Table of Contents

1. SentinelOne (S) – Earnings Review

a. SentinelOne 101:

SentinelOne directly competes with CrowdStrike, Microsoft Defender and Palo Alto in endpoint security. It specializes in small-and-medium-sized business (SMB) clients and is now expanding up-market. While CrowdStrike’s overarching platform is called Falcon, SentinelOne’s comparable suite is called the “Singularity Platform.” Core products include Endpoint Detection and Response (EDR). EDR offers constant monitoring and protection of endpoints (like a company iphone). It unveils, prioritizes and responds to observed threats. Like CrowdStrike, it offers highly autonomous services and a slick, lightweight agent to drive interoperability. This, in turn, means overarching coverage and superior breach protection vs. legacy incumbents.

Also similar to CrowdStrike, SentinelOne boasts a complementary data analytics platform (which it calls the Singularity Data Lake). This lake can ingest structured data from a multitude of diverse security products. It’s the perfect complement for every product it offers, as it can seamlessly collect data once, and recycle that data across as many relevant use cases as it needs to. This capability is especially important for the firm’s Extended Detection and Response (XDR). XDR is simply EDR with more diverse data usage to extend protection beyond solely the endpoint.

The Singularity Data Lake ingests data via “log scale,” which means logarithmically organizing and storing data. The company also says customers get lower cost and faster querying speeds with it too. The service of aggregating data (or “logs”) to help organizations uncover and remediate threats is called Security Information and Event Management (SIEM).

All in all, there are three compelling effects of this product architecture:

  • Open, inter-platform data sharing also leads to more effective algorithm seasoning to drive better coverage and false positive minimization.

  • Cross-selling is especially margin accretive for this business model. SentinelOne incurs most of its customer costs as it deploys its first module; cross-sells are almost pure margin.

  • Seamless expansion into other relevant security niches…

Just like CrowdStrike (noticing a theme?), it’s also actively expanding into cloud security. Important cloud security acronyms:

  • CWS = Cloud Workload Security. It’s an agent-based, preventative cloud protection tool to observe any bad behavior by cloud environment entrants. It sounds the alarm bell for SentinelOne’s automated breach protection and, if needed, the Managed Detection and Response (MDR) threat hunting team (called Vigilance).

    • This was SentinelOne’s original aloud product.

  • CNAPP = Cloud Native Application Protection Platform. This is a buzz phrase used to describe a firm’s full set of cloud tools.

  • CSPM = Cloud Security and Posture Management. CSPM reports vulnerabilities and conducts configuration analysis in any cloud environment. It can flag improper permissions or hygiene. It doesn’t stop breaches in isolation, but does offer needed alerts, which frees other cloud tools like CWS to do so.

    • It acquired PingSafe to expedite delivery of this key cloud capability and bring its product suite closer to parity with CrowdStrike.

Agent vs. Agentless in Cloud:

CWS takes an agent-based approach while CSPM is agentless. Agent-based requires a direct software installation, while agentless does not. One isn’t objectively better than the other. Agentless is considered cheaper, easier to deploy and easier to scale. It’s perfect for lower-stakes use cases like configuration analysis and is a perfect complement to CWS. Companies just starting out with finite budgets, massive potential scaling needs and a lack of hyper-sensitive data can adopt an agentless approach. Agent-based is considered more comprehensive and has more complete visibility. Industries with tighter regulation, more sensitive assets, a need for real-time EDR and more complex compliance are well served by agent-based. By offering both, SentinelOne can address both markets, thus eliminating the need for disparate point solutions.

GenAI:

PurpleAI is SentinelOne’s overarching GenAI platform layer to up-level its product offering. It’s quite similar to CrowdStrike’s Charlotte AI, in that it can actively detect anomalies, help orchestrate remediations and fix issues with a human analyst’s permission. All of this pushes beginner-level security analysts to much higher levels of capability. This matters a lot in our budget-and-talent-constrained world.

b. Demand

  • Beat revenue estimate by 0.8% & beat guide by 1%. Its 39.3% 2-year revenue compounded annual growth rate (CAGR) compares to 54% last quarter and 63% two quarters ago.

  • Beat Annual Recurring Revenue (ARR) estimate by 0.5%. Beat net new ARR (NNARR) estimates by 4.8%. Met vague NNARR guidance calling for a Q/Q “acceleration.” It exceeded internal ARR estimates by a “double-digit percentage.”

  • Remaining performance obligations (RPO) rose by 40% Y/Y as it enjoys more large contract momentum. This will translate into ARR over time, so it’s encouraging to see this metric’s growth leading ARR and revenue.

  • Missed 1,273 $100,000 ARR client estimates by 40.

  • Net revenue retention (NRR) remained “solidly in expansion territory.” It continues to focus on new customer wins rather than expansions. This means lower NRR today, but more cross-selling down the road.

The CrowdStrike outage had zero impact on Q2 results as it occurred almost all the way through the period. Q2 outperformance was based on general organic momentum. Much more on CrowdStrike later.

c. Profits & Margins

  • Beat -$10M free cash flow (FCF) estimate by $4.5M.

  • Beat -$12.0M EBIT estimate & beat identical guidance by a little over $6M each.

  • Beat 79% gross profit margin (GPM) estimate by 60 basis points (bps; 1 basis point = 0.01%) & beat guidance by 50 bps.

  • Beat $0.00 EPS estimate by $0.01. First quarter of positive EPS. EBIT will come later because it collects so much net interest income from its debt-free balance sheet.

Total operating expenses rose by 11% (GAAP & non-GAAP). R&D rose by 9%  Y/Y, sales and marketing (S&M) rose by 19% Y/Y and G&A fell by 11% Y/Y due to lower legal and stock comp charges.

d. Balance Sheet

  • $700M in cash & equivalents; $417M in LT investments.

  • No debt or notes.

  • Diluted shares rose by 6.6% Y/Y. That will slow as it moves further away from its IPO. As a good hint, stock comp dollars rose by 22% Y/Y to materially trail revenue growth. That needs to continue.

e. Annual Guidance & Valuation

  • Raised revenue guidance by 0.4%, which slightly beat estimates.

  • Reiterated -4.0% EBIT margin guide, which slightly missed -3.7% estimate.

  • Raised 78.5% GPM guide to 79%, which beat by 60 bps.

  • Q3 guidance was roughly in line across the board.

Guidance does not bake in material uplift from the CrowdStrike outage, even though management explicitly said it thinks it could come. It reminded us that sales cycles take 9-12 months, most customers don’t act impulsively here and that the financial impact will play out over the coming years, not months. SentinelOne told us it expected an acceleration in business trends throughout the 2nd half of the year last quarter. It reiterated that expectation this quarter, based on things like fantastic RPO growth.

f. Call & Letter

CrowdStrike & Microsoft Outage:

Unsurprisingly, SentinelOne leadership did not hold back in its criticism of CrowdStrike (and Microsoft too). As an important caveat, the two always talk trash about each other, and this quarter was no different. Here’s what it had to say about the incident:

“Performance shortcomings of other offerings are becoming more visible. In the last few months, we’ve seen breaches and system failures from the top two endpoint share vendors… The latest global IT outage highlights the significance of platform architectures, process controls, and building resilient security operations… This was an avoidable incident that was born out of risk-prone software deployment practices and a fragile product architecture… Understandably, customers and partners are now looking for better platform architectures and building more resilient cyber-defenses. Some of the largest enterprises in the world are now evaluating and appreciating the Singularity platform’s breadth and superiority relative to the competitive offerings… As a result, customer interest in our platform and AI-based security has distinctly risen.”

SentinelOne Founder/CEO Tomer Weingarten

SentinelOne took some time to walk us through how it thinks its architecture is superior to others. In reality, it’s somewhat similar to CrowdStrike, with the same claims of lower cost and superior efficacy.

CrowdStrike vs. SentinelOne — What’s Similar?

Both products can work on-premise or across multi-cloud environments. Both offer agent-based, on-device offerings and an agentless offering too. Both routinely talk up the multi-layered protection that it offers and how “redundancy” ensures reliable security if one layer isn’t properly working. Redundancy is a safety net in place to mitigate these risks.

CrowdStrike vs. SentinelOne —What’s Different:

On the other hand, there are some foundational differences to the architectures. There are more hardware installation requirements for most of SentinelOne’s products, which makes CrowdStrike arguably more scalable. CrowdStrike is considered to be more truly cloud native, without separate products for cloud and on-premise deployment. Next, SentinelOne requires less frequent software updates; this will become increasingly popular considering a software update is what caused the CrowdStrike outage. Beyond that, SentinelOne’s agent doesn’t need to be as deeply embedded in a customer’s core infrastructure (or “kernel”). This is a calling card for SentinelOne’s leadership team. For mac-based endpoints, it doesn’t touch the kernel at all. CrowdStrike does, which means any of its blunders will have a larger impact on overall operations.

“Self proclaimed industry leadership and overzealous marketing can create a false perception of reliability. This incident is resulting in significant pipeline pickup for us from some of the largest enterprises in the world that did not have a chance to appreciate our breadth and superiority relative to others. All of that is changing now… some of these companies have already made the decision to switch.”

SentinelOne Founder/CEO Tomer Weingarten

What do I think of all of this? I think when we look back 20 years from now, this will be like Coke and Pepsi arguing that one is king and the other is a loser. The two will endlessly bicker and throw shade at each other. They’ll both claim superiority and that the other is a pretender. What matters? That these are arguably the two best companies on the planet within a sector that offers a massive runway, antiquated incumbents and easy product expansion. Both offer endpoint efficacy that is materially better than alternatives and both are adamant that superior efficacy paves the way for minimal false positives and lower customer costs. They should both do very well over the coming years if they execute.

The Platform Play – Newer Products:

SentinelOne is a few years behind CrowdStrike in rounding out its product suite beyond solely endpoint. CrowdStrike has been deeply profitable for longer, and so has had the luxury to spend more aggressively on new products & M&A. With SentinelOne’s profit inflection now secured, it’s ready to match this aggression. Signs so far are good as Purple AI, the data lake and its cloud security solutions all grew more quickly than overall revenue. 

Platform expansion rates (new product up-take) “remained healthy” and ARR per customer again grew by over 10% Y/Y. While new products are working, its core endpoint niche is still growing very nicely. It took more market share there during the quarter and sees its best-in-class market share taking here (per IDC) as continuing in the years ahead.

  • $1 million+ ARR customers rose faster than $100K ARR customers (so faster than 24% Y/Y).

Purple AI:

For Purple AI specifically, SentinelOne continues to reiterate its ability to drive 80% faster threat hunting and investigations. It sees this AI arm as best-in-class, and cited it as a main reason for its outperformance. The product is “exceeding all expectations” early on and is enjoying a double-digit percentage purchase rate for all new endpoints sold in Q2. Leadership sees purple AI as having clear leads in onboarding, use case breadth and ease of use. Like CrowdStrike’s competing Charlotte AI tool, purple “alleviates the challenges of machine speed response, talent shortage, alert fatigue, and enhances analyst productivity.” It uplevels all beginner security analysts to extend highly finite client talent much further. It’s an efficiency force multiplier for better protection. This quarter, SentinelOne launched “Alert Summaries.” These are automated summaries of vulnerabilities to nudge analysts with prioritized alerts.

Cloud Security & Data:

SentinelOne added runtime cloud security and another cloud security product acronym to the fold. This time, it’s Cloud Infrastructure Entitlement Management (CIEM). CIEM offers seamless oversight of access controls for cloud assets. It can “detect over-privileged humans and machines, pinpoint toxic permission combinations and curtail risk with greater speed and efficiency.” This was the largest product gap remaining between SentinelOne’s suite compared to Palo Alto and CrowdStrike. Important debut.

Customer Wins Cited:

  • Its SIEM tool led to an expansion with a global aerospace firm. The first is ingesting 2x the data it used to and is saving money compared to its old SIEM vendor.

  • Global financial institution replaced 4 endpoint vendors with its product.

  • For one of the largest U.S. hospitals, Sentinel and a leading competitor were both deployed. The other vendor led to instant breaches and so this customer cut the other vendor.

Macro & Go-to-Market:

Macro did not improve Q/Q for SentinelOne. It simply executed better and began to see the fruits of its go-to-market overhaul to accelerate big customer growth and overall results. It’s seeing direct yet early progress in new business generation, pipeline, competitive win rates and its overall growth outlook. 

“We continue to win a significant majority of competitive evaluations against both next gen and legacy vendors across endpoint data and cloud.”

SentinelOne Founder/CEO Tomer Weingarten

Momentum here helped drive the outperformance this quarter. I would love to see $100K ARR customer growth accelerate, but it was too early to expect that this quarter. 

It’s leaning more heavily into its managed security service provider (MSSP), incident provider and cyber insurance partnerships. SentinelOne doesn’t struggle on the technology side. The team will readily tell you their tech is world-class, and 3rd party research firms do routinely back that boldness up. Where SentinelOne struggles is on the awareness and selling sides. It’s imperative to use these partners to help spread the word. It’s also imperative to work more closely with the public cloud vendors, like Google. Considering this, its expanded Mandiant Consulting (owned by Alphabet) partnership this quarter to make it the partner of choice across incident response is notable.

  • Created a network of insurers to help smaller clients find affordable rates as part of its SentinelOne Risk Assurance Initiative.

  • Partnered with Cybersecurity and Infrastructure Security Agency (CISA) to “provide threat detection and response across federal IT assets.”

g. Take

I wanted a larger annual guidance raise amid all of the commentary on already winning new customers from the CrowdStrike outage. I was slightly disappointed until I heard the revenue guidance doesn’t include any potential positive impacts from CrowdStrike. 

That potential positive impact will not come in Q3. It could come in Q4, as SentinelOne should be far enough along in some sales cycles to close deals. Commentary on deal closures already happening makes me quite confident in that being the case. Companies don’t make “snap decisions” on switching security vendors, so this will take more time than most thought.

With that said, results were again very good. The investment case is still quite strong. It offers best-in-class growth and leverage, with a pristine balance sheet and immense optionality. And? If I’m picking on a raise as my main source of disappointment, you know the quarter went relatively well.

2. CrowdStrike (CRWD) — Earnings Review

a. CrowdStrike 101

CrowdStrike is a next-gen, cloud-native endpoint cybersecurity company. It competes directly with SentinelOne, Microsoft Defender and Palo Alto. Its bread-and-butter is called endpoint detection and response (EDR), which replaces legacy anti-virus (AV). Beyond EDR, it offers applications in cloud security, log management, forensics, identity, data protection etc. to round out its “Falcon Platform.” Falcon’s edge is in its ability to digest near-endless amounts of data to automate and uplift breach protection. CrowdStrike uses its large and diverse dataset to constantly improve Falcon’s efficacy and use cases… all with a single console and single agent to ensure superior interoperability. It can recycle this same data over and over again to efficiently develop new products for a single interface. More utility without adding complexity.

Important Endpoint Security Acronyms:

  • Endpoint detection and response (EDR) provides end-to-end visibility, constant monitoring and full protection of endpoints (like a company iPhone). It unveils, prioritizes and responds to over served threats.

  • Managed detection and response (MDR) encompasses CrowdStrike’s team of threat hunters to augment EDR with human touch when needed.

  • Extended detection and response (XDR) is EDR with 3rd party, non-endpoint data sources infused. The incremental data sharpens breach protection and extends it beyond the endpoint.

Important Log Management Acronyms:

CrowdStrike’s security data lake is a vital complement to every single product it offers. It uses log scale to ingest, logarithmically organize and store data. Broader data ingestion means better breach protection as Falcon’s products are more properly trained on larger sets of relevant insight. CrowdStrike also says customers get lower cost and faster querying speeds with it too.

This allows for ingestion with more scale and faster time to value. As an important aside, Log Scale is a key ingredient for Falcon XDR. It is instrumental in XDR onboarding needed data sources in a scalable and efficient manner. This can be used to improve security and other parts of operations too.

  • Security Information and Event Management (SIEM) aggregates security logs/data to help organizations uncover and remediate threats faster. Log Scale is closely related to SIEM, as Log Scale is what actually collects data from various sources to be utilized here.

Important Cloud Security Acronyms:

  • Cloud Security & Posture Management (CSPM) tells you about your vulnerabilities and misconfigurations.

  • Cloud Infrastructure Entitlement Management (CIEM) tells you who is entering a software environment. It tells you if these entrants are allowed and exactly what they’re allowed to do.

  • Cloud Workload Protection (CWP) is a preventative measure to observe if anything bad is being done by entrants. This sounds the alarm bell while preventing and remediating cloud infrastructure attacks. It’s closely related to CSPM and CIEM.

  • Application Security Posture Management (ASPM) locates and facilitates the safe control of cloud apps.

  • Cloud Native Application Protection Platform (CNAPP) is the overall suite tying all of these cloud products together.

b. Demand

  • Beat revenue estimate by 0.6% & slightly beat guide by 0.3%.

  • Beat ARR estimate by 0.6% & beat net new ARR estimate by 11%.

  • Slightly beat 97.8% gross revenue retention (GRR) estimates & met GRR guidance.

c. Profits & Margins

  • Beat EBIT estimate by 10% & Beat guide by 8%.

  • Beat FCF estimate by 5%.

  • Beat $0.97 EPS estimate by $0.07 & beat guide by $0.05.

  • Beat 80.2% subscription GPM estimates by 40 bps.

d. Balance Sheet

  • $4B in cash & equivalents.

  • $743M in debt.

  • Diluted shares +3.8% Y/Y.

e. Guidance & Valuation

  • Lowered annual revenue guide by 2.4%, which missed by 1.5%.

  • Lowered annual EBIT guide by 14%, which missed by 12%.

  • Lowered $3.98 EPS guide by $0.35, which missed by $0.28.

  • Q3 guidance missed across the board.

The outage is driving lower visibility into the back half of the year, longer sales cycles and more deal scrutiny. It has also forced CrowdStrike to forgo outbound pipeline generation activity and some professional services work, but all of that has since resumed. These are all headwinds. Furthermore, as part of its new Falcon Flex initiative discussed below, it will be offering more discounting and less extensive module purchasing options. This will cost it $60 million in NNARR for the rest of the year, and was the main source of the guidance cut. These contractual concessions are likely a direct response to the outage, but that wasn’t explicitly said. All of these items will weigh on revenue and ARR for the next four quarters before an expected “acceleration starting in the back half of next year.”

“So I think that this type of incident has a half-life, right? So there'll be a diminishing impact over time. So Q3 will be harder than Q4. Q4 will be harder than Q1 and so on and so forth.”

CFO Burt Podbere

f. Call & Release

The Outage:

The majority of the prepared remarks were spent on the global CrowdStrike IT outage from July.  Founder/CEO George Kurtz started the call with an apology. He called the last several weeks the hardest of his career and committed to building a more resilient CrowdStrike. He reminded us how rapid the CRWD response was and how most endpoints were back to normal in a matter of hours. He also walked us through several CrowdStrike changes made to ensure this never happens again.

  1. Better software updates content visibility and control. It released new configurations so customers have more autonomy over what CrowdStrike can deploy and when.

  2. Added new content validators, which was the main thing that didn’t work during the outage. This went live in August.

  3. Added multiple 3rd party vendors for external code review and validation.

  4. “Enhanced” the content release process with “sample testing, internal lab testings, early access testing and staggered rollouts.

“Today starts a new chapter for CrowdStrike. One focused on ensuring that cybersecurity's best AI platform for security operations, protection, visibility, response and automation is also cybersecurity's most resilient platform… we've immediately addressed learnings from the incident and will continue to apply and evolve these lessons into our future.”

Founder/CEO George Kurtz

I’m rather confident that CrowdStrike will not repeat this mistake, but the July outage already happened. So what’s the impact? Over the last two weeks of this quarter (following the event), several deals were delayed, with almost all of them remaining in its pipeline. Before the event, CrowdStrike was poised to “deliver net new ARR growth well ahead of these results.” It thinks it lost about $60 million in total bookings, but thinks it will eventually win this business back. This $60 million headwind is in addition to the other $60 million committed package headwind already mentioned.

In terms of legal liabilities, there’s still a lot of uncertainty here. It does have contractual amendments that limit liabilities and insurance in place, but there are likely some fines coming (or at least more customer credits).

“Most of my customer calls lately start out the same. They talk about our response, how transparent we were and how we dealt with the problem. We talk about some of the mitigating steps that we've taken, and it generally ends with we want to do more with CrowdStrike.”

Founder/CEO George Kurtz

Evidence of Resilience:

For some evidence of CrowdStrike being able to quickly recover, it closed several large deals following the major outage. It highlighted three 8+ figure deals for its cloud division and two 8 figure deals for its SIEM product. For one of those clients, CrowdStrike cut 60% of their data processing and querying costs. A GenAI leader also standardized on CrowdStrike’s SIEM tool in a 7 figure win. One of these was a Fortune 500 insurer, which closed its contract with CrowdStrike right in the midst of the outage. Beyond winning new customers, it’s keeping old ones too. Gross retention remains at an elite 98% and dollar-based churn over the last 5 weeks was lower vs. the Y/Y period. Wow. Generally speaking, CrowdStrike remains confident in reaching $10 billion in ARR by 2030, which is at the backend of its previous time range. It reiterated all long term margin targets too.

“I'm reassured by customers and prospects feedback, wanting to do more with CrowdStrike post-incident as evidenced by multiple 7- and 8-figure platform expansions with most opting for multi year deals.”

Founder/CEO Geoge Kurtz

How in the world is it still confident in long term targets? I’m glad you asked. This platform is extremely sticky. When you are routinely displacing 10+ point solutions, driving superior interoperability, fostering better protection AND driving lower costs, ripping and replacing is just not attractive. Sure, the incident was immensely annoying for its clients, but this is an anomaly for CrowdStrike. Its reputation is as fantastic as its track record and tech.

“If you look at the latest MITRE results, Falcon had 98% coverage. Our next-gen competitor had 79% coverage. It took Falcon 4 minutes from mean time to detection. It took our competitor 47 minutes.”

Founder/CEO George Kurtz

One blunder is not proving to be nearly enough for clients (even prospective clients) to jump ship. Not surprising… still encouraging. CrowdStrike sells an average of 7 modules per customer and is “firmly rooted” in its customer base’s ecosystems. It also provides a massive data network effect by letting its large group of customers openly share insights with the Falcon platform to augment protection.

Risk of Losing Shared Microsoft Customer Kernel (core infrastructure) Access:

Kurtz was asked about the risk of Microsoft restricting its kernel access. CrowdStrike is somewhat reliant on deeply embedding its agent in the kernels of its customers, so that would be an issue. SentinelOne has also criticized CRWD’s architecture for reliance on kernel access. Here’s what Kurtz had to say about all of this:

“So despite a lot of the false narratives and misinformation from our competitors, I want to be clear that this was not a kernel update… It was a configuration update… I’ve got to set the record straight on architecture as well. We have a very lightweight agent that requires 100 megabytes of storage. Our competitor has a heavy agent, which requires 3 gigabytes of storage in the Windows environment. We didn't become #1 in the market by having a poor architecture. We became #1 by having a great architecture.”

Founder/CEO George Kurtz

So we'll continue to work with Microsoft as part of the ecosystem as they look to provide further enhancements around kernel access.

Platform Play:

While CRWD was once known as an EDR specialist, it’s now so much more than that. Per Kurtz, interest in platform consolidation remains very high. That’s encouraging, considering one of the takeaways from the outage was a need to move away from vendor consolidation, as it adds risk. That consolidation also drives interoperability, better product efficacy and lower cost. The pros continue to outweigh the cons. July did not change that in the least, per Kurtz.

Between SIEM, identity, cloud and data, CrowdStrike crossed $1 billion in ARR, with 85% Y/Y growth. Cloud rose 80% Y/Y to $515 million; identity rose 70% Y/Y to $350 million; data rose 140% Y/Y to $220 million. All of these product buckets are thriving.

  • 8+ module deals rose by 66% Y/Y.

Partner Momentum:

66% of CRWD’s customer wins during the quarter came from partners. Its system integrator (SI) business rose by 100% Y/Y while it continued to rapidly build momentum in the Google Cloud Marketplace. During the quarter, it was the fastest growing cybersecurity vendor there. Alphabet is rapidly joining AWS as another key hyperscaler selling partner.

Falcon Flex:

Falcon Flex is CrowdStrike’s program to cater to smaller and more price conscious customers. It allows for these customers to pay for only the modules they need as they need them. There are no pre-set commitments and customers are not locked into product usage. Momentum here is fantastic, as the new initiative jumped from $500 million in contract value to $700 million this quarter. This is especially resonating with its SI partners like Deloitte. The diminished buying friction “supercharges” platform adoption by making it easier to buy exactly what a customer wants when they need it. 

Notably, this quarter Falcon Flex added “customer commitment packages.” This uses Falcon’s traditional module selling process, but incorporates Flex’s pricing and contractual flexibility too. It offers a diverse series of bundles (with some comped services) and the ability for customers to lock in favorable pricing on a multi-year basis. Throughout all of this commentary on pricing, it’s important to note CRWD’s gross margin continues to expand and it expects that to continue.

“Customer commitment packages are a proactive and concerted investment we're making to build long-term loyalty and seed long-term platform adoption.”

Founder/CEO George Kurtz

Final Notes:

  • Set a new speed benchmark for threat detection in a MITRE study.

  • Named a leader in the Forrester Incident Response report.

  • Won more product awards at the SC Awards Europe event than any other vendor.

  • CrowdStrike will more deeply partner with Nvidia on its NIM Blueprints product (discussed in the NVDA earnings review) to let customers securely embrace GenAI.

  • Partnered with several tech distributors in Latin America to accelerate traction there.

g. Take

The question I’m left with following this earnings report is “that’s it?” That’s the impact from the historically large IT outage? Just a little more discounting, some guidance cuts and a small delay to long term ARR targets?

The muted impact is a testament to how sticky, well-regarded and effective CrowdStrike is in the world of security. This quarter leaves me immensely confident that this firm will rebound, and will do so more quickly than I initially thought. The team LOVES to sandbag, so you better believe they baked all potential weakness into that guidance. And still? We are left with an elite top and bottom line compounding with a massive runway. CrowdStrike was taken off of my “do not accumulate” list after this quarter. 

3. Nvidia (NVDA) — Earnings Review

a. Nvidia 101

Nvidia designs semiconductors for data center, gaming and other use cases. It’s unanimously considered the technology leader in chips meant for accelerated compute and Generative AI (GenAI) use cases. While it specializes in chips, it does a lot more than that too. Its toolkit includes chips, servers, switches, networking and cutting edge software. It designs the entire next-gen data center layout with slick software integrations so customers can enjoy the best of accelerated compute. Nvidia calls these data centers “AI factories.”

The following are important acronyms and definitions to know for this company:

Chips:

  • GPU: Graphics Processing Unit. This is an electronic circuit used to process visual information and data.

  • CPU: Central Processing Unit. This is a different type of electronic circuit that carries out tasks/assignments and data processing from applications. Teachers will often call this the “computer’s brain.”

  • Hopper: Nvidia’s modern GPU architecture designed for accelerated compute and GenAI. Key piece of the DGX platform. Blackwell is the next platform after Hopper. Rubin will come afterBlackwell.

  • H100: Its Hopper 100 Chip. (H200 is Hopper 200)

  • L40S: Another, more barebones GPU chipset based on Ada Lovelace architecture. This works best for less complex needs.

  • Ampere: The GPU architecture that Hopper replaces for a 16x performance boost.

  • Grace: Nvidia’s new CPU architecture that is designed for accelerated compute and GenAI. Key piece of the DGX platform.

    • GH200: Its Grace Hopper 200 Superchip with Nvidia GPUs and ARM Holdings tech.

Connectivity:

  • Nvidia Link Switches: Designed to connect Nvidia GPUs within one server. GPU connections power great efficiency, performance and computing scale (so cost advantages). 

    • The newest Blackwell system allows for 144 total GPUs to be connected (several factors higher than Hopper).

  • InfiniBand: Interconnectivity tech providing an ultra-low latency computing network. This can connect larger batches of accelerated compute clusters for more scalability.

  • Spectrum X: Newer networking tech for large-scale, Ethernet-only AI. It delivers 60% better networking performance vs. alternatives.

    • This can connect “tens of thousands” of GPUs. Nvidia wants to soon push that to the millions.

Software, Models & More:

  • NeMo: Guided step-functions to build granular GenAI models for client-specific needs. It’s a standardized environment for model creation.

  • Cuda: Nvidia-designed computing and program-writing platform purpose-built for Nvidia GPUs. Cuda helps power things like Nvidia Inference Microservices (NIM), which guide the deployment of GenAI models (after NeMo helps build them).

    • NIMs help “run Cuda everywhere” — in both on-premise and hosted cloud environments.

  • GenAI Model Training: One of two key layers to model development. This seasons a model by feeding it specific data.

  • GenAI Model Inference: The second key layer to model development. This pushes trained models to create new insights and uncover new, related patterns. It connects data dots that we didn’t realize were related. Training comes first. Inference comes second… third… fourth etc.

  • DGX: Nvidia’s full-stack platform combining its chipsets and software services.

b. Demand

  • Beat revenue estimate by 4.5% & beat guide by 7.1%. Its 66.4% 3-year revenue CAGR compares to 66% last quarter and 64% 2 quarters ago.

  • Beat data center revenue estimate by 4.8%. Data center revenue is where GenAI demand shows up for Nvidia. Within that bucket, compute revenue rose by 150% Y/Y and networking by 100% Y/Y.

c. Profits & Margins

  • Met GPM estimate & slightly beat its GPM guidance. GPM fell Q/Q due to new product mix and inventory provisions from Blackwell issues (more later).

  • Beat EBIT estimate by 6.6% & Beat guide by 8.9%. Operating expenses (OpEx) rose by 52% Y/Y to support rapid growth.

  • Slightly missed FCF estimate.

  • Beat $0.64 EPS estimate by $0.04. EPS rose by 152% Y/Y.

d. Balance Sheet

  • $34.8B in cash & equivalents.

  • $8.5B in LT debt.

  • Dividends +150% Y/Y.

  • Share count fell slightly Y/Y.

  • New $50B buyback.

e. Guidance & Valuation

  • Revenue guidance beat by 2.4%.

  • EBIT guidance beat by 1.7%. Now sees annual OpEx growth of 45%-49% Y/Y vs. 40%-43% previously.

  • GPM guidance missed 75.4% estimates by 40 bps. Reiterated expectations for a mid-70% GPM for the year.

f. Call & Release

Return on Investment Debate:

Leadership was asked several times on the call about customer return on investment. There’s undeniably an arms race taking place; large companies are eager to lay the foundational architecture to support the next generation of accelerated compute apps and services. With this in mind, many think customers are buying first and thinking second. They see risk to return on investment that could erode demand for more chips in the coming quarters.

Nvidia doesn’t see things this way. It’s confidence comes from a few places. First, its customers routinely save money when implementing accelerated compute capacity. Why? Because it’s wildly more efficient for complex use cases than general compute. All of the chat bots, copilots and agents that most of us now interact with cannot affordably run on general compute. CPUs cannot scale in a way that makes this at all feasible. They’re great for concrete, step-by-step tasks, but not model training and inference and so not high performance apps. Accelerated compute GPUs are needed to drive the efficiency gains needed to make these investments rational. Without them, “compute inflation” (as Jensen calls it) would be sky-high and anything but “transitory.” (couldn’t resist)

Blackwell GPUs are absolutely more expensive than commoditized CPUs, but cost is not value. The efficiency and performance gains pocketed from using the right technology for the right use case materially outweigh the added costs of purchasing this better technology. They’re best-in-class when it comes to speed of data processing, model inference, app creation and data center optimization (thanks to its integrated software).

Secondly, for hyperscalers, GPU demand is still booming. They can easily rent purchased GPU capacity to clients to profitably collect more revenue. For example, IDC reports that $1 spent on Nvidia infrastructure leads to $5 in revenue over the next 4 years. This creates a sub-1-year payback period and an extremely compelling value prop. Nvidia often says that its customers save more by spending more with Nvidia. Datapoints like the one above offer 3rd party verification of this being accurate.

The Demand & Margin Runways:

The other debate stemming from this call was how long the mega-cycle for high performance infrastructure can last. Nvidia is confident in strong data center growth lasting beyond fiscal year 2026, which gives it another 18 months of strong demand. Confidence here stems from the reality that new models will represent a (10x-40x) step-change in compute capacity requirements to make them more useful and dynamic. When combining this with the large roster of companies joining the model and app-building folds, the runway remains long.

But what about pricing power? Nvidia’s ridiculously high margins are a direct byproduct of its next-gen chips being better than everyone else’s. That drives supply scarcity, which will last for Blackwell through next year. If it didn’t have unmatched products, pricing power would wane, supply scarcity would diminish and margins would normalize. This is why it’s so important that Nvidia keeps rapidly driving more innovation… and it is.

Its H200 chip is now shipping in volume and has 40% more memory bandwidth than the H100. Hopper demand remains quite strong, and the team sees growth remaining robust for this platform through the end of the year. That is when demand for its new Blackwell platform will kick in. Blackwell will begin shipping in volume in Q4, and can drive 30x inference speed gains vs. predecessors. There were some issues with the mask of the semiconductor design, and these have since been resolved. A few analysts thought this would lead to delays, but Nvidia continues to expect to ship a few billion in Blackwell revenue in Q4. No changes to the chip’s foundation were needed.

  • Nvidia isn’t seeing customers pull back on Hopper orders as they await Blackwell and Rubin chips. Per Jensen, customers cannot afford to wait if they’d like to lead in the GenAI booms within their respective sectors.

  • The Hopper supply bottleneck has not vanished, but is improving.

  • The MLPerf inference benchmarks awarded Nvidia with top ranks across all categories.

Enterprise Adoption of GenAI:

As I’ve discussed many times, most GenAI monetization has happened at the hardware and infrastructure level to date. That’s why Nvidia’s results look so impressive. Foundations are being laid to support the coming decades of accelerated data processing compute. As that foundation is laid and companies drive product-market fit for their apps, the next wave of monetization will be at the software level.

That seems to be beginning. Nvidia is now working with most of the Fortune 100 on AI apps. It’s helping customers reduce customer service costs by 30% and was instrumental in creating the NOW AI Assist product, which was the best launch in its history.

One of the most popular enterprise AI tools so far has been its Omniverse product. This allows companies to build digital twins and run massive simulations of factory workflows, healthcare outcomes etc. It enables powerful testing in a zero stakes environment to turn trial and error into well-intentioned operations. Winstron is using this to fun factory cycle times by 50%; Foxconn and Mercedes are also using this product.

To nurture this enterprise AI momentum, Nvidia is partnering with Meta and its Llama 3.1 frontier-level model. Meta’s decision to make Llama open-source and its ability to create world-class models create compelling opportunities. The formula paves the way for client developers to freely use these elite models to build better GenAI apps within the managed Nvidia environment. Accenture is the first customer here.

Software & Networking Notes:

Nvidia launched NIM Agent Blueprints this quarter. This is a library of template apps, with Nvidia’s end-to-end suite of chip, networking and software tools. The first use cases are in customer service, drug discovery and retrieval augmented generation.

  • Aramco, Lowe’s and Uber were named as users of NIMs. AT&T is driving 70% savings with NIMs for call transcription and classification.

  • Nvidia reiterated its belief in networking revenue being a multi billion dollar revenue line within the next year.

  • Software and support revenue will reach $2 billion annualized this year. It reached $1 billion at the end of calendar 2023.

China:

Following Chinese export restrictions on next-gen chips, revenue there cratered for Nvidia. It was 20% of its total data center segment, but is now much lower. This just shows you how strong demand is everywhere else. Nvidia is still somewhat supply constrained (getting better) even without that key source of demand. It is still selling some lower-quality chips into the country, which allowed Q/Q revenue growth there to turn positive for the first time in a while.

Final Notes:

  • Gaming demand remained strong, with channel inventory levels called healthy.

  • 20% Y/Y ProViz growth was driven by the auto and manufacturing sectors.

  • Autonomous vehicle chip demand fostered 37% Y/Y auto and robotics growth.

  • Japan's National Institute of Advanced Industrial Science and Technology is building its new supercomputer with Nvidia. Nvidia raised its outlook for sovereign AI revenue from $7-$9 billion to $10-$12 billion for this year.

  • building its AI bridging cloud infrastructure 3.0 supercomputer with NVIDIA.

g. Take

Nobody focusing on the data can call this quarter anything but strong. Nvidia has trained the world to expect crazy, jaw-dropping, out-of-this-world outperformance. The level of outperformance was ~only~ very good.

The debates on how long this cycle will last and how durable Nvidia’s lead is will rage on after this quarter. It’s tech lead seems quite solid as it sprints to deliver more innovation and performance gains. It’s hard to envision anyone catching up. AMD has the best chance, but won’t reach Blackwell-level performance until Nvidia’s newer, better Rubin platform begins to ramp. Still, AMD can stitch together its own GPUs at a lower cost (does not need a 75% gross margin like Nvidia has) to emulate its performance and that could lead to more competition next year. That would erode pricing power and lead to profit growth pressure as it laps historically high margins. Not the easiest setup, but Nvidia has been overcoming difficult setups for over a year. We’ll see what happens.

So what about cycle longevity? That is the trillion dollar question. Yes, all hyperscalers and mega-caps have said they’ll spend more on CapEx in 2025. Yes, Nvidia sees the demand runway lasting through the end of next year. But? With expectations for this company as high as they are, will that growth be enough? Sell-side wants 40% Y/Y revenue growth next year, and also probably wants Nvidia to not only meet that target, but exceed it. That’s a high bar to clear.

These are the questions for bulls and bears to ask themselves. I don’t have any strong, passionate opinions about these topics… but they will be the topics that drive the next several quarters of Nvidia debates and price action.

Salesforce & Lululemon earnings reviews will be published tomorrow. Have a great night.

Reply

Avatar

or to participate