Tomer Weingarten
Analyst · Scotiabank
Good afternoon, everyone, and thank you for joining our second quarter earnings call. Q2 was an outstanding quarter for SentinelOne. We exceeded our top and bottom line guidance, delivered record second quarter net new ARR, and record operating margin. Building on this momentum, we are raising our revenue operating income outlook for the year. Q2 marks our fifth consecutive quarter of positive net new ARR growth and outperforming expectations. These results reflect what increasingly defines SentinelOne: top-tier growth, expanding margins and undisputed technology leadership. Cybersecurity is at a fork in the road. AI is transforming the way software is built, businesses operate, and adversaries attack. The speed, scale and sophistication of AI models are making the threat landscape increasingly complex. At the same time, AI also gives defenders the power to transform security outcomes through accelerated response times and unmatched efficiency. The approach of bundling fragmented products or marketing disjointed platforms is not the answer. The strategy repackages complexity, it doesn't remove it. Enterprises today do not need another point solution, a feature product, or a bigger bundle. They need real-time connected intelligence that operates at machine speed. This requires a unified architecture, a single control plane, purpose-built to defend the modern infrastructure in the age of AI. This is the vision we founded SentinelOne on, an AI-native approach to cybersecurity long before the Mythos moment. Singularity is the autonomous security platform of the future. Our technology differentiation lies in a clear architectural advantage. Every platform solution we offer, from endpoint, Cloud and Data to AI SOC, AI EDR and ADR is the best-in-class capability on its own, unified by our industry-leading autonomous runtime engine, and delivered via a single pane of glass. Machine speed runtime protection is fundamental to our platform architecture, and our AI security growth and contribution already indicate we are leading in this fast-moving category. This quarter provided a clear validation across 4 fronts for SentinelOne: one, market-leading wins with the world's most discerning organizations; two, growth acceleration of our AI security, data and cloud solutions; three, sustained displacements of legacy endpoint vendors; and four, our distinct architectural advantage in securing modern AI infrastructure. First, let's start with how the most discerning buyers in the world are choosing SentinelOne. Our competitive win rates increased sequentially and year-over-year, anchored by growing platform momentum and consolidation wins. Net revenue retention among our largest customers expanded again in the quarter. 7- and 8-figure customer wins are becoming consistent. And cross-platform adoption drove a record ARR per customer, growing double digits year-over-year. Enterprises are increasingly consolidating multiple point products with the Singularity platform. The clearest example, a leading aerospace and defense enterprise, chose Singularity to execute a complete rip and replace of our primary competitor, consolidating endpoint, Data, Cloud as well as AI Security with SentinelOne. And our AI Security capabilities widened the gap as the competitive alternative was not good enough to help this enterprise accelerate AI adoption. Facing sophisticated nation-state threats, this customer had extremely stringent security requirements. During an intensive proof of concept, SentinelOne delivered a step change improvement in analyst workflows and security efficacy over the incumbent. Second, we are seeing strong contributions across the board from our AI, Data, Cloud, Wayfinder and endpoint solutions. We had another exceptional quarter for Prompt Security, which remains our fastest-growing platform solution. As organizations move AI models and autonomous agents into live production, robust security is mandatory. We are capturing this wave, driving strong demand across model security, agentic guardrails, and enterprise AI usage. Prompt Security is leading this category as the definitive AI security solution for the enterprise. Demonstrating this momentum, Bell Canada selected Prompt Security to secure one of the nation's most critical networks. They required real-time visibility, automated guardrails, and strict compliance for their workforce, and SentinelOne delivered it. This win validates that enterprise-grade AI security is a prerequisite for safe AI adoption, and our momentum in this category continues to accelerate. The telecom sector continues to be an area of competitive edge for us. We protect operators across 5 continents, including several of the largest carriers in their respective markets. These are among the most demanding security environments anywhere, massive distributed infrastructure, persistent nation-state threat exposure, and stringent regulatory requirements. Our scale and expansion in that environment demonstrates the breadth and the resiliency of the Singularity platform. We continue to win stand-alone AI security deals from our direct competitors. This is serving as a strategic entry point for broader platform expansion. As AI adoption scales, enterprises are confronting an unprecedented threat landscape. They need to protect AI tools and sensitive data while enforcing strict run time controls over autonomous agents. Our increasing AI security innovations address these challenges, now offering agentic security, AI red teaming capabilities, and enhanced AI entitlement management. This is enabling enterprises to adopt AI rapidly without compromising security, privacy, or trust. Building upon our technology leadership in EDR, we are on track to establish similar leadership in agentic as well as AI detection and response. Next, Purple AI continues to redefine the AI SOC, serving as our core engine for autonomous security operations. An increasing number of new customers are landing with Purple AI from day 1, while our existing customer base continues to expand its usage. With our recently launched agentic investigations, Purple AI autonomously analyzes alerts across complex environments, producing definitive assessments in seconds rather than hours. IDC independently validated a 338% 3-year ROI for Purple AI customers. Purple AI's accuracy relative to human-led workflows further underscores its disruptive potential. As Security operations evolve towards continuous agentic defense with human oversight, SentinelOne sits at the forefront of this paradigm shift. By continuously advancing Purple AI, we empower customers to accelerate detection, automated investigations and execute remediation at machine speed. ARR from our AI security offerings, Prompt and Purple AI, continues to be in hyper growth, tripling year-over-year in Q2. We expect this to become our next 9-figure ARR category, following endpoint, Cloud, Data and Wayfinder. This momentum highlights our technology differentiation and market leadership in defining the next generation of AI cybersecurity. For data solutions, Q2 marked our fifth consecutive quarter of ARR growth acceleration. We believe the future SOC will be hybrid. Enterprises will continue to operate across diverse security tools and data sources while increasingly adopting AI-driven investigation and automation. Our security data lake is built for that transition, from intelligent data pipelines and AI SIEM to Purple AI and hyper automation. We help customers consolidate and optimize security data and turn it into faster detection, investigation, and response from pipeline to SIEM to autonomous SOC. SentinelOne covers the full security data life cycle. This is evident in our accelerating momentum with AI SIEM. Among new customer wins, a global services firm selected SentinelOne's AI SIEM over both legacy and next-gen alternatives to unify telemetry, improve operational visibility, and accelerate incident response. By establishing the Singularity platform as their centralized security data foundation, the customer unlocked petabyte-scale telemetry control, and laid the groundwork for AI-driven automation. Demonstrating our expansion momentum, a major international retailer expanded its deployment with SentinelOne. This win fully displaces a legacy endpoint vendor while expanding this customer's data footprint. By unifying endpoint protection and security data analytics on the Singularity platform, this customer is establishing a foundation to scale their data volumes by several terabytes in future phases. External validation continues to highlight our competitive edge. According to an IDC business value study, SentinelOne's AI SIEM delivers a 331%, 3-year ROI, 70% faster queries, 75% faster investigations, and 4x the threat coverage. For cloud security, Q2 marked the third consecutive quarter of ARR growth acceleration. This momentum is driven by strong adoption of our best-in-breed runtime cloud security, covering both cloud and on-prem environments. The massive AI infrastructure build-out is driving accelerated demand for us, making real-time run-time protection an absolute imperative as enterprise cloud footprints expand and AI workloads multiply. Among cloud security wins, a major American tech giant significantly expanded its SentinelOne deployment, choosing Singularity Cloud over a close competitor. The customer cited our superior platform performance and operational ease of use as the decisive factors. As their cloud infrastructure rapidly scales, this expanded partnership creates a natural compounding growth opportunity for Singularity across their environment. Among new customer wins, a leading global financial institution standardized on the Singularity platform following a rigorous competitive evaluation against both legacy incumbents and next-gen contenders. Given strict regulatory requirements and the operational complexity of a distributed cloud environment, this enterprise selected SentinelOne for a unified autonomous cloud security. Modern cloud environments are dynamic, distributed, and directly connected to mission-critical AI workflows. Static posture management and periodic vulnerability scans are simply not enough. Organizations need runtime cloud security to detect and neutralize active threats at execution. Underscoring our cloud security leadership, Frost & Sullivan named SentinelOne a visionary leader in its 2026 Frost Radar for cloud workload protection platforms, recognizing our innovation and growth against the field of more than 45 qualified vendors. Third, we continue to grow our endpoint footprint, particularly through large-scale consolidation deals. Through our strategic partnerships with MSSPs, we are consolidating multiple incumbent endpoint states onto the Singularity platform. Singularity endpoint delivers the most autonomous EDR technology, which combines industry-leading efficacy, performance and user experience. The secular shift towards infrastructure modernization continues to provide a powerful long-term tailwind. Nearly half of the sector still relies on legacy antivirus, creating a massive displacement opportunity. This transition is backed by proven economic value, with IDC Research demonstrating that Singularity endpoint delivers a 301%, 3-year ROI. Highlighting our traction for endpoint security, a major government agency administering national public services standardized on Singularity EDR. This agency selected SentinelOne following a rigorous evaluation that demonstrated our platform's real-time speed, autonomous response, and superior total cost of ownership. Validated by existing reference deployments across major public institutions, this win underscores our trusted position in securing mission-critical government infrastructure. Fourth, we have a distinct architectural advantage in securing the modern AI infrastructure. As AI agents gain autonomy, real-time runtime security becomes paramount. Behavioral detection and continuous validation at machine speed are essential to intercept unauthorized actions before harm occurs. Governance defines what an AI agent is permitted to do, but runtime is where the actions are executed. Securing AI requires deep visibility directly at the point of execution across endpoints, cloud workloads, and the underlying infrastructure where agents operate. This plays directly to SentinelOne's core strengths. Our AI native EDR foundation combines years of technology leadership in behavioral detection and autonomous response. As cybersecurity shifts from detecting threats to governing autonomous agents, EDR naturally evolves into AI detection and response. This positions SentinelOne as the premier platform to defend both traditional endpoints and the emerging AI stack. We are also capturing a structural tailwind in sovereign defense, a major differentiator for SentinelOne. As public and private institutions deploy private AI stacks to maintain data residency, sovereign AI security becomes an operational imperative. Organizations simply cannot rely on architectures that export sensitive telemetry off site. We are the only modern security platform that can be deployed to cloud, on-premises, and air-gapped environments. Our platform's on-premises deployment capability delivers high velocity runtime protection wherever the AI workload resides. This magnifies our competitive advantage. When sovereignty, control, and machine speed defense matter most, the world's most security-conscious organizations select SentinelOne. Demonstrating our sovereign deployment differentiation, an aerospace and defense giant selected SentinelOne after rigorous multi-vendor proof of concept in an air-gapped, highly restricted environment. SentinelOne was the sole provider to pass every requirement, delivering a seamless deployment and operational capabilities that legacy and next-gen competitors simply cannot offer. On the distribution front, our partner ecosystem continues to serve as a force multiplier. We are expanding our global reach, accelerating platform adoption and driving efficient scale. Singularity's multi-tenant architecture, centralized management and native automation empower service providers to efficiently manage vast customer states. A great example of this momentum is LevelBlue, the world's largest managed security provider who selected SentinelOne to scale its managed security service offerings. In Q2, we expanded our partnership by naming LevelBlue as a premier remediation partner for Wayfinder Frontier AI Services to bridge the gap between threat discovery and resolution. SentinelOne customers leveraging Wayfinder Frontier AI Services can now connect directly with LevelBlue experts to develop and execute prioritized remediation programs. This capability empowers security teams to eliminate software vulnerabilities faster, improving overall application resilience. Simultaneously, we are scaling our hyperscaler alliances as cloud and AI infrastructure converge. We expanded our AWS collaboration around unified AI governance, integrating our AI security capabilities directly with Amazon Bedrock AgentCore to deliver real-time run-time guardrails for autonomous agents. On SentinelOne Flex. It's becoming an increasingly important driver of platform adoption that gives customers a streamlined way to adopt and expand across the Singularity platform. Within a year of its launch, SentinelOne Flex has now exceeded 10% of total ARR. We are seeing strong traction with both new and existing customers, larger strategic commitments and a strong pipeline of Flex opportunities. Our Flex offering aligns purchasing with evolving security priorities and reduces the friction associated with adding new capabilities over time. Overall, the Flex model is creating a stronger foundation for consolidation, expansion, and long-term partnership. Across the broader industry, SentinelOne is emerging as a clear winner of the AI security era. And that is because we spent a decade building toward it. Offensive AI capabilities are compressing the time between vulnerability discovery and weaponization. What was theoretical quarters ago is now an operational reality. Frontier models are advancing from basic vulnerability discovery to reasoning through multi-stage attack paths and executing autonomous cyberattacks. For instance, Anthropic recently demonstrated models executing end-to-end attacks across complex networks, while OpenAI noted that emerging model capabilities are rapidly approaching critical cybersecurity thresholds. By serving as a security partner in initiatives like Glasswing and Daybreak, we are helping establish SentinelOne as a trusted runtime security layer for emerging AI-native software. As AI tools become more capable, security must evolve in parallel, detecting and stopping threats at machine speed autonomously. The implication is undeniable. The window between vulnerability discovery and exploitation has effectively collapsed. Autonomous agents introduced unprecedented operational risk. Agents don't just generate text, they execute code, call APIs, handle credentials, and interact with infrastructure, often finding execution paths their developers never intended. A stark example occurred recently at Hugging Face, where an autonomous agent system executed thousands of actions at machine speed, escaped its sandbox, crossed boundaries, and compromised external infrastructure. For defenders, the lesson is clear: you cannot assume an agent will remain confined or behave as intended. While governance defines what an agent should do, runtime security governs what it actually does. This is our foundational vision and our moat. We are a pioneer in modern runtime security. Our technology sits precisely where AI agents execute across data, endpoints, cloud workloads, and applications. Our proprietary behavioral AI engine was built to analyze anomalies and intercept malicious execution in real time. As cybersecurity evolves to governing autonomous software or agents, our runtime foundation gives us the unique ability to map behavior through action, making SentinelOne the essential platform for the AI era. As AI compresses the attackers' time line from discovery to exploit, SentinelOne is helping defenders compress the time line from detection to remediation. We are leading this paradigm shift on both fronts, delivering AI for Security and Security for AI. Singularity is the autonomous security platform of the future. Reflecting on the overall performance, we made exceptional progress across every dimension of our business, sustaining top-tier revenue growth, accelerating profitability and extending our technology leadership across the highest growth categories in cybersecurity. We outperformed expectations, delivered our fifth consecutive quarter of positive year-over-year net new ARR growth, achieved a company record double-digit operating margin and drove expanding customer adoption across data, cloud, AI security, Purple AI and Flex, and we are pairing all of this with a stronger growth and operating income outlook for the year. SentinelOne is built by innovators with a relentless commitment to technology leadership, and our performance demonstrates the talent and execution of our teams. As we enter the second half of fiscal year '27 we are well positioned to build on this momentum and lead the AI security landscape while delivering durable, profitable growth and long-term shareholder value. In closing, I want to recognize all Sentinels for their dedication, as well as our customers, partners, and shareholders for their continued support. Our mission to be a Force for Good remains paramount as we work to ensure AI itself remains a force for good. Thank you again for joining us today. I'll now hand the call over to our CFO, Sonalee Parekh.