allow us to continue to provide services to customers. Our competitors or other vendors may refuse to work with us to allow their products to interoperate with our solutions, which could make it difficult for our cloud platform to function properly in customer networks that include these third-party products. We may not deliver or maintain interoperability quickly or cost-effectively, or at all. These efforts require capital investment and engineering resources. If we fail to maintain compatibility of our cloud platform with our customers’ network and security infrastructures, our customers may not be able to fully utilize our solutions, and we may, among other consequences, lose or fail to increase our market share and experience reduced demand for our services, which would materially harm our business, operating results and financial condition. Risks Related to Our Sales and Operations If we are not able to maintain and enhance our brand, our business and results of operations may be adversely affected. We believe that maintaining and enhancing our reputation as a provider of high-quality security solutions is critical to our relationship with our existing customers and channel partners and our ability to attract new customers and channel partners. The successful promotion of our brand will depend on a number of factors, including our marketing efforts, our ability to continue to develop high-quality features and solutions for our cloud platform, uninterrupted delivery of our cloud services and our ability to successfully differentiate our platform from competitive products and services. Our brand promotion activities may not be successful or yield increased revenue. In addition, independent industry or financial analysts often provide reviews of our platform, as well as products and services of our competitors, and perception of our platform in the marketplace may be significantly influenced by these reviews. If these reviews are negative, or less positive as compared to those of our competitors’ products and services, our brand may be adversely affected. Additionally, the performance of our channel partners may affect our brand and reputation if customers do not have a positive experience with our channel partners’ services. The promotion of our brand requires us to make substantial expenditures, and we anticipate that the expenditures will increase as our market becomes more competitive, we expand into new markets and more sales are generated through our channel partners. To the extent that these activities yield increased revenue, this revenue may not offset the increased expenses we incur. If we do not successfully maintain and enhance our brand, our business may not grow, we may have reduced pricing power relative to competitors and we could lose customers or fail to attract potential customers, all of which would materially and adversely affect our business, results of operations and financial condition. If we do not effectively develop and expand our sales and marketing capabilities, we may be unable to add new customers or increase sales to our existing customers, and our business will be adversely affected. To increase the number of customers and increase the market acceptance of our platform, we will need to expand our sales and marketing operations, including our domestic and international sales force. Although we have a channel sales model, our sales representatives typically engage in direct interaction with our prospective customers. Therefore, we continue 31 Table of Contents to be substantially dependent on our sales force to obtain new customers. Increasing our customer base and achieving broader market acceptance of our cloud platform will depend, to a significant extent, on our ability to expand and further invest in our sales and marketing operations and activities. There is significant competition for sales personnel with the advanced sales skills and technical knowledge we need. We believe that selling a cloud-based security solution requires particularly talented sales personnel with the ability to communicate the transformative potential of our cloud platform. Our ability to achieve significant growth in revenue in the future will depend, in large part, on our success in recruiting, training and retaining enough talented sales personnel in both the U.S. and international markets. New hires require significant training and may take significant time before they achieve full productivity. As a result, our new hires and planned hires may not become as productive as we would like, and we may be unable to hire or retain enough qualified individuals in the future. As a result of our rapid growth, a large percentage of our sales and marketing team is new to our company and selling our solutions, and therefore this team may be less effective than our more seasoned employees. Furthermore, hiring sales personnel in new countries, or expanding our existing presence, requires upfront and ongoing expenditures that we may not recover if the sales personnel fail to achieve full productivity. We cannot predict whether, or to what extent, our sales will increase as we expand our sales force or how long it will take for sales personnel to become productive. The effectiveness of our sales and marketing has also varied over time and, together with the effectiveness of any partners or resellers we may engage, may vary in the future. Our business and operating results may be harmed if our efforts do not generate a correspondingly significant increase in revenue. We may not achieve anticipated revenue growth from expanding our sales force if we are unable to hire, develop and retain talented sales personnel, if our new sales personnel are unable to achieve desired productivity levels in a reasonable period of time, or if our sales and marketing programs are not effective. Our sales cycles can be long and unpredictable, and our sales efforts require considerable time and expense. The timing of our sales and related revenue recognition is difficult to predict because of the length and unpredictability of the sales cycle for our cloud platform, particularly with respect to large organizations. Our sales efforts typically involve educating our prospective customers about the uses, benefits and the value proposition of our cloud platform. Customers often view the subscription to our cloud platform as a significant decision as part of a strategic transformation initiative and, as a result, frequently require considerable time to evaluate, test and qualify our platform prior to entering into or expanding a relationship with us. Large enterprises and government entities in particular often undertake a significant evaluation process that further lengthens the sales cycle. In addition, the impact of macroeconomic or geopolitical conditions could materially and adversely affect our business, operating results and financial condition by reducing sales, lengthening sales cycles and lowering prices for our services. We have experienced and may experience in the future increased scrutiny and a longer approval process for initial purchases by new customers, as a result of challenging macroeconomic conditions. Our sales force develops relationships directly with our customers, and together with our channel account teams, works with our channel partners on account penetration, account coordination, sales and overall market development. We spend substantial time and resources on our sales efforts without any assurance that our efforts will produce a sale. Platform purchases are frequently subject to budget constraints, multiple approvals and unanticipated administrative, processing and other delays. As a result, it is difficult to predict whether and when a sale will be completed and when revenue from a sale will be recognized. Sales to larger customers involve risks that may not be present, or that are present to a lesser extent, with sales to smaller customers, which can act as a disincentive to our sales team to pursue these larger customers. These risks include: • competition from companies that traditionally target larger enterprises and that may have pre-existing relationships or purchase commitments from such customers; • increased purchasing power and leverage held by larger customers in negotiating contractual arrangements with us; 32 Table of Contents • more stringent requirements in our support obligations; and • longer sales cycles and the associated risk that substantial time and resources may be spent on a potential customer that elects not to purchase our solutions. The failure of our efforts to secure sales after investing resources in a lengthy sales process could materially and adversely affect our business and operating results. Because we recognize revenue from subscriptions for our services over the term of the subscription, downturns or upturns in new business may not be immediately reflected in our operating results and may be difficult to discern. We generally recognize revenue from customers ratably over the terms of their subscriptions, which are typically one to three years. As a result, a substantial portion of the revenue we report in each period is attributable to the recognition of deferred revenue relating to agreements that we entered into during previous periods. Consequently, any increase or decline in new sales or renewals in any one period may not be immediately reflected in our revenue for that period. Any change, however, may affect our revenue in future periods. Additionally, subscriptions that are invoiced annually in advance or multi-year in advance contribute significantly to our short-term and long-term deferred revenue. Accordingly, the effect of downturns or upturns in new sales and potential changes in our rate of renewals may not be fully reflected in our results of operations until future periods. We may also be unable to reduce our cost structure in line with a significant deterioration in sales or renewals. Our subscription model also makes it difficult for us to rapidly increase our revenue through additional sales in any period, as revenue from new customers must be recognized over the applicable subscription term. We provide service level commitments under our customer contracts. If we fail to meet these contractual commitments, we could be obligated to provide credits for future service and our business could suffer. Our customer agreements contain service level commitments, which contain specifications regarding the availability and performance of our cloud platform. Any failure of or disruption to our infrastructure could impact the performance of our platform and the availability of services to customers. If we are unable to meet our stated service level commitments or if we suffer extended periods of poor performance or unavailability of our platform, we may be contractually obligated to provide affected customers with service credits for future subscriptions, and, in certain cases, refunds. In addition, the limitation of liability provisions in our customer agreements may not fully or effectively protect us from claims as a result of federal, state or local laws or ordinances or unfavorable judicial decisions in the United States or other countries. To date, there has not been a material failure to meet our service level commitments, and we do not currently have any material liabilities accrued on our balance sheet for such commitments. Our revenue, other results of operations and financial condition could be harmed if we suffer performance issues or downtime that exceeds the service level commitments under our agreements with our customers. Our ability to maintain customer satisfaction depends in part on the quality of our customer support, including the quality of the support provided on our behalf by certain channel partners. Failure to maintain high-quality customer support could have an adverse effect on our business, financial condition and results of operations. If we do not provide superior support to our customers, our ability to renew subscriptions, increase the number of users and sell additional services to customers may be adversely affected. We believe that successfully delivering our cloud solution requires a highly skilled level of customer support and engagement. We or our channel partners must assist our customers to deploy our cloud platform, resolve performance issues, address interoperability challenges with a customer’s existing network and security infrastructure and respond to security threats and cyberattacks. Many enterprises, particularly large organizations, have very complex networks and require high levels of focused support, including premium support offerings, to fully realize the benefits of our cloud platform. Any failure by us to maintain the expected level of support could reduce customer satisfaction and hurt our customer retention, particularly with respect to our large enterprise customers. 33 Table of Contents Additionally, if our channel partners do not provide support to the satisfaction of our customers, we may be required to provide this level of support to those customers, which would require us to hire additional personnel and to invest in additional resources, including the possible use of AI support agents. We may not be able to hire or deploy such resources fast enough to keep up with demand, particularly if the sales of our platform exceed our internal forecasts. We may also not be successful in our efforts to fully onboard new hires and provide adequate training to our employees, many of whom continue to work remotely. To the extent that we or our channel partners are unsuccessful in hiring, training, retaining or deploying adequate support resources, our ability and the ability of our channel partners to provide adequate and timely support to our customers will be negatively impacted, and our customers’ satisfaction with our cloud platform could be adversely affected. We currently rely in part on contractors provided by third-party service providers internationally to provide support services to our customers, and we expect to expand our international customer service support team to other countries. Any failure to properly train or oversee such contractors could result in a poor customer experience and an adverse impact on our reputation and ability to renew subscriptions or engage new customers. Furthermore, as we sell our solutions internationally, our support organization faces additional challenges, including those associated with delivering support, training and documentation in languages other than English. Any failure to maintain high-quality customer support, or a market perception that we do not maintain high-quality support, could materially harm our reputation, adversely affect our ability to sell our solutions to existing and prospective customers and could harm our business, financial condition and results of operations. We rely on our key technical, sales and management personnel to grow our business, and the loss of one or more key employees or the inability to attract and retain qualified personnel could harm our business. Our future success is substantially dependent on our ability to attract, retain and motivate the members of our management team and other key employees throughout our organization. In particular, we are highly dependent on the services of Jay Chaudhry, our Chief Executive Officer and chairman of our board of directors, who is critical to our future vision and strategic direction. We rely on our leadership team in the areas of operations, security, marketing, sales, support and general and administrative functions, and on individual contributors on our research and development team. Although we have entered into employment agreements with our key personnel, these agreements have no specific duration and constitute at-will employment. We do not maintain key person life insurance policies on any of our employees. The loss of one or more of our executive officers or key employees could seriously harm our business. We have added several new senior management employees in recent years, including our Chief Financial Officer. Any significant leadership change or senior management transition involves risk, especially nearly simultaneous changes involving so many leaders and employees, and any failure to transition effectively or to retain these new leaders could hinder our strategic planning, business execution and future performance. To execute our growth plan, we must attract and retain highly qualified personnel. Competition for these personnel in the San Francisco Bay Area, where our headquarters are located, and in other locations where we operate, is often intense, especially for experienced sales professionals and for engineers experienced in designing and developing cloud applications, security software and AI and ML solutions. In addition, the United States and other regions in which we operate have in the past and may again in the future experience acute workforce shortages for highly skilled workers, which in turn, can create hyper-competitive wage environments that may impact our ability to attract and retain employees. We have from time to time experienced, and we may continue to experience, difficulty in hiring and retaining employees with appropriate qualifications. For example, in recent years, recruiting, hiring and retaining employees with expertise in the cybersecurity industry has become increasingly difficult as the demand for cybersecurity professionals has increased as a result of the ongoing cybersecurity attacks on global corporations and governments. Many of the companies with which we compete for experienced personnel have greater resources than we have. In addition, job candidates and existing employees often consider the value of the equity awards they receive in connection with their employment. Volatility or lack of performance in our stock price may also affect our ability to attract and retain our key employees. 34 Table of Contents If we fail to successfully attract, integrate or retain qualified personnel to fulfill our current or future needs, or if we need to materially increase the value of the compensation packages necessary to attract and retain these employees, our business, operating results and financial condition could be materially and adversely affected. Our business depends, in part, on sales to the public sector and significant changes in the contracting or fiscal policies of public sector organizations could have an adverse effect on our business and operating results. We derive a significant portion of our revenue from contracts with government organizations, and we believe the success and growth of our business will in part depend on adding public sector customers and expanding sales to existing government customers. However, demand from government organizations is often unpredictable, and we may not be able to maintain or grow our revenue from the public sector. Sales to government entities are subject to substantial risks, including the following: • selling to government agencies can be highly competitive, expensive and time-consuming, often involving significantly longer procurement cycles than commercial sales, and significant upfront time and expense without any assurance that such efforts will generate a sale; • U.S. or other government requirements relating to the formation, administration and performance of contracts with the public sector affect how we and our channel partners do business with governmental agencies; • U.S. or other government certification requirements applicable to our cloud platform, including the Federal Risk and Authorization Management Program (FedRAMP), are often difficult and costly to obtain and maintain and failure to do so will restrict our ability to sell to government customers; • government demand and payment for our services may be impacted by public sector budgetary cycles and annual funding authorizations (including the impacts of possible government shutdowns and changes in governmental administrations) and government sales are inherently at risk of securing funding; • sales to the U.S. and other governments are subject to procurement regulations, which impose heightened compliance obligations on us and our channel partners; • governments routinely investigate and audit government contractors’ administrative processes and compliance with procurement regulations and any unfavorable investigation or audit could result in fines, civil or criminal liability, further investigations, damage to our reputation and debarment from further government business; • government customers procuring commercial items get the benefit of more favorable terms and conditions by operation of law, regardless of agreed upon contractual terms; and • changes in government policy positions, including tariffs and other trade regulations, or the threat of such changes; spending priorities or reductions in government employees or programs, which result in a reduction of government spending in general or on technology and cybersecurity products in particular. The occurrence of any of the foregoing could cause governments and governmental agencies to delay or refrain from purchasing our solutions in the future and could result in temporary suspension or permanent debarment from sales to government organizations. Any such penalties, disruptions or limitations in our or our channel partners' ability to do business with the public sector could have a material adverse effect on our business, operating results, financial condition and prospects. 35 Table of Contents