Executive readout · one minute
Call research workspace
Read the call alongside every captured source. Transcript, audio stay in one workspace.
Conference · 2026-08-11
Executive readout · one minute
Read the call alongside every captured source. Transcript, audio stay in one workspace.
Research coverage
2 live sources
Switch sources without leaving this page or losing your listening position.
Open the source you need; every reader stays inside this workspace.
Listen and read together
The spoken word highlights as audio plays. Select any word to seek to that moment.
Hi, good morning, everyone, and thanks for joining us for Oppenheimer's 29th Annual Technology Conference. We have with us today AftPoint CEO TJ, CFO Jim Khaki, and Jamie Arista from Investor Relations. Gentlemen, thank you so much for joining us today. Before we begin, for the audience, we do have a question bar for you that you can send questions, or separately, you can email me at parham.singh at opco.com, and I can ask the question on your behalf. So first, thanks again, TJ, Jim, for joining us. I wanted to kind of thank you again for taking the time today. And again, very high level to begin for some of the audience here who may not be as familiar with AftPoint. If you could kind of start with, you know, where you participate in the market, what are some of the niche areas where you are advantage and kind of give a lay of the land for the audience here?
Good morning, Paran. Thank you for having us. Yeah, so AppPoint, we're an industry leader in cloud data management, governance, and security. Where we play is really helping enterprises curate and govern their unstructured data, which includes all emails, chats, files, contracts, and what have you. So we have been doing this for 20 plus years, and we have done this very successfully globally in the large enterprise public sector. regulatory industry, as well as now SMB. Of course, in the AI era, folks very quickly realized that to have good, high-quality AI deployments, you need to also have high-quality data that AI grounds on. So we have extended since the last few years into the space of AI governance, Agenic, asset governance, and cost control, and discovery. So this is now really the really massive tailwind for us as we lean into this narrative of being the AI trust layer for our customers and partners. We're the layer between the model and the data. So as everyone knows, the commercial large language models, frontier AI companies, their models are trained on public available data. But for companies, for them to leverage AI to be productive for their business, they need to have AI refined on their own corporate decades worth of corporate industry data. And that's context aware. That's also dynamic. So in this framing, increasingly the ability to be able to manage both the foundational data layer as well as the AI agentic layer to work in cohesion with the right data set, with time sensitivity, with the right access control, life cycle management, permission control. And also, very importantly now, also cost visibility. It's what allows our partners and customers globally to have comfort and confidence in their AI deployment. So the two top-of-mind issues we help companies large and small address, one is AI risk and AI cost. So that boils down to fundamentally what we do. And we are the largest such cloud player specializing in Microsoft cloud ecosystem. But we have extended beyond that because customers are multi-cloud. So we now also cover Google, cover Salesforce, and Atlassian, and a number of other ecosystems as well.
Fantastic. You know, there's a lot of different topics I want to dive into. But maybe first, the most intriguing one for everybody in the audience and myself has been AI and how different vendors are participating in it, right? right? So TJ, you kind of touched upon that a little bit, that you're adding the governance and the compliance layer to the agent side, the AI side. Maybe we can delve into a little bit that, especially with your new product, Agent Pulse, right? How are you specifically addressing that market? Because it's so nascent. How do you kind of get confidence around what the agents are doing? What are they doing from a rules and regulatory perspective? Or maybe some of the advantages that AvePoint brings as an organization that would allow people to use your product versus somebody else for monitoring and governing, let's say, Egypt here?
Right. That's a great question. So for a decade plus, our expertise has been helping companies manage the risks and exposures of employees working on corporate data, right? So what data the employees have access to internally, externally, how long those data should reside, should live for, and how do these data get ingested into the corporate system and how do they get retired, right? Whether it's archived out, record managed out, tiered storage out, or completely purged. So in the age of AI, AI agents are no different than employees in the sense that they have access to systems, process data, make decisions. Except now AI is operating at machine speed. So everything is accelerated. So we already have this governance framework for quite a number of years in the cloud to manage large data estates. We're talking about petabytes of data and for our customers around the world. So now when Microsoft first introduced Power Apps, we did the same thing. We just elevated our delegated governance framework to include Power Platform, Power Apps. So this delegated model means IT doesn't really understand what data and what business applications are doing for the business users. So our framing allows the business user to provide context richness to that. So then this delegated governance framework, compliance framework, then implement and actuate the corporate policy. So in the age of agentic AI, it's the same thing. So basically, a business user can provide that context and richness of what this agent has access to. If you Vibe code an AI agent, by default, that agent inherits your permission structure. But that may not necessarily be the actual intended outcome. So we have the governance framework to allow users to actually provide that context so that we can then, our software, can then start to track those agents just like any other semi-autonomous or fully autonomous computer applications, their access rights, their data rights, and also, of course, their lifecycle, and then monitor their cost. So we help enterprises go out and discover all the agents running in cloud, whether it's Microsoft or Google. Very shortly, we're extending onto the devices so we can actually discover like open cloud agents that's running there as well. So today, of course, we support Microsoft Copilot, Google Gemini, and then also now Anthropic Cloud and ChatGPT, those type of, you know, AI services and agents. and then bring them under control. So this is something we've been doing for a long time. It's just really, in the agentic era, we then extend to the agents. Again, no different than previously how we governed employee access, except now everything is just operating at machine speed.
No, that's great. And that's one point, TJ, I kind of wanted to delve into. I think people kind of forget that there is some inherent advantage of taking the skill set from dealing with human-based governance and compliance to machine governance and compliance, and of course, everything is at machine speed, which means it's exponentially higher. But maybe for my edification, too, if you can kind of talk about what are some of the inherent advantages in practical terms that you are leveraging from your existing expertise, one. And then two, when you're dealing with things at a machine speed, what are some of the newer items you had to introduce to be able to handle that, both from a monitoring perspective, but also from a response perspective, right? Because you also need to kind kind of manage a much larger databases, have the correct accurate information and kind of stop things at machine speed as well. So maybe some clarity that would certainly be better for my edification here.
Yeah, that's a great question, Prem. So the benefit, firstly, the benefit that we have the right to own this space is that, again, we've been in this space for a long time. And our software are certified by some of the most rigorous security agencies, FedRAMP certification, U.S., ISMAP in Japan, which is like 3,000 security check certifications. So we are running government data centers already in commercial data centers. So that fully vetted compliance and regulation and scaling and that capability around cloud security, cloud app, has already been vetted out for the last 15 plus years for some of the most rigorous commercial and public sector enterprises, including the biggest banks on Wall Street. So that's a massive, you know, basically credit and trust that's already there in a highly scalable software. Now, the challenges in the machine speed that you rightly point out is that then the reaction and monitoring it have to also step up in machine speed. So this is why actually last week at Black Hat, we released what we call kinetic classification, which is basically dynamic reclassification of content based on policy changes, role changes, data changes. so then we can actually in real time modify the context richness of objects so that as AI act on those different type of things, we can actually evolve and change. So my background is in machine learning and data mining, actually. So in our space, there's the concept called drift. So I think most of your audience understand that now. AI, especially Gen AI, is a non-deterministic technology, general purpose technology. but what it can do over time is it can have drift just like in social media if you know this echo chamber that people talk about right so the the the fact is uh 60 percent of unstructured data today are now generated by ai so if ai is acting on ai generated data if you don't actually go proactively curate it and manage it and govern it and retire it that drift problem becomes uh happens very quick right so all of a sudden you're detaching from ai you know basically another way to think about it is it'll hallucinate more right so it detached from reality very quickly so it is that continuous proactive uh coverage and lastly i would say because we have a singular platform that doesn't only begin and end with governance and compliance but we also have resiliency and data protection and data integration so what happened then is if you have bad actors, whether it's human actors or agenic actors that go and modify or destroy part of the infrastructure, we can actually recover also at machine speed. So this is also something we released last week. Again, on top of everything we already have, what we call rapid intelligence recovery to prioritize the assets that you want to recover very, very quickly. So this actually came into light very um relevant when we talk about q1 earnings we we talk about the middle east conflict when that first occurred uh amazon data centers were hit uh in middle east right regional data centers so we were able to help our customers recover very very quickly uh in other you know environments so customers realize that you cannot just only rely on one hyperscalar infrastructure so um the demand for resiliency for recovery this technology has been deployed for, you know, 20 plus thousand customers in terms of ransomware detection and recovery, and now are using it for AI, you know, damage detection and recovery. So that's the resiliency side that we do. So this is an end-to-end platform that provides this risk management and cost management for our customers.
That's phenomenal, TJ. It's really good to see, you know, some of the progress being made here as an industry. Maybe we could kind of quantify some of these things. It seems like a newer vertical for you, even though the technology is more expansive from what you're already doing. How would you quantify, say, from a cross-sell perspective or maybe an incremental ARR and TAM to the business here?
Yeah, so we just finished Q2 where we announced for the 13th straight quarter of double-digit net new AR growth. We had the largest net new AR quarter as well. So, clearly, we're showing acceleration in our business. So, 87% of our business is fully recurring. That's what the ARR captures. And then we have 12% to 13% that's in services. Increasingly, that's becoming AI foundry type of services. Because what we found is that customers also recognize, it's no surprise that Anthropic OpenAI is now starting consulting arms, right? And Microsoft Consulting now pivoting towards frontier company. You actually need intelligent engineers who understand data, who understand integration and intricacies of systems, connectivity of systems to land AI. So we also have that piece going for us as well. So we see strong momentum. We share specifically to Agent Pulse. It's part of our control suite. We GA in Q1. And by Q2, the number of control suite customers have already doubled. the demand is so high that we actually made it into a independence queue in july just last month a light version that allow customers to quickly discover all the shadow ai that's happening in their enterprise that that requires their attention to go remediate and bring under governance and control and monitor costs for and we also share that when on average when when customer deploy Agent Pulse product from us, our customers are actually already managing actively on average 5,000 AI agents. And what's remarkable, it's the speed of growth of that number of agents. So we see that it's doubling, literally we release in Q1, right? So we see that number is doubling on a per customer basis every quarter, every three months. So we already have customers that's managing, monitoring and managing 100,000 agents. Again, mind you, any AI agent can be a light agent, can be a workflow, right? It doesn't have to be a full-on virtual employee type of agent. Those are still very rare and few because those are very costly for companies to run as well, right? They could cost hundreds of thousands in token consumption on a yearly basis. But any agent that employees Vibecode for workflow that's just running out there, it's an agent. it's a computer process.
Got it. I know that's pretty helpful, TJ. And, you know, we've taken this one lens of how you are addressing AI from a product standpoint, but how about using AI for your existing products? You know, what have you used internally to maybe upscale your capabilities or maybe improve time to market on introducing new versions of the same product? Anything you'd share from internal use of AI here?
Yeah, that's a great question. So, obviously, we are dev shop we're a very large engineering organization so our developers are using github copilot behind the scenes of copilot can actually github copilot allow you to change different type of frontier models for for usage of coding assistance of course from a qa perspective that's harness testing harness automated testing harness are now leveraging ai internally for for customer support, for sales support, for finance. We also have our own internal AI initiatives and projects. Even back in 2022, we released these very, very intelligent AI services that allow employees to go find resources very quickly and be able to engage our partners and customers much quickly and more intelligently. So there's that internal consumption of AI. But very importantly it's the integration of that into our product so for example in our product we have this assistant called ava apple and virtual assistant it actually uh help our customers proactively identify risks and exposures they have and proactively highlight different aspect of our confidence platform that can being be brought to bear to help customers solve problems to help them save license costs um and uh you know storage costs and all that so so there's already this uh internal essentially uh product level ai capability that actively recommend function and features and lastly um we we also because we we collect a lot of signals uh for for our customers across office graph so we have this uh product called tie graph that collects all the um interactions sentiments these you know essentially metadata across all the conversations emails and file access patterns etc and that's a very nice intelligent database we also now offer a genetic experience with that layer because well our customer come to us some of the big four consulting company audit firms they say hey not only IT and CISL want to use your product for Intel. Now, business users want to query that for information, whether it's HR or finance folks, but they don't want to use your UI. Can they just use AI to directly interface? And we also made that possible. So it's the agentic experience. So we go from UI to UX to AX experience as well. So that allows us to expand significantly the type of persona we can help within the enterprise.
That's great, TJ. One of the products that I was looking at that I was kind of personally excited about with some of these AI developments was Opus, was lifecycle management. And, you know, maybe that ties into what we're seeing today with identity and identity resilience and what's coming up in the space. So maybe we can talk a little bit more about some of this identity and overall lifecycle management, particularly because, you know, with everything that's going on in the world and international threats and so on and so forth, it's the topic du jour. and that's where everyone is spending a lot of incremental dollars on. So maybe, TJ, you know, we can talk about Opus a little bit more and what you're seeing there.
Yeah, that's a great question. So our background as a company, we came from the enterprise content management background, right? So think about the old days. You have Documentum, you know, OpenTax, you know, Fionet, those type of products. So record management, document management, compliance, data classification. It's a core part of what we do. So what Opus does is actually, it started off as a record management product. It has the AI classification capability to help discover taxonomy. And we also use this, by the way, in our modernization suite when we help customers classify, tag, and then migrate through data analytics and migrate data between systems. So migration is basically data movement. Data would never stop moving between systems, on-prem to cloud cloud to cloud think about you know you're moving data from maybe microsoft stack to amazon stack to google stack and from salesforce to dynamic crm to uh you know hop spot you know different systems when you do migration to movement we actually help support a lot of that happen so this is why part of our recurring revenue is the migration side so we use the opus capability to do taxonomy discovery help them classify tag and move assets over so we always give the framing when you move the house you don't move everything as is and put it exactly where they were because the new house have completely new structure you get rid of stuff you're doing yourself you dump stuff and then you remove and you reorganize that's what a typical enterprise system move looks like and then um so opus allow customers to do what we call one shots or even guided capability to classify. So kinetic classification is another layer on top to do the machine speed classification in real time. What Opus also does, a very popular and strong feature, is storage optimization. It allows customers to save, basically, if you move all your data in cloud, everything in cloud has a cost, right? There's compute cost, there's network cost, there's storage cost. In compute, of course, everybody know about token maxing, right? That was last year's thing. But that's just GPU compute. But there's also a CPU compute. So now, do you want to leave all your stuff there to incur cost? You may not. So we have a very – part of what Opus does is storage optimization. It will basically, based on its study and analysis of your data set, it will say, hey, this set of data hasn't been touched for a year, right? It's under this classification or this version. Because in the office world, in productivity world, whether it's Google or Microsoft, you can keep many versions of the same document to track changes, right, from an audited, palliative perspective. So, but do you really need 100 versions of the same document? Can you actually version out the previous 90 versions, the previous year versions? So, those storage and deduplication. So, all those storage optimization is also part of Opus capability to actually help our customers save costs and stay compliant.
Got it. That's great, TJ. Before I move on, I do have a question from the audience. And I do want to remind everyone, you can definitely type in your questions, or you can email me at barum.singh.com. So for the audience question, TJ, Jim, how do you price across your different product portfolio at this time?
So predominantly, it's a subscription pricing. It's priced predominantly based on the number of employees, just like Microsoft pricing Office H5 and how Google prices work workplace. So it's employee account pricing, seed-based pricing. In some cases, we do consumption pricing. So even migration, for example, we have partners. We have a very robust partner ecosystem. Nearly 60% of our revenue is done through partners. We have partners that are system integrators that would continually migrate one client after another, manage service providers. So they're basically subscribing to the software. But we also have partners that would do large projects and one and done. And those large projects, when the data size is of a certain amount, we start flipping over to a capacity-based, consumption-based licensing. Same thing applies to backup. So resiliency side, if you have very few employees, but tons and tons of data, and we have many design shops that are like that, then we also have consumption-based pricing. Because if we don't do that, then we will start to, you know, essentially operate at a loss. So we have, but predominantly we are seed-based licensing mode. We are increasingly covering what we call IaaS and PaaS. So infrastructure as a service, platform as a service. These are basically compute cloud workloads. So you think about AWS, think about Microsoft Azure, think about Google GCP. So because a lot of AI actually run and applications run in compute cloud, not in productivity cloud, which is where emails and documents are hosted. So over there, the predominant market kind of framing of licensing is consumption-based. So we also have consumption there. So we really follow the market. The hyperscalers are effectively the market makers. They will say, okay, for productivity, we do seed-based. For the compute side, for the IaaS and PaaS, we do consumption-based.
I think, Jim, you want to chime in? I don't know if...
Yeah, no, I think TGA did a very good job of summarizing that. And, you know, we've always talked about really, you know, treating the value of our software as truly an ROI proposition for our customers. And we still strongly believe that. So whether that ultimately winds up being years from now, whether it's consumption or, you know, ultimately, if some sort of seed-based licensing continues in one way, shape, or form, the end result is really always comes down to ROI. Are you getting value from the dollars you're spending? We believe that our software provides that value. And so ultimately, however it's being charged, it's about providing value to our customers.
Got it. I had a couple on pricing as well. So one I'm curious about how things change with agent pulse. That has to be priced very differently. Obviously, you can't do it on a per agent basis either because it's going to be, I don't know how you would do it, right? because there's millions and billions of agents getting turned on and they're ephemeral and some are longer than others and so on and so forth. So that's one part of it. And then separately, I had a question on what you're seeing as an industry, right? Seed-based pricing in general is under flux. The idea is under the AI landscape, headcount will get reduced over time. So is there a way to mitigate that because you might see more usage per user rather than an expansion in the number of seats? So how are you guys thinking about that second dynamic as well?
That's a great question. So first, I'll address the second part. So I know last year, everyone was worried about, you know, in the SaaS puckerless phase, everyone's worried about the massive C reductions. And also, obviously, you know, AI replacing human phase of the hype curve. we think that has largely gone away because also at the same time the way hyperscaler think about it microsoft and google specifically they think about in the world where you have full-fledged virtual employees right these are very sophisticated ai agents they will have full email access crm privileges and data access privileges so they're actually licensed as a person they're license as a non-human identity, but same as seat-based licensing. So there's that, right? In the very sophisticated side of it, AI is essentially a virtual employee. As far as a hyperscaler is concerned, it's a licensed entity, just like a carbon-based employee, right? Right. So we right now do the seed based licensing because also our customer is the customers are really frustrated over the consumption based licensing, especially when it comes to AI. So last year is token maxing. This year, of course, the price has gone up. Nobody nobody's doing that anymore. Right. It's kind of also silly to approximate productivity and return on investment by counting out how many tokens you're actually consuming. It's really the business outcome that really matters. So this year is really much more intentionality around measuring business outcome of with deployment AI and also obviously managing AI risk. Right. So because every other day we hear about frontier models, letting their dinosaur out of the cages and go do some damage on the Internet. So so that's also another side problem. So but so, yeah, so I think right now for us, we're monitoring very closely. We stay with seed-based because customers also want that for predictability. Nobody wants to all of a sudden budget a certain amount, and also with AI consumption, you vastly exceed that. What do you do then? Do you just shut off all AI access, and then your employees are used to using AI, and they cannot use it anymore? That's also not a good thing to have. So predominantly, we still stay at seed-based. We're monitoring this very closely. We continue to, because we have economy of scale, and we also, behind the scenes, are balancing different type of model usage cases. So, we're controlling our gross margins on the product side. So, we do monitor that. But for now, we like to predict the consistency and predictability for our customers.
I know we're getting close to time, but since we started late, maybe I can sneak two different questions in. And firstly, you know, you have a lot of different products that are coming into the market. You're also expanding beyond your core Microsoft capabilities. You mentioned it earlier in the conversation. You mentioned Salesforce, Google, Atlassian, if I remember correctly. So let me put it all together, right? How should we be thinking about your TAM and ARR expansion? And again, you mentioned, you know, marquee quarter of NetU ARR in your 2Q results last week. So how should, as an audience, be thinking about, like, net new ARR going into next year and that expansion? And within that, how do you kind of balance your investments in R&D to support these new initiatives and expansion capabilities versus operating margin expansion?
Yeah, that's a great call. So we actually are looking at, so we think the TAM is massive. So just to give you a sense, right, even Microsoft, just Microsoft Office 365 alone, it's anywhere from 450, it's roughly around 450 million user seats. entire Microsoft Office co-pilot activation, it's just 30 million seats, right? So, and this is, it's been three years, you know, so they went from 20 million to 30 million in a quarter, but it's still been three years. So there's really a massive uplift. So we think the market is huge in terms of not only the number of user seats, but also the different type of cloud coverage, the different ecosystems and different use cases. This is also why in the most recent earnings, we announced that we are stepping up the investment to increase investment on go-to-market, especially the channel side, which helped us reach very good sales efficiency. When we went public, sales and marketing is 44% cost of revenue. Now it's like 31%. We think we can do better. But there, we need to bring on the partner and channel development and also brand awareness campaigns, marketing, because these things take time to ramp, to build up for acceleration into next year and beyond. And there's also technology investment as well, because, again, the token consumption costs are going up. At the same time, we're getting more efficiency. So I think the TAM is getting much bigger. So we want to actually present to the market at our next investor day, the new reframing of the TAM, because we think that TAM has now completely, there's a very dynamic change to our TAM. We're very, very excited about expanding TAM.
Great. TJ, now this is a question, my last one, and this is what I ask everybody. One is what you're most excited about and one what keeps you up tonight. So I think most of the call kind of already highlighted all the excitement that you have. But maybe we could focus on what is the number one thing or a couple of things you're most concerned about or keep you up at night here?
I think what keeps all CEOs up at night is security. Honestly speaking, it's getting – because now cyber, it's operating at machine speed, right? So we have established a very good reputation in terms of, you know, governing and protecting our customers' data, some of the most sensitive agencies in the world. But it's an everyday battle. And so now it's a genic type of, you know, fighting machine with a machine type of case now. And I think everyone is very, very worried about this. The frontier model company's marketing tactics doesn't really help either. So I think that's – so this is – there's no silver bullet, honestly, right? And there's no one provider that can help you solve all your security concerns. It's truly a multi-layered, multi-facet approach to security. You have to protect your endpoints. You have to protect your emails. And you have to educate your employees to be vigilant. And, you know, and also the nature of Gen AI with these prompt injection attacks, it's very, very hard to catch as well. Right. You can even do a prompt injection attack on commercially, you know, sanctioned tools, you know, if the attacker is creative enough.
So these are new security services that's keeping most CEOs up at night, I think. no that's great and look uh for me personally tj uh jim i'm more excited about the next iteration of uh fpoint's journey so thank you for making the time today uh tj jim jamie um and thank you for the audience for attending our conference today thank you for having us thank you