Sanjay Beri
Analyst · RBC Capital Markets
Thanks, Michelle. We had a strong second quarter with our results reflecting durable demand for Netskope's highly differentiated platform. In the age of AI, security and network modernization have become inseparable, and businesses can no longer afford to trade security for performance. As enterprises embrace AI and cloud, they need a modern architecture that understands the context and intent of today's internet, cloud and AI environments. This architecture must protect massive amounts of transactions and data spanning thousands of cloud and private applications and data stores, billions of websites and other destinations and a vast set of commercial and open-weight AI apps and models. It must inspect and control traffic in real time at high speed and with data sovereignty. The need for this architecture is becoming even more acute as the volume and velocity of transactions and data and the number of humans and AI agents originating these transactions and operating on data grows exponentially. Netskope uniquely delivers this modern, scalable, resilient and sovereign real-time architecture through the combination of our Netskope One platform and NewEdge Private Cloud network. This is why customers are choosing us as the trusted partner to help them say yes to AI. They want to capture the enormous potential of one of the most defining technologies of our lifetime without compromising security, performance or control. This positions us exceptionally well to address a massive $170 billion greenfield opportunity in AI security within our $336 billion total addressable market. I'll come back to that in a moment. First, a few highlights from the quarter. We ended Q2 with ARR of $899 million, up 27% year-over-year and delivered net new ARR of $54 million. Revenue grew 29% year-over-year to $221 million, ahead of our guidance, and our net retention rate, or NRR, increased to 114%. Our outperformance flowed through to the bottom line with our operating margin improving 11 percentage points year-over-year to negative 9%, significantly ahead of our guided range. Demand for our Netskope One platform of 25-plus security, networking, analytics and AI products remain strong as enterprises continue to modernize their infrastructure for the AI era. We were particularly encouraged by the traction from our recently announced AI security suite. While it's still early, we're seeing strong customer engagement and rapid pipeline generation for these products with some deals closed and many more currently in the proof of concept or POC stage. Enterprises globally remain strategically focused on modernizing their security and infrastructure, reducing technology sprawl, protecting sensitive transactions and data, ensuring data sovereignty and, of course, safely using AI. A hot topic in my daily dialogues with CXOs is the fact AI creates exponentially more transactions and data and a much more complex attack surface and how modernization and AI adoption go hand-in-hand. The Mythos moment this past spring underscored just how quickly the landscape is changing. The pace of innovation across frontier models and increasingly capable open-weight models is accelerating the ability to discover vulnerabilities and strengthen defenses at AI speed. But that same acceleration works both ways. These models are also lowering the barrier for attackers, compressing the time from discovery to exploitation and expanding the attack surface, not only through human adversaries, but increasingly through autonomous AI agents operating at machine speed. We are already seeing this play out with AI agents escaping isolated environments, exploiting vulnerabilities, escalating privileges, moving laterally and stealing credentials, even when they were not explicitly instructed to attack. They were simply asked to complete a cybersecurity benchmark, and when the intended route proved difficult, found another path to the answer. This is perhaps the clearest example yet of cyber risk extending beyond human attackers leveraging AI. Malicious intent is no longer the security threshold. An agent does not need to be prompted to be a bad actor. Instead, a stated task, enough autonomy in an environment that can be circumvented can be enough to do damage. All this reinforces that rogue agent risk is not an isolated incident or a mishap. It is a real and emerging control risk that CISOs face today and considerably broadens the security problem. And this is why AI security is becoming such a critical priority for enterprises. The challenge is no longer simply how to secure AI models or prevent employees from using AI. It's how to give enterprises the visibility, control, protection and performance they need as AI becomes deeply embedded across their people, applications, data and increasingly autonomous agents. I've had more than 100 conversations with customers this quarter. And in almost every one of them, a CISO or CIO comes back to the same question, how do we move faster with AI without losing control? Security, IT and infrastructure leaders don't want to say no to using AI. They want to say yes to it but do so safely. Let me share a few challenges they are facing and how Netskope is helping solve it. First, let's start with visibility. The majority of customers I talk to about AI security do not know what or how AI models and applications are being used, what corporate data is being fed into them, where agents are in their organization, what they have access to and what they are doing. Netskope's platform solves this problem by allowing companies to answer the question of what AI am I using, including providing full visibility into agentic and MCP traffic via our Agentic Broker. It bridges the gap between human or agent and LLM interactions or machine-to-machine workflows. Agentic Broker has been a natural starting point for customers securing AI and a game changer as they tackle unsanctioned and unmonitored AI usage in their organizations. In addition, our recently released AI Command Center provides customers with a unified, real-time, continuous and correlated view of where their AI risk is and makes policy and remediation recommendations that help them act on it. The second issue customers are grappling with is how to put the right defense layer around AI to prevent AI-specific threats like prompt injection and jailbreaking and to ensure models adhere to company policy, preventing misuse or unwanted responses. Imagine a scenario where an adversary attempts to override system rules through a multi-turn attack in order to exfiltrate data. Our AI Guardrails solution is designed precisely to help customers address this. In addition, our AI Gateway secures API traffic between private applications, autonomous agents and LLMs and can be deployed on-premises or in the cloud. Third, customers need a highly performing network that can handle the exceptional volume of AI transactions and data and the growing amount of highly interactive, latency-sensitive agentic communications while ensuring they're adhering to strict regulations, including data sovereignty. Our NewEdge Private Cloud spans more than 120 data centers around the globe, and we operate all our products in our unified platform in each location, creating distinct performance and sovereignty advantages. NewEdge also allows customers to define geo-based policies to control exactly where their AI, security and networking processing occurs, giving them sovereignty over their transactions and data wherever it lives or flows. Customers are seeing that today's AI environment has become a watershed moment for security. AI security-related pipeline is growing at a rapid pace and deals are moving into proof-of-concept phases. In fact, we estimate that approximately 1/3 of our AI security pipeline is already in or entering the important POC phase. In general, enterprises are following their structured budgeting, validation, executive approval and procurement life cycle, which typically takes 6 to 12 months. Let me share a few early AI security wins closed during the second quarter and the use cases we solve for customers. First, a global electronics manufacturer in EMEA needed visibility into agentic or MCP traffic, a way to understand the associated risk, enable governance and apply a control point to enforce policy. In Q2, they expanded their existing Netskope deployment with a broad AI security upsell, including AI Guardrails, our DLP AISecOps Agent, Agentic Broker and AI Gateway. They're putting the controls in place to safely embrace agentic AI rather than having to slow down or shut it off. In another example, a large auto insurer had a mandate from leadership to drive AI adoption company-wide, but they recognized that they couldn't move at that pace without the right security and governance foundation. In Q2, they expanded their Netskope One platform with AI Guardrails, AI Gateway, Agentic Broker with DLP and Red Teaming, giving them the visibility, controls and guardrails to move forward with AI confidently. These wins showcase how we are enabling customers to say yes to AI today, letting them safely use, not block, AI and move faster with it, but with the confidence that their transactions and data are protected, their AI usage is governed, and their agents are operating within appropriate boundaries. Netskope delivers that AI runtime security with the guardrails and high-performance network customers need to adopt AI broadly without compromising security or user experience. As security leaders navigate an increasingly complex AI landscape from open-weight models to closed frontier models, from copilots to autonomous agents and from traditional AI applications to MCP-based interactions, they need a platform that can see, understand and govern all of it. That is what Netskope One was built to do. From inception, our AI-native platform was built to give customers granular visibility and real-time context and control of all their transactions, users, agents, tool calls, data and more. This includes dynamically and intelligently understanding the nature, intent and risk of those transactions, combined with a high-performance private cloud network that delivers both security and performance and enables real-time policy and security enforcement. That foundation is now becoming even more important in the AI era. We're excited to see this important validation of our product market fit and strategy resonating with our existing customers as well as a strong AI pipeline of opportunity with new customers. In addition to our early success in AI security, our platform selling motion continues to drive momentum across our SSE and SASE business with customers increasingly adopting more products across our Netskope One portfolio. The number of customers spending more than $100,000 in ARR during Q2 grew 23% year-over-year and 59% of our customers are now using 4 or more Netskope One products, up from 51% a year ago. During the second quarter, we had great new logo and expansion wins across geographies and key verticals like financial services, manufacturing, health care, telecom and government. Let me share a few that illustrate the key problems we solve for customers across key use cases. First, customers continue to select our Netskope One platform to modernize for the cloud and AI. As I mentioned previously, modernization is an important precursor to AI-safe adoption. As such, customers are adopting our SSE and SASE offerings as the infrastructure and foundation to then build on and adopt our AI security offerings. We saw this in a great new logo win with a U.S. financial services company in which cloud modernization and AI enablement are key initiatives driving their future growth and scale. Our platform differentiation across network and security helped us win a competitive deal in which they purchased 8 products across our SASE suite. In addition, they also landed with our AI Guardrails and Agentic Broker AI security products. Similarly, we landed another cloud modernization and AI deal with a leading technology company who needed to improve SaaS and cloud visibility and data protection, protect and govern AI usage, including shadow AI, and monitor and control MCP traffic. Again, our single unified platform and highly performant NewEdge network were the differentiating factors against competitors in this deal. We also continue to see customers replace legacy infrastructure with our modern SASE architecture built for scale. For example, a Fortune 500 health care provider selected Netskope to modernize security, replace fragmented legacy systems and consolidate vendor sprawl with a unified platform for a global distributed workforce. Doing so required protecting highly sensitive IP and other data for regulatory compliance and safely enabling and governing increased GenAI usage. Our highly granular contextual controls, unified data protection and NewEdge high performance were key drivers in winning the 7-figure multiproduct deal from an incumbent competitor. And finally, data sovereignty is increasingly important for customers in highly regulated industries and governments. For example, we expanded with a European government agency that chose us for our data sovereignty capabilities and bought our digital experience management to pair with our in-country NewEdge network for optimized user experience. Another example is a new win with a financial services company where data sovereignty is key to regulatory compliance. In addition to achieving this with our NewEdge Data Planes, which run all of our products at the Sovereign Edge, they also consolidated and modernized their legacy network security tools with Netskope's unified SSE platform. As these wins demonstrate, customers are gravitating to Netskope to modernize their network, become a core security platform for the cloud and AI era and eliminate the trade-off between security and network performance. Shifting gears a bit, we've long believed in openness, industry collaboration and integration across our ecosystem. Earlier this year, we joined Anthropic's Project Glasswing and OpenAI's Daybreak programs and released integrations with these and other cloud and AI partners. These partnerships demonstrate the important role Netskope plays within the broader AI and security landscape. In Q2, we continued to expand and deepen these collaborations in addition to announcing important new partnerships. We were pleased to join NVIDIA's Open Secure AI Alliance, a coalition of industry leaders committed to building open frontier AI tools that defenders can inspect, adapt and trust. The world needs both open and closed frontier models, orchestrated proactively and with care across the entire AI ecosystem to truly bring positive impactful outcomes to the world. NVIDIA has been a terrific partner to build alongside, and this initiative accelerates our commitment in building open AI tools, ensuring our enterprise customers can trust, adapt and securely deploy advanced AI across their environments. We were also pleased to join CrowdStrike's Project QuiltWorks, integrating real-time data from Netskope into Falcon's Next-Gen SIEM, giving critical insight across users, applications and data and helping defenders correlate risk automatically and prioritize action faster. We also continued to broaden our collaboration with Anthropic, integrating our industry-recognized DLP and threat scanning with Claude Enterprise. In addition, we announced an integration with Amazon Bedrock AgentCore, bringing Netskope AI Guardrails into agentic workflows for AWS customers. This lets organizations move AI agents into production with the confidence that what an AI agent is allowed to do and what it actually does are, in fact, the same thing. And finally, on the go-to-market partnership front, we launched the Netskope Catalyst Managed Service Provider program to streamline the delivery of managed services based on Netskope solutions. As we've mentioned in the past, we value our partnerships with MSPs around the globe and view them as an important vehicle and lever for growth within the mid-market. Last quarter, I talked about how Netskope is transforming how we operate and how AI is accelerating our product velocity. In Q2, we kept up our relentless pace of innovation. Let me share some of these innovations. Last month, we introduced Netskope One DataSec Command Center, a unified control plane that discovers, understands and protects sensitive data everywhere it lives, in the cloud, on the network, on-premises, on endpoints, in e-mail and inside AI applications. It goes right at a problem I hear from CISOs everywhere. They still lack a central overview of their sensitive data. That fragmentation represents a large underserved market opportunity for a platform that can unify it. DataSec Command Center is built to do that by correlating signals from DLP, DSPM, CASB, SWG and more, so teams can go from finding a risk to fixing it in a few clicks instead of a multi-day investigation across disconnected tools. DataSec Command Center sits alongside the DLP AISecOps agent we introduced in AgentSkope last quarter. As customers scale their use of AI, they're increasingly focused on optimizing the cost and performance of each workload. This is creating a growing need for network optimization purpose-built for AI. In July, we announced the real-world results of our AI Fast Path technology. AI Fast Path optimizes the network path between users, sites, and agents to AI destinations for faster inference results and minimizes time to first token to accelerate agentic AI workflows. In real-world testing on our NewEdge network, AI Fast Path reduced latency by as much as 90%. NewEdge analyzes tens of millions of routes per day, evaluating latency, jitter, and packet loss, amongst other factors, and ultimately makes tens of thousands of route changes to identify the fastest, most reliable path for AI traffic. Beyond AI, we're continuing to innovate across our Netskope One platform, including delivering enhancements to our enterprise browser and Zero Trust access solutions during Q2. And finally, we enhanced our platform to address advances in quantum computing that are shrinking the timeline for Q-Day when some of the existing cryptography algorithms that are central to secure communications on the internet will be compromised. Sophisticated threat actors are pursuing the harvest now, decrypt later technique to store away encrypted packets now to decrypt it later when powerful quantum computers are available. These trends have resulted in government mandates throughout the world on hard timelines for implementing post-quantum cryptography algorithms. In order to address this, Netskope engineered and natively integrated NIST-approved post-quantum cryptography algorithms in its SASE platform across our more than 120 data centers globally in Q2, bringing quantum-resilient encryption to the globe. This helps our customers transition to a quantum-safe environment and meet regulatory mandates for their sensitive communications to SaaS and AI services worldwide. We strongly believe that we have and are continuing to build upon the right platform for the right moment. In Q2, we are proud to receive important third-party validation of our leadership in key markets. Netskope was again named a leader in the prestigious Gartner Magic Quadrant for both SSE and SASE for the fifth year and third year in a row, respectively. Correspondingly, in Gartner's companion Critical Capabilities report for SSE, Netskope ranked amongst the 2 highest-scoring vendors for all 4 category use cases, including essential SSE, advanced SSE, private application access and secure SaaS and AI enablement. And in the corresponding critical capabilities report for SASE, Netskope was the only vendor ranked as the highest-scoring for 3 key use cases, including foundational SASE platform, Zero Trust SASE platform and sovereign SASE. Additionally, in IDC's Worldwide SASE MarketScape report published last month, Netskope was recognized for SASE leadership, pointing to our single policy engine, common data model and NewEdge's distributed enforcement as significant differentiators. This also points to something crucial to understand. While AI is dominating the conversation, modern cloud and network security is the foundation for corporate AI adoption that is safe without compromising on performance. In fact, with growing agentic infrastructure, customers are increasingly recognizing that speed is a distinct competitive advantage and that Netskope offers the optimal path for inference. I've shared in the past, Netskope's AI-native philosophy, not only in how we build our market-leading platform, but in how we operate our business. Today, AI is accelerating how we work across the company, helping us innovate and expand our Netskope One platform faster than ever before, while also accelerating sales rep and SE training, streamlining customer support, recruiting and developing talent and automating other processes. Our teams have leaned into this new era, enabling us to move faster, operate more efficiently and scale with greater leverage. In closing, Netskope sits at the intersection of cloud, AI, networking and security, positioning us to address a massive market opportunity that we are still in the early stages of capturing. We are scaling our go-to-market engine well to capitalize on that opportunity while continuing to innovate rapidly and deepen our strategic position with customers and partners. Our goal is to be the essential adaptive fabric for the modern AI enterprise. And we believe our differentiated architecture, technology leadership and growing customer footprint create a durable structural moat that will compound over time. I am pleased with our second quarter outperformance across every key metric and proud of our team of Netskopers for continuously embodying the guts, resolve, integrity, and tenacity that define our culture and what we stand for. As well, I am grateful to the thousands of customers who trust Netskope to help steer them through 2 of the greatest technological revolutions in our lifetime, cloud and AI. With that, let me now turn the call over to Drew.