Table of Contents
1. GitLab (GTLB) — Brief Earnings Snapshot
As a reminder, I write these “brief” earnings snapshots on names that aren’t part of the core coverage network based on reader interest. The “detailed” earnings reviews offer much more thorough looks into quarters.
a. Demand
Beat revenue estimate by 4.7% & beat guide by 4.9%.
Beat remaining performance obligation (RPO) estimate by 5%.


b. Profits
Beat EBIT estimate by 36% & beat guide by 37%.
Beat $0.18 EPS estimate by $0.07 & beat guide by $0.075.
Missed -$0.19 GAAP EPS estimate by $0.03.
Missed FCF estimate by 35%. This is highly lumpy on a quarterly basis due to things like accounts payable timing. Best to focus on annualized FCF generation.


c. Balance Sheet
$1.2B cash & equivalents.
1.7% Y/Y dilution.
d. Guidance & Valuation
Raised annual revenue guide by 1.4% which beat estimates by 1.3%. Q3 revenue guidance slightly beat estimates. Most of the raise came from Q2 outperformance.
Raised annual EBIT guide by 8.7% which beat estimates by 8.7%. Q3 EBIT guidance beat estimates by 19%.
Raised annual $0.805 EPS guide by $0.055 which beat estimates by $0.05. Q3 $0.195 EPS guidance beat estimates by $0.015.
GitLab traded for 57x EPS heading into the earnings report. Pre-analyst estimate revisions, EPS is expected to fall by 15% this year and then grow by 27% next year. Estimates will rise following this upbeat report.


2. UiPath — Brief Earnings Snapshot
a. Demand
Beat revenue estimate by 3.1% & beat guidance by 3.2%.
Beat $32M net new ARR estimate by 15.6% & beat guidance by 17.5%.
Slightly beat total ARR estimate & slightly beat guidance.
Net revenue retention (NRR) was 109% vs. 109% Q/Q, 108% Y/Y and 115% 2 years ago.


b. Profits
Beat EBIT estimate by 18.4% & beat guidance by 18.7%.
Met $0.15 EPS estimate.
Slightly beat FCF estimate.


c. Balance Sheet
$1.27B cash & equivalents.
Diluted share count shrank 3.7% Y/Y.
No debt.
d. Annual Guidance & Valuation
Raised net new ARR guidance by $7M from $206.5M to $213.5M, beating estimates by $6.5M. Net new ARR growth was raised from 10.4% to 14.2%.
Total ARR guidance was slightly raised and slightly ahead of estimates.
Raised annual revenue guidance by 0.8%, beating estimates by 0.7%.
Raised annual EBIT guidance by 3.5%, beating estimates by 3.2%.
Q3 guidance was slightly ahead across the board.


3. Samsara (IOT) — Brief Earnings Snapshot
a. Demand
Beat revenue estimate by 5.1% & beat guidance by 5.2%.
29% constant currency growth comfortably beat 22.5% growth expectations.
Beat $104M net new ARR expectations by 29%.


b. Profits
Beat 76.9% GPM estimate by 140 basis points (bps; 1 basis point = 0.01%).
Beat EBIT estimate by 21.7% & beat guidance by 21.8%.
Beat FCF estimate by 18.7%.
Beat $0.01 GAAP EPS estimate by $0.02 & beat guidance by at least $0.03.
Beat $0.16 EPS estimate by $0.04 & beat guidance by $0.045.


c. Balance Sheet
$800M+ in cash & equivalents; $500M in long-term investments.
No debt.
3.3% Y/Y dilution.
d. Guidance & Valuation
Raised annual revenue guidance by 1.8%, beating estimates by 1.5%.
Raised 23.5% constant currency (CC) growth guidance to 26% CC growth.
Raised $0.71 EPS guidance by $0.06, beating estimates by $0.06.
Reiterated positive GAAP EPS for the year.
IOT trades for 48x EPS. EPS is expected to grow by 38% this year and by 20% next year.


4. CrowdStrike (CRWD) — Investor Day 2026
a. AI – Research & Models
CrowdStrike announced the Cyber Superintelligence Lab as a research entity dedicated to blending AI adoption with sound security. It’s led by Dr. Bartley Richardson (who they just hired from Nvidia to run CrowdStrike’s AI programs) and will have some of CRWD’s $1B annual R&D budget. Kurtz thinks a lot of the work and investment thus far has been focused on product and general performance improvements. To him, more work is needed on developing security systems to guard assets going forward, and CRWD is all in.
Next, CrowdStrike introduced its very first family of models called SafeMind. They’re built using Nvidia’s Nemotron models (Jensen made an appearance) and trained on a boatload of sensor and outcome data flowing through the Falcon Platform. It’s that information, built on decades of effective scaling across a wide array of security use cases, that improves model quality for security use cases. That’s especially true because these models don’t need to be good at anything else, allowing CRWD to focus all efforts to maximize security talents.
Within this new family are two models. First is Red Tempest, which is an agentic threat hunter perpetually sifting for vulnerabilities to be exploited. This matches machine-speed attacks with machine-speed vulnerability management, helping customers keep up with and prioritize patch work backlogs. While Red Tempest is described as CRWD’s agent-based proactive offense, Blue Solano is the response-based defense. It’s responsible for stopping breaches as they pop up. Both models constantly improve from the ever-increasing access to data on CRWD’s massive platform, and as the two scale, the experience each builds will directly support the efficacy of each other. Yet another way for CrowdStrike to turn data scale into defensible product edges that sub-scale incumbents can’t match.
CrowdStrike is not interested in forcing model lock. Instead, they’re eager to offer these tools to customers, allowing easy ways to mix and match models for different tasks. This will help optimize for cost and performance right on CRWD’s platform, making them a more valuable partner. And they still get paid when other models like OpenAI’s are consumed through their platform, making them a more compelling partner for the emerging giants. Importantly, alongside these models, world-class data loss prevention (DLP) and posture management modules offered by Falcon ensure data flowing to and from them is done so safely and compliantly. So? Customers get to freely use whichever tools they want without worrying about data leakage issues.
With these models, CrowdStrike is delivering a sharp 70% improvement in output accuracy compared to off-the-shelf options while cutting cost per detection and remediation from $10 to $0.03. And to build on that dramatic cost improvement, the two models materially lower the false positive rates (as high as 80% per Sentonas) that off-the-shelf models and harnesses can produce, further reducing costs and focusing companies on the right issues more quickly. SafeMind will be offered later this year only via Falcon Flex and used by CrowdStrike in two ways. First, natively in the Falcon platform, where red and blue will power existing modules like exposure management. Second, as standalone models and harnesses for customers that want direct access.
CrowdStrike’s deep customer relationships give it an intimate understanding of their day-to-day operations. With this knowledge, it’s using SafeMind to build an agent that serves as a digital twin engine to test vulnerabilities and exposure.
CRWD says Blue Solano performance is 29%+ better at detection than two frontier labs while being 99% cheaper. Red Tempest is 66%+ cheaper as well.
SafeMind will be sold via token consumption packs and served through their Falcon Flex go-to-market as they nudge customers to that plan.
b. Falcon Guardian – AIDR Becomes a Product Category
CrowdStrike upgraded AI Detection & Response (AIDR) under the module name Guardian and established it as a formal product category. It became available during the week and is compellingly seamless to add thanks to native inclusion in Falcon Flex. Like Palo Alto’s AI Runtime Security (AIRS), this provides an end-to-end service for protecting all AI-related assets and their interactions, with detection and response capabilities to uncover threats quickly enough to remediate before disaster.
AIDR secures agents across the endpoint (where Claude, Codex and Electron apps are consumed), cloud workloads, and SaaS agents. It also extends to the browser. Capabilities in this release include AI agent discovery and inventory to create that overarching view of operations, find impermissible (shadow) AI and know what is deployed at all times. CrowdStrike uses all of these capabilities to actively set agent permissions and facilitate them too. With CrowdStrike, companies not only know what agents are doing, but they can trace it back to the exact prompt that initiated that action, the user who wrote the prompt and all affected parts of a company. More capabilities include:
An AI Gateway similar to what Zscaler and Palo Alto have built that offers a centralized location for AI traffic processing. This has open integrations with competing AI Gateways if customers prefer using theirs.
CrowdStrike is adding an AI-augmented Falcon Complete offering for Falcon Guardian, bringing managed detection and complete operational service to these capable modules.
Tight integration with CrowdStrike’s Security Information and Event Management (SIEM) to ensure the modules have needed data and can collect incoming data to perpetually improve performance.
CrowdStrike thinks they can win here against Palo Alto and Zscaler in what sound like network-based tasks. To them, the dominant position in endpoint is a better base to build off of than their network counterparts. It sees the traffic before it enters a network and pre-encryption, giving it a better shot to respond quickly. It also offers a wide array of modules that produce a broad range of useful data from a massive customer base. This also helps fortify their solution and create a product that’s harder for network-centric players to beat.
The AIDR ramp post-launch is about 8x faster than EDR was at the same stage of maturity. They see this eventually being much bigger than EDR.
c. Identity Updates
Identity got a new product called Agentic Identity Provider (IdP). Traditional identity providers were built for humans with logins and passwords. Agents have none of that, so organizations have been giving these agents passwords like they would human identities and hoping for the best. Conversely, CrowdStrike’s Agentic IdP is purpose-built only for agent and machine-based systems. It uses Falcon Guardian to register all agents with cryptographically verifiable identities. Rather than getting permanent passwords they’re offered exactly what’s needed for a specific request over a short period of time. This eliminates the possibility of threat actors abusing these logins. For years, essentially every major breach has been via a username and password pulled out of a vault with standing privileges attached. These systems have not worked, and yet some wonder what will happen if we try to still make them work with exponentially more traffic. CrowdStrike offers a different way to alleviate this concern that I think will build quick traction.
The agent registration arm pairs perfectly with CrowdStrike’s Continuous Identity module that actually enforces permissions and grants real-time entry based on the information that Agentic IdP provides.
Tightened admin-level account control (privileged access) across more SaaS apps, endpoints and cloud environments. And thanks to Agentic IdP, CRWD knows exactly when an agent has been registered and tags it with identity details on the spot, eliminating any gap between onboarding and permission enforcement that could lead to issues.
d. The Next Evolution of the Agentic SOC
CrowdStrike added a slew of new SOC tools to position it as the most complete centralized security admin in a crowded field. New products include multi-agent investigations that simultaneously release agents and let them perform root cause analysis and remediation mapping until the agents converge on a best plan. Importantly, all of this agent-based work comes with persistent memory, meaning learning and improving from one permanently helps all of these machine-based tools improve.
Next, CrowdStrike combined AgentWorks, Charlotte AI and Falcon Foundry to create a bundled solution that should make the SOC even better. Now, customers can conversationally build their own, enterprise-specific agents with whatever model they want and defend against hacks more quickly. They can also plug seamlessly into 3rd-party tools to unlock more work, while granularly tweaking levels of autonomy for these agents. While lower costs are always welcomed, with sensitive use cases across cybersecurity, sometimes a human-in-the-loop is preferable to catch model hallucinations before they turn into big issues.
Falcon Onum’s Certified data pipelines filter low-quality garbage out, helping cut storage costs in half.
e. More on Products
Modern software is routinely built on pre-built code blocks from various repositories. There’s an emerging trend in security entailing “poisoning” popular code blocks with vulnerabilities that can be exploited. CrowdStrike built a product that allows them to inspect all of these blocks in automated fashion before they run.
Debuted Falcon IQ as an automated service for full customer security evaluations. Instead of a team of experts spending weeks digging through data by hand, more than 50 AI agents inside the Falcon platform automatically pull together everything CrowdStrike knows about that customer, spot the biggest weaknesses, rank them by how dangerous they are, and write up a plan for fixing them, all at the push of a button.
f. Partner News
Anthropic is adding Falcon to the Anthropic Claude Marketplace as the first security partner included. Anthropic customers can take a piece of their massive token budget to seamlessly spend it on some CrowdStrike security from the same pool. Considering how rapidly Anthropic is growing, I think this is a pretty big win for CrowdStrike. We’ve seen how AWS and other channel partners can become $1B business contributors. Claude will also add Charlotte AI AgentWorks for better execution on security agent building. Customers conversationally input what they want and this product does the rest. Finally, CrowdStrike will offer Anthropic models as foundations for some modules for customers that want that going forward.
Falcon Guardian included OpenAI’s Codex Agents in its protection menu. And in other OpenAI news, the company’s newest cybersecurity model will be added to Falcon.
CrowdStrike’s platform is being added to Snowflake’s marketplace.
Rubrik's Identity Resilience platform will combine with CrowdStrike's identity suite to offer an end-to-end offering across vulnerability management, breach prevention and remediation. The combined offering will be provided via Charlotte’s Security Orchestration, Automation and Response (SOAR) offering. Joint customers will get CRWD's world-class detection and threat containment modules with Rubrik's up-to-date activity logs and immutable backups amid any issues. The idea here is to expedite resolutions by leveraging the complementary skills each company brings to the table, with a tight integration to drive console consolidation and more interoperable work.
CrowdStrike has 8 partners with $1B+ in lifetime total contract value, with Optiv crossing $2B as of this event.
The full Falcon platform is now running on Google Cloud in U.S. regions to start.
Added 12 new independent software vendors (ISVs) including Rubrik to Project Quiltworks.
g. Financial News
CrowdStrike moved its long-term ARR targets up by 1 year. It now expects to reach $10B by fiscal year 2030 and $20B by fiscal year 2035. Interestingly, the 2035 guide assumes CrowdStrike takes 3.5% of the addressable business available to them each year. This compares to consistently registering 4%, meaning there’s probably more upside to these forecasts. CFO Burt Podbere reminded us of CrowdStrike’s consistent beat and raise track record as a wink towards more outperformance being likely. In the meantime, it also told investors to expect 20% net new ARR growth for fiscal year 2028, pointing to about 24% ending ARR growth for next year as this world-class growth engine keeps marching on at massive scale.
The $20B by 2035 includes an expected $7.5B in AI ARR.
Total addressable market to compound at a 17% clip through calendar 2034 to reach $565B. They aim to take considerable market share during this time, setting themselves up to potentially achieve 20% top-line compounding for many more years.
Reiterated fiscal year 2029 target margins (83.5% subscription GPM; 30% EBIT margin; 36% FCF margin). FCF margin should move from 30%+ this year to 32.5%+ next year despite higher CapEx.
Even their most mature segment (endpoint) is accelerating right now.
h. Quick Take
I think it’s clear that this company is thriving by any measure right now. They are the highest quality security platform in public markets. They are the innovation trailblazer and the organization most capable of expanding beyond their original security category without relying on large M&A to do so. The products announced at this event simply continue a pattern of rapidly setting the product road map curve. Their positioning is dominant and their new modules all seem to build immediate traction while forming an even stickier, more valuable platform. Despite their massive scale, they could easily have several more years of 20%+ compounding with a boatload of operating leverage left to enjoy as well.
5. Meta (META) — Model Momentum
Meta is rapidly making sizable progress and climbing up AI leaderboards with its new models. I don’t get excited about this because I suddenly think Meta is going to build a permanent and defensible lead in the category. I think there’s going to be a lot more leapfrogging. Instead, I get excited because having one of the models in the conversation will (in my opinion) pay handsomely via core business improvements, agent-based software monetization and token consumption. Not needing to pay a direct competitor massive fees just to keep driving product innovation would be ideal, while improvements in model intelligence should keep unlocking more actionable experiences to offer consumers. Through the end of the year, Meta is expected to debut several of these experiences, which I think will make it clear how it aims to monetize hefty AI infrastructure costs at lofty returns outside of boosting core business trends.
I also know Meta is willing to sharply undercut competition on model costs, so having one around the leaders should be more than enough to win some market share. Especially with its world-class distribution networks providing strong appeal for developers.

We’re just a few months removed from Meta being mocked for falling behind in the race. They caught up at lightning speed, which is obviously good news for the company and a sign that their spend and talent are working. At the same time, I don’t think that is a good sign for durable model differentiation. It points to a bunch of money being the main hurdle to building the best general purpose model out there. And while few companies have that cash, all of the companies that can afford it are choosing to do so. I think that leads to a future where there’s a pack of leading frontier models all constantly undercutting each other on token costs as efficiency gains flow in (much like we’ve seen in public cloud computing). Returns can be fine in that scenario, but the real margin opportunity will come from layering on more services with this compute in place.
I think the future batch of model leaders will be complemented by a slew of open-source options and even cheaper alternatives for low-stakes tasks. And? I think the theme of customers wanting to use many different models to cut costs will merely grow in popularity.
To me, all of this means that differentiation will come from data, distribution, and great applications sharpened by years of trial and error. In other words, differentiation will come from the same enterprise software and consumer internet platforms that have thrived for years and years. I think the winners will keep winning.
6. Axon (AXON) — Flock Drama
Ongoing Flock backlash about their cameras being used by officers to break privacy laws and stalk people is heating up. This has led to 50 cities and counties canceling contracts with the company. Axon was very volatile all week and I think it’s getting swept up in all of these ugly events due solely to offering a competing product.
I continue to think Flock’s failure is good news for Axon. The public complaints are not predominantly based on wanting to ban automated license plate reading (ALPR) like both Flock and Axon offer. That’s not a likely outcome in the least. It’s more so a push to improve transparency, cut the illegal creepiness and get companies like Flock to act the right way. Axon leadership explicitly mentioned last quarter how much business they’re winning from Flock because of what’s happening. That’s because Axon is the company that does things the right way. They’re the company with the pristine reputation that customers work with if they don’t want to worry about legal issues popping up.
I think all of this will continue to incrementally feed Axon’s growth engine on top of the remarkable momentum it’s already enjoying. If the stock keeps correcting, I’d likely add.
7. Headlines & Macro
Lemonade renters debuted in Kansas this week while the car product for Tesla FSD drivers debuted in Missouri. A more complete footprint unlocks more efficient national marketing campaigns and allows them to rationally pursue more growth.
Uber laid off 10% of its workers. This includes a 20% cut to managers and consolidating its delivery operations across retail and restaurants. Savings will be used for AV investments. Layoffs are always unfortunate. This isn’t shocking given the large investment cycle they’re in. Uber is also exiting Nigeria and Uganda.
Per WSJ, Gemini 4 is "performing well" in pre-training with more work needed. That will be an important release from Google. Alphabet went from struggling to leading when Brin came back into the picture. They've struggled a bit more lately on shipping models in timely fashion. This could be a good way to change that current narrative.
There's a new FTC suit accusing Amazon of overcharging by $20B via hidden fees charged to merchants and ad buyers. I'd anticipate some tweaks to their fee disclosure policies, maybe a small fine, and no material impact on the business.
Nvidia invested $3.5B in MediaTek (custom chip designer).
Waymo launched in Denver, San Diego and Tampa Bay.
Want more to read? The following detailed earnings reviews were sent during the week:
There was also a portfolio change this week so I updated my holdings and performance.
Next week, I will be sending out a Salesforce earnings review and several reviews of investor conference chats (Goldman event).

