Tomer Weingarten3:29
Good afternoon everyone, and thank you for joining our first quarter earnings call. Q1 was a solid start to the year for SentinelOne. We delivered strong revenue growth, record net new ARR growth, and significant operating margin improvement year-over-year. Total ARR growth accelerated to 23% in Q1, driven by strong new logo acquisition and expansion with existing customers. We delivered $44 million in net new ARR in Q1, a 55% increase year-over-year, setting a new company record. This marks our fourth consecutive quarter of positive net new ARR growth while exceeding expectations. These results showcase execution consistency and strong business momentum.
Our platform strategy is showing solid traction. We have established clear technology leadership across the most critical domains of cybersecurity, including AI, data, cloud, and endpoint. Enterprises realize they cannot defend against AI-driven threats by consolidating onto legacy platforms that simply bolt separate tools together. What's needed is a natively unified AI-driven data and security architecture, and that is what SentinelOne delivers. According to Gartner, AI security is the fastest growing segment in cybersecurity, growing more than 70% year-over-year. AI represents a massive market opportunity for us and a durable tailwind for our business. We are already seeing this momentum with our AI offerings, as our AI security ARR nearly doubled again in Q1. AI has been foundational to the Singularity platform from day one. This inherent AI advantage has never been more critical, and we are well positioned to expand our market share across a hundred billion plus market opportunity.
Now, let's dive deeper into the details of our quarterly performance. We are winning new logos and expanding our footprint across diverse platform categories. Beyond the Singularity platform's best-in-class efficacy and autonomy, its intuitive design and operational simplicity are driving strong customer adoption. In Q1, our total ARR mix reached an important inflection point. For the first time, the total ARR from our non-endpoint solutions approached 50%. This performance was driven by accelerated ARR growth of our AI security, data, and cloud solutions, a clear testament to the diversity and customer outcomes of the Singularity platform. Our cross-platform adoption drove a record ARR per customer in the quarter, signifying the momentum and contributions across our platform solutions. Overall, we're maintaining a healthy balance between new logo acquisition and existing customer expansion. Given our scale and relative market share, this strategy allows us to increase our market share while still retaining significant future expansion potential. We maintain solid win rates across all competitive situations. We're gaining mind share and market share among customers and partners. Customers of all sizes, especially large enterprises, are increasingly recognizing SentinelOne's AI advantage.
Among our platform solutions, AI security continues to be a bright spot, with ARR nearly doubling again sequentially in Q1. Today, Prompt security stands out as the only enterprise-grade, scalable solution capable of securing AI at this level, and organizations are recognizing that this is a prerequisite for safely accelerating their AI initiatives. Let's look at our Q1 wins that exemplify this. A US state government selected SentinelOne to secure its AI infrastructure in one of the first government deals led by AI security. With thousands of employees accessing AI tools across sensitive government systems, the need for real-time visibility and governance was urgent. This customer chose Prompt alongside endpoint, cloud, and AI SIM to get runtime visibility into their employees' AI usage while satisfying strict government compliance requirements. Moreover, we are increasingly winning standalone AI security deals from the customers of our direct competitors. This serves as a strategic entry point to expand our broader market exposure. In Q1, an iconic enterprise selected Prompt security over the incomplete AI offering of their incumbent next-gen endpoint vendor. Winning this head-to-head evaluation has built tremendous trust. By demonstrating the superiority of SentinelOne's technology, we have opened the door to displace that next-gen competitor and drive broader consolidation for this enterprise with the Singularity platform.
As organizations race to build and deploy homegrown AI applications, the attack surface is expanding faster than legacy tools can address it. To close that gap, we launched Singularity AI Red Teaming in May, purpose-built to secure AI applications from the inside out. This solution autonomously stress tests AI applications against real-world attack scenarios before they ever reach production. This creates a highly complementary land and expand motion for us. Red teaming discovers the vulnerabilities in development, and our core platform seamlessly blocks them at runtime. We are now delivering AI security from the first line of code through execution.
Next, Purple AI. Our agentic SOC solution is rapidly becoming the bedrock of modern security operations. With the increasingly sophisticated capabilities of Purple, we are empowering customers to respond faster, accelerate detection, and automate investigations. In Q1, we announced the general availability of Purple AI Auto Investigations, a major milestone in our journey towards delivering a fully autonomous SOC. Purple AI represents a significant expansion opportunity over time. In several early rollouts, we are seeing instances where ARR from Purple AI's end-to-end deployment can outgrow a customer's core endpoint footprint. Delivering agentic SOC's autonomous capabilities can drive outsized value. Purple is built for enterprise scale and natively integrated with Singularity Hyperautomation, but its value extends well beyond large enterprises. We've architected Purple to deliver meaningful impact across customers of all sizes, and we see a particularly compelling opportunity with MSSP providers who stand to benefit from significant cost efficiencies and a step-change acceleration across their entire operations.
At the capability level, Purple's latest auto investigation feature delivers human-level reasoning at scale, providing one-click and soon zero-click automation with clear verdicts in seconds. This closes the critical gap between insight and action, fundamentally changing what security teams can accomplish. The accuracy we're seeing compared to human analysts make this a true game-changer, allowing security practitioners to shift from manual investigation to immediate remediation. This is consistent with IDC's finding noting a 338% ROI for Purple AI customers.
For data solutions, Q1 marked the fourth consecutive quarter of ARR growth acceleration. We are seeing increasing demand for our AI SIM as enterprises seek unified visibility, real-time detection, and autonomous response, all this with far more efficient unit economics than legacy alternatives. With an integrated Observo AI, our customers now benefit from owning the critical data pipeline that powers modern security operations. We are delivering a truly comprehensive security data lake that natively unifies petabyte-scale ingestion, orchestration, and hyperautomation into a single seamless experience.
Among several wins in the quarter, an iconic luxury brand displaced Splunk with a multi-year commitment to SentinelOne's AI SIM as their dedicated security data platform. Their global operations needed a solution that offered unified visibility into a single AI-native platform. The combination of real-time autonomous security and operational simplicity of the Singularity platform made it a winning choice. In another win, a multinational services enterprise signed a seven-figure expansion with SentinelOne, replacing their existing SIM provider. This enterprise selected the Singularity platform for superior cost of ownership, machine-speed investigations, and AI-native unified platform. Independent validation continues to reinforce our competitive position. A recent IDC business value study found that SentinelOne's AI SIM delivers a 331% three-year ROI with only a 7-month payback period. Our AI SIM customers see 70% faster queries, 75% faster investigations, and four times the threat coverage.
For cloud security, ARR growth accelerated in Q1, driven by the strong adoption of our best-breed runtime security, covering both on-prem and cloud environments. As AI workloads multiply and cloud environments expand, the need for robust runtime security is increasing. Among cloud security wins, one of the most valuable private companies in the world, soon to become public, significantly expanded its footprint with SentinelOne in the quarter. To secure an enterprise of this magnitude, static cloud visibility or partial management was simply insufficient. This enterprise doubled down on Singularity Cloud for autonomous AI-powered runtime protection capable of actively neutralizing AI-based threats across their dynamic infrastructure in real time.
To secure dynamic cloud environments, organizations need more than static posture management. Our runtime cloud security stops real-world cloud attacks in real time and seamlessly scales alongside our customers' operations. It is clear that in an AI-driven threat landscape, static defenses are no longer sufficient. Verifying identity at the door is useful, but it doesn't stop modern threats. We've seen this play out repeatedly. Traditional identity access management solutions and PAM solutions were built for the past. They were fine at mapping and governing access, but they were never designed to autonomously detect and respond to what happens next. Attackers often bypass access controls post-authentication, operating undetected inside environments where trust was already granted. Machine-speed behavioral analysis and continuous validation at runtime is the key competitive edge and the only formidable defense strategy to stop real-time attacks in the age of AI.
As the market pivots towards securing AI agents and frontier models, the endpoint remains the ultimate control plane. You simply cannot deliver comprehensive AI security without deep foundational visibility at the point of execution on the host machine that runs AI. AI-powered EDR remains a critical vector for capturing the evolving AI security opportunity. With deep expertise and a significant portfolio of patented machine learning and behavioral detection algorithms, SentinelOne is uniquely positioned to protect endpoints and AI workloads directly where they are created and operated. Beyond monitoring access, we align intent to action through real-time behavioral analysis, detecting threats that no identity or perimeter control can see. Most recent supply chain attacks, including those targeting LLM and Axios, underscore this point clearly. These were exploit-free attacks purpose-built to bypass traditional security controls and move at machine speed, no signature, no known vulnerability, no perimeter trigger. The only effective defense was autonomous behavioral protection at the host level, exactly where SentinelOne operates. These real-world examples reinforce why the execution layer is where the battle is won.
We continue to be a growth leader in the broader endpoint sector by delivering the most autonomous endpoint security solution available, combining industry-leading efficacy, performance, and user experience. Nearly half of the existing endpoint sector is still using legacy antivirus solutions. This is a clear opportunity for continued market share gains. We're also beginning to see increased traction in securing highly restricted on-prem environments where true sovereignty is required, which is a distinct structural advantage for us, while our competitors can't truly secure these environments. This provides an emerging growth avenue for us. We have the distinct advantage of delivering fully autonomous, high-velocity AI protection in any environment, both cloud and on-prem. Our expanding customer base now includes some of the most sophisticated and iconic companies on the planet. From frontier AI labs and major financial institutions to critical global supply chains, the world's most demanding organizations rely on and trust SentinelOne.
Turning to SentinelOne Flex, it is proving to be a highly effective model for broader platform adoption. We're seeing an increasing number of large deals and contributions from Flex. In just three quarters of its launch, Flex has crossed $200 million in TCV. Looking ahead, our pipeline and demand for Flex shows continuation of this momentum. SentinelOne Flex is simplifying the purchasing process and driving an increasing number of large seven and eight-figure deals and longer-term commitments. Overall, our success up market is directly fueling bigger deals, driving steady retention, and creating a highly visible, durable runway for long-term growth. With the growth of token-based AI adoption, we're also expanding our monetization model to capture the full value of how customers use our emerging solutions. Usage-based metering creates a natural growth engine. As customers expand their use of our products like security data lake and Purple AI, customers can choose upfront annualized SentinelOne Flex commitments that provide cost visibility and preferred economics while giving us committed revenue visibility. Together, SentinelOne Flex and prepaid structures create a durable hybrid model, a reliable baseline with meaningful expansion opportunity layered on top.
In the partner ecosystem, we continue to expand our reach and scale. Our partner ecosystem is a force multiplier, expanding our global reach and driving broader platform adoption. For MSSPs, the Singularity platform delivers the AI-native multi-tenancy and remote management capabilities that drive valuable operational leverage. This structural advantage gives us a unique competitive edge within the MSP ecosystem. A strong proof point of this leadership came at RSA, where we announced an expansion of our partnership with Level Blue, the world's largest MSSP. This partnership drives the strategic consolidation of their endpoint estate onto the Singularity platform in the coming years and extends our reach across their global customer base. At RSA, we also announced an expanded strategic alliance with Google Cloud to deliver autonomous security at global scale, and we were honored by winning the 2026 Google Cloud Partner of the Year award. Last week, we also announced Singularity Platform's integration into AWS Security Hub Extended. This removes the traditional barriers of enterprise procurement. AWS customers can now turn on SentinelOne's AI-powered runtime security in minutes directly from their AWS console without new contracts or procurements. This pay-as-you-go model allows organizations to seamlessly secure their modern digital footprints with SentinelOne.
Let's shift gears to the broader industry dynamics. Frontier AI models are rapidly changing cyber defense, allowing adversaries to execute AI-based attacks and weaponize weaknesses faster than human teams can react. To stay secure, enterprises must rebuild infrastructure from the ground up with a unified AI-native foundation to build modern and secure enterprise infrastructure. We believe a collaborative approach is key to solving this generational challenge. Our relationships with the frontier labs are deep and strategic. We partner with Anthropic on the launch of cloud security and with OpenAI through its early access for cyber program, embedding frontier models throughout our platform. We complement these with our own proprietary and fine-tuned models, and our core engines remain multimodal and model-agnostic by design. AI security is becoming a focal point across the industry with programs like Glasswing or Daybreak. It validates the approach we have been building towards for years, and we are actively engaged with both Anthropic and OpenAI to ensure SentinelOne's role in this ecosystem continues to grow alongside our platform leadership. I am also pleased to share that we are a participating vendor in Project Glasswing.
Proactive visibility is only half of the equation. We must neutralize active threats at the point of execution. The new class of AI-based attacks are designed to move faster than any human analyst could react. To give the advantage back to defenders, we launched Wayfinder Frontier AI Services in Q1. With our elite partner coalition including Mandiant, WWT, KPMG, and Booz Allen, we're fusing multimodal AI with tip-of-the-spear human intelligence. Protecting the AI-powered business world requires securing the systems where AI is actually being built and used, often Linux and Mac operating systems. While many cybersecurity vendors remain dependent on securing only Windows environments, our established strength to secure Mac and Linux systems gives us structural advantages in AI security. We're expanding our native EDR telemetry to protect autonomous AI agents across these operating systems where AI compute is rapidly growing. Our Singularity platform's on-device behavioral AI recognizes malicious execution patterns and mitigates the processes preemptively. We autonomously stopped recent supply chain attacks instantly across multiple customers with zero prior knowledge and no human analysts in the loop before they could do any damage. At SentinelOne, we are delivering end-to-end AI security from data to runtime.
Shifting gears to our operating model, as always, we remain committed to balancing durable growth with improving profitability and accelerating our path towards the Rule of 40. That commitment requires us to continuously sharpen how we operate. As I outlined in March, we have been actively refining our team structures and go-to-market focus while accelerating our internal use of AI. In alignment with this strategy, we made a difficult but necessary decision. We are streamlining our organizational structure, resulting in about an 8% reduction in our workforce. This is not a reactive measure. It is a deliberate evolution to reduce complexity, raise the performance bar, and build a leaner, more agile SentinelOne. On the go-to-market side, we see an opportunity to uplevel our teams and streamline distribution. This includes tightening our coverage and driving greater productivity across our sales organization. Our goal is straightforward: driving better operating leverage, sales efficiency, and execution velocity. On the AI side, through the company-wide rollout of frontier models, we are seeing meaningful productivity gains across our organization. Work that previously took months is now being completed in weeks and, in some cases, days. Together, these actions provide us the resources and flexibility to concentrate investments in our highest conviction growth areas: AI, data, cloud, and endpoint.
Before I turn the call over, I'm very pleased to officially welcome Sonali Parikh to her first earnings call. Over the past months, we have been working closely together. Sonali brings an impressive level of operational rigor that aligns with our focus on execution velocity and profitability. She's a phenomenal addition to our executive team and already making an impact. In closing, I want to take a moment to acknowledge the contributions of all Sentinels. The relentless focus, dedication, and execution drives our success. And thanks to all our customers, partners, and shareholders for their continued support. Thank you again for joining us today. With that, I'll hand it over to our CFO, Sonali Parikh.