Zscaler, Inc. Common Stock 2026 Q4 Earnings Call
Review the key takeaways and the transcript of this earnings call.
- Zscaler reported strong fourth quarter fiscal 2026 results with 25% year-over-year growth in IRR and revenue reaching $898 million, up 25% year over year and 6% sequentially, exceeding guidance.
- Net new IRR grew 24% year over year to $246 million, with total IRR at $3.8 billion, up 25%.
- Non-GAAP operating margin reached a record 24.3% in Q4, with full fiscal 26 non-GAAP operating margin at 22.9%.
- The company processed over 750 billion transactions per day through its security cloud, highlighting its scale.
- Zscaler saw strong momentum in its AI security solutions, with security for AI bookings increasing over 50% sequentially in Q4.
- Z Flex bookings exceeded $1.7 billion in fiscal 26, with strong upsell and new logo activity, including multiple seven-figure deals.
- The company ended Q4 with 785 customers generating over $1 million in IRR and 4,182 customers generating over $100,000 in IRR, growing 18% and 20% year over year, respectively.
- Geographically, the Americas accounted for 57% of revenue and grew approximately 30% year over year, EMEA 27% with 17% growth, and APJ 16% with 23% growth.
- Zscaler completed a workforce restructuring affecting approximately 3% of employees, with expected charges of $30 million to $33 million.
- Free cash flow margin was 23% for fiscal 26, down from 27% the prior year due to timing of cash collections and CapEx.
- The company integrated Red Canary technology into its SecOps platform, with Red Canary revenue contributing $144 million in fiscal 26 but no expected net new IRR contribution going forward.
STOCKNOW INSIGHTS
Continue with outlook and guidance.
Log in to unlock executive comments and Q&A highlights.
Log in for the full summaryStockNow uses AI to translate and summarize earnings calls. Accuracy and completeness are not guaranteed.
Transcript
Preview the first fifteen paragraphs, organized by speaker.
I would now like to hand the conference over to your speaker today, Kim Watkins, SVP, Investor Relations and Strategic Finance.
Good afternoon, and thank you for joining us today. Welcome to Zscaler's fourth quarter fiscal 2026 earnings conference call. On the call with me today are Jay Chaudhry, Chairman and CEO, and Kevin Rubin, CFO. Please note that we posted our earnings release, shareholder letter, and a supplemental financial schedule to our investor relations website. Unless otherwise noted, all numbers we talk about today will be on an adjusted non-GAAP basis. You will find a reconciliation of GAAP to the non-GAAP financial measures in our earnings release.
Before we get started, I'd like to remind you that today's discussion will contain forward-looking statements, including, but not limited to, the company's anticipated future revenue, annual recurring revenue, net new annual recurring revenue, operating margin, gross margin, operating profit, net other income, earnings per share, and free cash flow margin, our customer response to our products, our expectations regarding AI and its impact on our business and customers, and our market share and market opportunity, and our objectives and outlook. These statements and other comments are not guarantees of future performance, but rather are subject to risk and uncertainty, some of which are beyond our control. These forward-looking statements apply as of today, and you should not rely on them as representing our views in the future. We undertake no obligation to update these statements after this call.
For a more complete discussion of the risks and uncertainties, please see our filings with the SEC, as well as in today's earnings release. I also want to inform you that we'll be attending the following conferences this quarter: Citi 2026 Global TMT Conference on September 9, Goldman Sachs Communacopia + Technology Conference on September 9, Wolfe Research TMT Conference 2026 on September 9, and JP Morgan 2026 Software Forum on October 1. With that, I'll turn the call over to Jay.
Thank you, Kim. Good afternoon, everyone. We delivered a strong finish to the fiscal year with 25% ARR growth and a non-GAAP operating margin of 24%. We are seeing significant positive trends in net new ARR, with growth excluding Red Canary accelerating to 17% in Q4. These results reflect increasing market adoption of our Zero Trust platform. AI is quickly becoming the largest tailwind we've ever seen, driving demand for our Zero Trust Everywhere data security and Security for AI solutions. Our customers are relying on us to both combat the threats created by agentic AI and safely deploy AI agents and models at scale. Since our last earnings call, new AI models have become more powerful, more autonomous, and more dangerous from a cybersecurity perspective.
The ability of these new frontier AI and open weight models to uncover previously unknown vulnerabilities at a rapid pace has become even more apparent. Organizations simply do not have enough time or resources to fix the unprecedented number of software vulnerabilities that are being discovered. The time between vulnerabilities being discovered and exploited is also shrinking. You cannot win a patching race against AI. This is leaving organizations exposed and likely leads to more breaches. Over the past few months, our team has conducted hundreds of frontier AI risk assessments for global enterprises to help them assess their cyber resilience posture to minimize potential breaches. The takeaways have been incredibly revealing. Over 90% of organizations had AI applications, models, and other servers exposed to the internet, and more than one-third had known exploitable vulnerabilities.
At the same time, the threat landscape has been compounded by the ability of new AI models to power ungoverned autonomous agents. We are now seeing the impact of fully autonomous AI attacks. There have already been multiple high-profile incidents from three leading frontier model companies where agents went rogue and took unauthorized actions. This includes the recent Hugging Face incident, where a swarm of agents went to extreme lengths to break out of a sandbox training environment, get onto the corporate network, and move laterally to conduct a sophisticated attack. This is driving urgency at the highest levels, and Zscaler is uniquely equipped to meet the moment. CEOs and boards are looking to us as their trusted partner to address three essential business challenges. First, how do we secure our environment when we can't patch security vulnerabilities fast enough?
Our Zero Trust Exchange makes applications, AI models, and data invisible. An attacker, human or agent, cannot breach what it cannot reach. Second, how do we minimize the impact of a potential breach? Our Zero Trust Exchange connects users, workloads, branches, and agents directly to the applications they need without placing them on the network. This eliminates lateral threat movement, containing the impact of a breach. Third, how do we take advantage of all the benefits of AI without introducing significant new risks? Zscaler has a full portfolio of data security and Security for AI solutions that prevents data exfiltration, provides guardrails to prevent abuse or misuse of AI applications, and enables secure agentic communication. Because of these advantages, customers trust us to secure their business-critical environments. We are also differentiated by our scale, operating the world's largest distributed inline security cloud, processing more than 750 billion transactions per day.
This scale provides unmatched high-fidelity telemetry that continuously improves our AI-powered security capabilities. In the AI era, zero trust is now an imperative, and we are not alone in this belief. Anthropic published a white paper in late May encouraging adoption of a zero trust architecture for AI agents, emphasizing the importance of treating every agent like an untrusted entity and making sure it only has access to authorized data and applications. This is why customers are expanding their investments with us to secure their agentic infrastructure and why we are confident our platform is uniquely equipped to address the risks companies face in this new world. In addition to protecting companies from the threats created by agentic AI, we are also enabling organizations to safely deploy AI agents and models.
Our AI solutions are key to providing enterprise visibility, governing what data and applications agents can access, and what actions they are permitted to perform. We are often asked why our solutions are needed alongside identity for AI security. While identity solutions answer who is requesting access, our in-line exchange determines what that user or agent should be allowed to do and enforces that policy in real time. Put simply, identity is only the starting point for securing AI. Greater visibility and control is needed for organizations to trust agents accessing sensitive data, interacting with applications, and taking action on behalf of users. Earlier this year, we introduced the industry's most comprehensive Security for AI solution designed for exactly that reason. We are seeing strong, proactive inbound interest from both new and existing customers, and we are seeing no budget constraints.
Security for AI bookings increased more than 50% sequentially in Q4 on top of a strong Q3. Our Security for AI solution provides new logo opportunities by offering organizations an integrated way to secure AI use at scale. At our ZenithLive conference in June, we unveiled the latest additions to our Security for AI lineup, including our Zero Trust Exchange for Agents and Endpoint AI Security, both of which we expect to scale in the second half of fiscal 2027. Both products are in early access, and we are seeing tremendous interest from customers. These new solutions will provide organizations the ability to enforce AI policy, both at our exchange and the endpoint, enabling policy enforcement at the optimal location. We continue to innovate in this area at a rapid pace. Next week, we are announcing the next major innovation on our platform with our new Agentic SecOps solution.
Just as AI is increasing the threat surface, it is also stressing the human-driven traditional SOC approach where remediation can take days or weeks. In contrast, our AI-first approach brings together our proprietary telemetry and Red Canary's decades plus of experience in managed detection and response, or MDR. Our Agentic SecOps solution enables security teams to prioritize real threats and leverage specialized AI agents to detect, investigate, and respond to threats at machine speed. We are driving closed-loop remediation in real time by integrating our Agentic SecOps with our Zero Trust Exchange, enabling customers to move with speed as the time between detection and exploitation has decreased from months to minutes. We will be launching our new Agentic SecOps solution with a webcast on September 9th, which will be streamed on our website. Our approach for securing users and non-users and ensuring safe adoption of AI is resonating.
This is increasingly evident in my conversations with customers and partners and is illustrated with a few customer examples. First, we had a notable seven-figure upsell Z-Flex win with a Fortune 500 transportation customer who deployed our Security for AI portfolio to secure their full AI life cycle. Our Security for AI solution provides an integrated approach to secure AI use at scale. This includes discovery and management of all AI assets, including shadow AI and enforcement of safe access to approved apps. It also includes real-time prompt and response inspection to stop data leaks and threats like prompt injections and continuous red teaming assessments. This customer selected our Security for AI solution over two major platform competitors, and with this win, the customer's ARR grew to nearly $10 million.
In another seven-figure Z-Flex upsell, a Fortune 500 semiconductor manufacturer expanded its adoption of the Zscaler platform to secure a company-wide rollout of Cloud Cowork. After assessing several vendors, this client determined Zscaler's Security for AI was the only solution capable of securing the customer's AI adoption, including its endpoints, secure agent-to-agent communication, and model usage in private and public environments. This is a great example of how our customers are expanding the use of Zero Trust Exchange to safely deploy AI agents and models as well as combat the threats created by agentic AI. While we are in the early innings of Security for AI, these deals give us tremendous confidence in our ability to expand this offering significantly over time. Next, our leadership in data security is a powerful tailwind for our Security for AI business.
As enterprises embrace gen AI and agentic AI, they're confronting a new wave of data exfiltration risks, including data abuse and over-privileged access to data. Our inline architecture, coupled with our endpoint DLP and now Endpoint AI Security, enhances our ability to enforce data loss prevention in the cloud as well as on the endpoint. Securing data and AI go hand-in-hand, as evidenced by the fact that 70% of our Security for AI deals this quarter included our data security solution. In Q4, we also closed a seven-figure Z-Flex upsell win with a large global asset management firm. The customer selected Zscaler's Data Security Posture Management solution over a privately held DSPM vendor. This customer chose Zscaler to address gaps related to sensitive data discovery across its multi-cloud environment and data governance.
FULL TRANSCRIPT
Continue the full translated transcript in StockNow.
Log in to unlock every statement, the English original, and speaker-by-speaker history.
Log in for the full transcriptCall participants
14 people spoke on this call — only 2 are shown here.
PARTICIPANT LIST
View participant details in StockNow.
Log in to see executives and analysts, their roles, and complete speaking history.
Log in to view all participantsKeep exploring
