Risk Factors Dashboard

Once a year, publicly traded companies issue a comprehensive report of their business, called a 10-K. A component mandated in the 10-K is the ‘Risk Factors’ section, where companies disclose any major potential risks that they may face. This dashboard highlights all major changes and additions in new 10K reports, allowing investors to quickly identify new potential risks and opportunities.

Risk Factors - NTNX

-New additions in green
-Changes in blue
-Hover to see similar sentence in last filing

Item 1A. "Risk Factors" in this Annual Report on Form 10-K. Moreover, we operate in a very competitive and rapidly changing environment and new risks emerge from time to time. It is not possible for us to predict all risks, nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ materially from those contained or implied in any forward-looking statements we may make. In light of these risks, uncertainties and assumptions, the forward-looking events and trends discussed in this Annual Report on Form 10-K may not occur and actual results could differ materially and adversely from those anticipated or implied in the forward-looking statements.

You should not rely upon forward-looking statements as predictions of future events. Although we believe that the expectations reflected in the forward-looking statements are reasonable, we cannot guarantee that the future results, performance, or events and circumstances reflected in the forward-looking statements will be achieved or will occur. The forward-looking statements in this Annual Report on Form 10-K relate only to events as of the date on which the statements are made. We undertake no obligation, and expressly disclaim any obligation, to update, alter or otherwise revise or publicly release the results of any revision to these forward-looking statements to reflect new information or the occurrence of unanticipated or subsequent events, except as required by law. We may not actually achieve the plans, intentions or expectations disclosed in our forward-looking statements and you should not place undue reliance on our forward-looking statements.

iii


PART I

Item 1. Business

Overview

Nutanix, Inc. ("we," "us," "our," or "Nutanix") is a hybrid cloud and AI platform company, offering organizations a unified infrastructure software platform to run applications, data, and AI anywhere. ("we," "us," "our," or "Nutanix") is a hybrid multicloud computing leader, offering organizations a unified software platform for running applications and AI and managing data anywhere. Our vision is to simplify the deployment and operation of hybrid computing infrastructure and AI factories to support the increasingly distributed landscape of apps and data, including agentic AI, while freeing organizations to modernize their infrastructure and focus on business goals. Our mission is to delight customers with an open, secure platform with rich data services that increases their ability to take advantage of technologies such as cloud native and AI, optimizes how they run their organizations today, and accelerates innovation, efficiency, and growth. Our mission is to delight customers with an open, secure platform with rich data services that increases their ability to take advantage of new technologies such as cloud native and AI, optimizes how they run their organizations today, and accelerates innovation, efficiency, and growth.

The Nutanix Cloud Platform is designed to enable organizations to build hybrid cloud infrastructure. It provides a consistent cloud operating model with a single platform for running and managing applications, agentic AI workloads, and data in core data centers, at the edge, and in public clouds. We aim to provide customers with flexibility and choice across server platforms, storage options, virtualized and cloud-native environments, public clouds, and deployment models. The Nutanix Cloud Platform supports a wide variety of workloads with varied compute, storage, and network requirements. These workloads include traditional business-critical general-purpose applications, modern applications (including containerized applications running on Kubernetes), data platforms (including SQL, NoSQL and vector databases, as well as business intelligence applications), and enterprise AI workloads (including machine learning, generative AI, and agentic AI applications).

We first pioneered hyperconverged infrastructure ("HCI") by combining compute, storage and networking through a software-defined architecture. We subsequently developed Nutanix AHV, our native enterprise hypervisor. Building on this foundation, the Nutanix Cloud Platform has evolved into a unified infrastructure platform. The Nutanix Cloud Platform supports a broader range of architectures, applications and deployment models, across public clouds (including AWS, Azure, and Google Cloud), datacenters, and edge. This expansion includes support for qualified external storage systems, modern applications through our Kubernetes platform, and enterprise agentic AI workloads through our AI infrastructure and management offerings. Our research and development efforts on the agentic AI front aim to provide customers with an optimized full stack platform to run, control, and govern AI workloads.

Our business is organized into a single operating and reportable segment. We operate a subscription-based business model, meaning our products, including associated support and maintenance arrangements, are sold with a defined duration. We operate a subscription-based business model, meaning one in which our products, including associated support and entitlement arrangements, are sold with a defined duration. For more information, see the section titled "Components of Our Results of Operations" included in Part II, Item 7, as well as Note 2 of Notes to Consolidated Financial Statements included in Part II, Item 8 of this Annual Report on Form 10-K.

The Nutanix Cloud Platform

The Nutanix Cloud Platform brings together infrastructure, application, data and management capabilities that enable organizations to run traditional, modern and AI workloads across hybrid multicloud environments. The Nutanix Cloud Platform’s scale-out architecture, common operating model, integrated data services and expanding support for server platforms, storage options, virtualized and cloud-native environments, and public and managed cloud environments provide organizations with flexibility in how they modernize and operate their environments. The Nutanix Cloud Platform’s scale-out architecture, common operating model across locations, enterprise-grade data services and freedom of infrastructure choice enable organizations to standardize on the Nutanix Cloud Platform as a single cloud platform to run a wide variety of workloads.


1


Nutanix Cloud Infrastructure (NCI) is a distributed HCI for enterprise IT applications. NCI software combines compute, storage, and networking resources from a cluster of servers into a single logical pool with integrated resiliency, security, performance, and simplified administration. NCI also supports qualified external storage systems in supported configurations. We believe this expands infrastructure choice for customers and allows organizations to modernize virtualization and cloud infrastructure while leveraging existing storage investments. NCI includes the following underlying features and services:

Nutanix AOS is the scale-out storage technology that makes HCI possible. It delivers enterprise-grade capabilities via a highly distributed software architecture that runs across clusters of servers. AOS includes integrated snapshots, replication, and disaster recovery that can be used with block, file, and object storage, for both virtual machines and containers. Nutanix AOS includes integrated snapshots, replication, and disaster recovery that can be used with block, file, and object storage and for both virtual machines and containers. AOS can be run on virtual machines such as AHV and in containers such as AWS EKS, enabling customers to leverage AOS storage for both virtualized and containerized applications.
Nutanix AHV is our enterprise hypervisor—a virtualization solution designed to provide software-defined compute capabilities to power all kinds of applications including AI, cloud-native, and traditional virtualized workloads.
Nutanix Data Services for Kubernetes offers enterprise data services such as data protection, recovery, migration, cloning, and copy data management for containerized, modern applications on Kubernetes.
Nutanix Disaster Recovery helps organizations design disaster recovery plans. With options that include on-prem, public cloud, and managed service providers, Nutanix Disaster Recovery offers one-click failover, failback, and automated recovery.
Flow Network Security is a stateful, distributed firewall providing microsegmentation designed to secure network traffic between applications.
Flow Virtual Networking provides software-defined networking with multi-tenant isolation, hybrid cloud networking, self-service provisioning, and IP address preservation.
Nutanix Cloud Clusters (NC2) extends the Nutanix platform to public clouds. NC2 enables organizations to run and manage applications across on-premises and multiple public clouds in a consistent manner.•Nutanix Cloud Clusters (NC2) enables organizations to run and manage applications across on-premises and multiple public clouds in a consistent manner. NC2 is designed to enable IT operators to place workloads in their clouds of choice with ease of deployment and migration, delivering flexibility and portability across public clouds. NC2 empowers IT operators to place workloads in their clouds of choice with ease of deployment and migration, delivering flexibility and portability across public clouds.
Nutanix Central provides management of the Nutanix hybrid multicloud environment. Nutanix Central provides global visibility and simplified governance through a single console with federated access, license management, and seamless navigation across on-premises and public cloud deployments.
Nutanix Service Provider Central (SP Central) is a purpose-built control plane designed specifically for Service Providers. SP Central enables consistent, secure, and scalable multi-tenant operations across the Nutanix Cloud Platform.
Nutanix Prism is the unified control plane and UI that provides centralized management for end-to-end IT infrastructure management and operations.

Nutanix Cloud Infrastructure with External Storage is an option for customers wishing to run Nutanix compute and network virtualization and data services with external storage. Organizations can leverage Nutanix Cloud Infrastructure for compute while integrating with qualified external storage solutions, including Dell Technologies PowerFlex and PowerStore platforms and Everpure, Inc. FlashArray storage systems. We have also announced support for NetApp ONTAP-based and Lenovo ThinkSystem external storage integrations, with the NetApp ONTAP-based solution currently available through limited-availability programs.

2


Nutanix Cloud Manager (NCM) is a unified management solution for providing intelligent operations, self-service and orchestration, security compliance and visibility, and control of cloud costs. NCM includes the following underlying features and services:

NCM Intelligent Operations optimizes capacity, proactively detects performance anomalies, and automates operational tasks.
NCM Self-Service and Orchestration streamlines how teams deploy, manage, and scale virtualized and cloud-native applications across hybrid cloud environment through self-service, automation, and centralized role-based governance.
NCM Cost Governance provides visibility into resource utilization, multicloud metering and chargeback.
Nutanix Security Central unifies security operations across distributed deployments to help organizations simplify security planning, define microsegmentation policies, and support regulatory compliance for zero trust.

Nutanix Kubernetes Platform (NKP) is an enterprise Kubernetes platform for deploying and managing modern, containerized applications across hybrid multicloud environments. NKP is designed to standardize application deployment and Day 2 operations across fleets of Kubernetes clusters while providing customers flexibility across infrastructure environments. We believe NKP expands the Nutanix Cloud Platform beyond traditional virtualized applications by enabling customers to operate virtualized, cloud-native and AI workloads through a more consistent operating model across virtual machines and Kubernetes environments.

NKP Metal, currently available through an early access program, brings automated lifecycle management, resiliency, and enterprise data services to bare-metal Kubernetes deployments.

Nutanix Enterprise AI (NAI) is a centralized fine-tuning and inferencing platform. NAI provides AI developers and infrastructure managers with access to models and AI services, with built-in resource management, control and governance capabilities for token economics, data privacy, and sovereignty management. NAI manages resources across GPUs, CPUs, DPUs, and other accelerators, for resource management, performance optimization and operational efficiency across AI workloads.

Nutanix Agent Gateway governs interactions between agents, LLMs, and tools. Nutanix Agent Gateway standardizes agent access to large language models (LLMs), MCP servers, and enterprise applications through a single governed gateway. In addition, it provides organizations with policy management and budget enforcement tools, usage visibility, and real-time token cost accountability across public cloud and self-hosted inference environments. Nutanix Agent Gateway facilitates token-efficient economics through smart model routing, real-time cost visibility, and token-based rate limiting across both private and cloud-hosted LLMs.
Nutanix Private Inferencing helps organizations build adaptive AI factories to serve inferencing needs across their AI initiatives. NAI provides inferencing on CNCF Kubernetes, running across public clouds, data centers, the edge, neoclouds, and OEM partner platforms (such as Cisco, Dell, and Supermicro), complete with Day 2 operations, security, and resilience.

Nutanix Unified Storage (NUS) is a software-defined platform that consolidates file, object, and block storage into one intelligent data fabric. It features a compute-adjacent architecture that provides low-latency access to data for powering real-time AI pipelines and agentic AI workflows. NUS includes the following underlying features and services:

Nutanix Files Storage is a software-defined scale-out file storage solution that enables organizations to store, manage, and scale unstructured data by consolidating storage silos onto a single platform, while keeping it secure with integrated cybersecurity and ransomware protection.

3


Nutanix Objects Storage is a scale-out S3-compatible object storage solution for modern cloud native, AI, and big data applications. It offers intuitive operations, high performance, security, and flexibility for multicloud deployments.
Nutanix Volumes Block Storage is an enterprise-class, software-defined storage solution that exposes storage resources directly to virtualized guest operating systems or physical hosts using the iSCSI protocol.
Nutanix Data Lens is a cyber resilience service offering proactive defense and global visibility for unstructured data that can identify and inform users of malware attacks, such as ransomware, on the NUS platform.

Nutanix Database Service (NDB) is a platform that automates management of diverse database environments with a database-as-a-service platform functionality across on-premises and public cloud environments. NDB automates database lifecycle management and integrates with cloud-native development processes.

Delivery of Our Solutions

The Nutanix Cloud Platform can be deployed in core data centers, at the edge, or in public or managed clouds. The Nutanix Cloud Platform runs on a variety of qualified hardware platforms, in popular public cloud environments such as Amazon Web Services ("AWS"), Microsoft Azure ("Azure") and Google Cloud through NC2, or, in the case of our cloud-based software and software-as-a-service ("SaaS") offerings, via hosted service. Our subscription term-based licenses are sold separately and typically have durations ranging from one to five years. Our cloud-based SaaS subscriptions have durations extending up to five years. Our customers generally purchase their qualified hardware platforms for deployment of our software from one of our channel partners or original equipment manufacturers ("OEMs").

The Nutanix Cloud Platform typically includes support and entitlements. This provides customers with the right to software upgrades and enhancements as well as technical support. Purchases of term-based licenses and SaaS subscriptions have support and entitlements included within the subscription fees and are not sold separately. Purchases of non-portable software are typically accompanied by the purchase of separate support and entitlements.

Our Partners

We have established relationships with our channel, OEM, ecosystem and cloud partners, all of which help to drive the sale and adoption of our solutions with our end customers. Our solutions can be purchased through one of our channel partners or OEMs.

Channel Partners. Our channel partners sell our solutions to end customers, and in certain cases, may also deliver our solutions to end customers through a managed or integrated offering. Our Elevate Partner Program simplifies engagement for our partner ecosystem using a consistent set of tools, resources, and marketing platforms. Our channel partners include distributors, resellers, managed service providers, telcos, and global systems integrators. Our top two distributors to our end customers represented 47%, 41% and 39% of our total revenue for fiscal 2024, 2025 and 2026, respectively.

OEM Partners. Our software can run on qualified hardware from Cisco Systems, Inc. ("Cisco"), Dell Technologies ("Dell"), Fujitsu Technology Solutions GmbH ("Fujitsu"), Hewlett Packard Enterprise ("HPE"), and Lenovo Group Ltd. ("Lenovo"), as part of Cisco Compute Hyperconverged with Nutanix, Dell XC, Fujitsu XF, HPE DX, and Lenovo Converged HX, respectively. HPE also delivers our software with HPE DX servers as a service through the HPE GreenLake offering. Our OEM partners sell our solutions to end customers. We have also worked with Cisco to certify Cisco UCS blade servers for Nutanix AHV, enabling organizations to repurpose existing qualified server deployments.

4


Ecosystem Partners. We have established relationships with a broad range of technology companies that help us deliver world-class solutions to our customers. We have developed relationships with a broad range of leading technology companies that help us deliver world-class solutions to our customers. Through the Technology Alliance Partner and AI Partner arms of our Elevate Partner Program, our developer, application, networking and security, data protection, hardware, infrastructure, and AI infrastructure partners receive access to resources that allow them to validate and integrate their products with Nutanix solutions and engage in joint sales training and enablement. Through the Technology Alliance Partner and AI Partner arms of our Elevate Partner Program, our developer, application, networking and security, data protection, hardware, and infrastructure partners receive access to resources that allow them to validate and integrate their products with Nutanix solutions and engage in joint sales training and enablement. Such integrations enable a simplified deployment and consumption experience for our customers and increase adoption of our platform. Such integrations enable a simpler deployment and consumption experience for our customers in their environments and increase adoption of our platform. We have also developed and announced strategic technology partnerships that bring together best-in-class solutions across the ecosystem into integrated offerings and demonstrated interoperability and support for our customers, including partnerships with Advanced Micro Devices, Inc., Citrix Systems, Inc., Intel Corporation, NVIDIA Corporation, Omnissa, LLC, and Palo Alto Networks, Inc., Intel Corporation, Nvidia Corporation, Omnissa, LLC, Palo Alto Networks, Inc. In addition, we work closely with our technology partners through co-marketing and lead generation activities in an effort to broaden our marketing reach. In addition, we work closely with our technology partners through co-marketing and lead generation activities in an effort to broaden our marketing reach and help us win new customers while retaining existing ones.

External Storage Partners. We partner with enterprise data infrastructure providers to integrate the Nutanix Cloud Platform with qualified external storage solutions. Current offerings include Dell Technologies PowerFlex and PowerStore platforms and Everpure, Inc. FlashArray storage systems. We have also announced support for NetApp ONTAP-based and Lenovo ThinkSystem external storage integrations, with the NetApp ONTAP-based solution currently available through limited-availability programs. These integrations enable customers to deploy NCI with external storage and manage workloads across hybrid multicloud environments.

Cloud Partners. Our partnerships with public cloud providers support our hybrid multicloud strategy. Our partnerships with leading public cloud providers support our vision of a hybrid multicloud. NC2 extends our platform to AWS, Azure, Google Cloud and OVHcloud, enabling organizations to run and manage workloads across private and public cloud environments with a consistent operating model.

Our Support Programs

Product Support. We offer varying levels of software support to our customers based on their needs. We also offer hardware support for customers who purchase the Nutanix-branded NX configured-to-order hardware platforms.

Professional Services. We provide consulting and implementation services to customers through our professional services team for assessment, design, deployment, and optimizing of their Nutanix environments.

Our End Customers

We have end customers across a broad range of industries, such as financial services, retail, manufacturing, public sector, automotive and other transportation, consumer goods, education, energy, healthcare, media, technology, and telecommunications. We also sell to service providers, which utilize the Nutanix Cloud Platform and Nutanix Cloud Infrastructure (NCI) to build new cloud-based service offerings, including solutions tailored to assist their customers seeking virtualization alternatives. We had a broad and diverse base of over 32,000 end customers as of July 31, 2026. We define the number of end customers as the number of end customers for which we have received an order by the last day of the period, excluding partners to which we have sold products for their own demonstration purposes. A single organization or customer may represent multiple end customers for separate divisions, segments, or subsidiaries, and the total number of end customers may contract due to mergers, acquisitions, or other consolidation among existing end customers.

5


Growth Strategy

Key elements of our current growth strategy include:

Expanding our hybrid multicloud platform. We intend to continue investing in the Nutanix Cloud Platform through internal innovation and product development to enable customers to run traditional, modern and AI workloads and manage data and applications across hybrid multicloud environments. Our product priorities include our core hybrid cloud infrastructure, enterprise AI, Kubernetes and modern applications, database services, expanded infrastructure choice (including expanded server support and support for qualified external storage), and continued investments in our portfolio to support the broader partner ecosystem. We may also pursue strategic partnerships, technology investments and selective acquisitions where they can accelerate product development or expand platform capabilities.
Landing new end customers and expanding our addressable opportunities. We intend to continue to grow our customer footprint through targeted investments in sales and marketing and our channel, OEM, cloud and ecosystem partnerships. We intend to continue to grow our customer footprint through targeted investments in sales and marketing, our network of channel partners, and strengthening our OEM partnerships. We believe broader support for server and storage infrastructure, together with our cloud-native, Kubernetes and enterprise AI capabilities, increases the range of customer environments, workloads and modernization initiatives that our platform can address.
Expanding within existing end customers through platform selling. Our end customers typically deploy our technology initially for a specific workload. Our sales teams and channel partners then target follow-on opportunities to drive additional purchases by expanding capacity for the existing workload, targeting new workloads, upselling higher product tiers, and cross-selling new products. We believe this land-and-expand strategy enables us to expand our footprint within our existing customer base. We also believe that our platform's recent expansion to support external storage and strengthened Kubernetes capabilities drive opportunities to expand with existing end customers.
Driving renewals and retention in existing end customers. In addition to our land-and-expand strategy, as part of our subscription-based business model, we intend to continue to focus on adoption and renewals among our existing customer base. Our focus on adoption drives customer value and stickiness. Our renewals are associated with lower sales costs as compared to landing new customers or expanding into our existing customer base, and help us drive profitable growth.
Leveraging our partner ecosystem. We intend to continue deepening relationships with channel, OEM, technology, cloud, silicon, service provider, and neocloud partners and expand our partner ecosystem globally to broaden the availability and capabilities of the Nutanix Cloud Platform. We intend to continue to deepen relationships with existing channel and OEM partners and expand our partner ecosystem globally, while also supporting deployment of our software on qualified hardware and hosted services. These relationships can expand our routes to market, increase customer consumption options through cloud, managed service and AI infrastructure offerings, broaden infrastructure choices available to customers, and expand the range of services and solutions built on or integrated with our platform.A number of companies, both within and outside of the enterprise and cloud computing infrastructure industry, hold a large number of patents covering aspects of storage, servers, networking, desktop, security, virtualization, containerization, database management, cloud services products, and other technologies relevant to our products.
Driving profitable growth. We intend to continue to invest in our growth, while balancing such growth against our operating expenses. By maintaining this balance, we believe we can sustain profitable growth. Key drivers of profitable growth include landing new customers, a growing base of renewals, expansions with existing customers, leveraging our partner and alliance ecosystem, and a continued focus on improving operational efficiencies across sales, marketing, and research and development.

6


Sales and Marketing

Sales. We primarily engage with our end customers through our global sales force who directly interact with key IT decision makers while also providing sales development, opportunity qualification and support to our channel partners. We have established relationships with our channel partners, who represent many of the key resellers and distributors of data center infrastructure software and systems in each of the geographic regions where we operate. We also engage our end customers through our OEM partners, which license our software and package it with their hardware and sell through their direct sales forces and channel partners. We expect to continue leveraging our relationships with our channel and OEM partners, deepening relationships with our cloud and ecosystem partners, and expanding our strategic engagements with service providers and neoclouds, to reach our end customers. We expect to continue leveraging our relationships with our channel and OEM partners, and deepening relationships with our cloud and ecosystem partners, to reach our end customers.

Marketing. Our marketing team enables our global sales force and sales via our partner ecosystem. Our marketing focuses on educating our customers, prospects, partners, media and analysts, and influencers about the benefits and business outcomes our cloud software platform and solutions can deliver. The breadth of our product portfolio allows us to engage multiple buyer and user personas across the organization, including senior executives, IT professionals, and developers. Over the past year, we have focused on driving market awareness of our virtualization, cloud-native, and enterprise AI-ready capabilities amid ongoing industry disruption. In addition, we continue to drive market awareness of our evolution from a pioneer in HCI to a provider of a unified platform that helps enterprises manage the growing complexity of virtualized, containerized and enterprise AI workloads across hybrid multicloud environments. We seek to create and capture buyer demand through a variety of outbound and inbound marketing programs that include email, digital marketing, corporate and third-party events that generate customer and prospect awareness - including our annual user event, .NEXT, in-person and virtual demand generation activities, social media outreach, media and analyst relations activities, learning certifications, community programs, platform test drives, thought leadership, and our website. Our robust community empowers customers and partners to share and discuss best practices for leveraging our solutions as well as network with peers. We foster strategic marketing partnerships with our ecosystem of technology, channel, OEM, system integrator, and service provider partners, as well as emerging neoclouds, to expand market reach, increase brand awareness, and drive business growth. We foster strategic marketing partnerships with our ecosystem of technology, channel, OEM, system integrator, and service provider partners to expand market reach, increase brand awareness, and drive business growth. Through our unified Elevate Partner Program, we offer qualified partners access to market development funds, co-branded marketing campaigns, joint demand programs, and comprehensive learning paths.

Research and Development

Our research and development efforts are focused primarily on enhancing our existing technologies, developing new technologies in current and adjacent markets, and supporting existing end customer deployments. Our research and development teams include distributed systems software engineers, platform engineers, systems engineers, user interface engineers and user experience designers. A large portion of our research and development team is based in San Jose, California and India. We also maintain research and development centers in North Carolina, Washington, Serbia, Canada, Germany, Mexico, and the United Kingdom. We also maintain research and development centers in North Carolina, Serbia, Washington, Germany, Mexico, and the United Kingdom. We plan to dedicate significant resources to our continued research and development efforts and intend to continue to invest in our global research and development teams to support enhancements to our solutions, improve integration with ecosystem partners, and expand the range of technologies and features available through our platform. We believe that these investments will support our long-term growth strategy, although they may result in increased expenses and adversely affect our profitability in the near term.

7


Manufacturing

We do not manufacture any hardware. The Nutanix-branded NX series hardware platforms are manufactured by Super Micro Computer, Inc. ("Supermicro"). Supermicro provides the server chassis, assembles and tests the Nutanix-branded NX series hardware platforms and it procures the components used in the NX series hardware platforms directly from third-party suppliers in accordance with our design specifications. Our agreement with Supermicro automatically renews annually in May for successive one-year periods thereafter, with the option to terminate upon each annual renewal. Distributors handle fulfillment and shipment to end customers on demand, but do not hold hardware or component inventory. Distributors handle fulfillment and shipment for certain end customers, but do not hold inventory.

Competition

We operate in the intensely competitive cloud infrastructure, platform services and enterprise AI markets and compete with a broad range of companies that sell software and hardware to build and operate private clouds, integrated systems, standalone storage and servers, and platforms supporting modern and agentic AI workloads, as well as cloud services providers and managed service providers.We operate in the intensely competitive cloud infrastructure and platform services markets and compete with a broad range of companies that sell software and hardware to build and operate private clouds, integrated systems and standalone storage and servers, as well as cloud services providers and managed service providers. These markets are characterized by constant change, rapid innovation, and evolving licensing and consumption models. We face competition from a broad range of providers, including, among others:

software providers that offer virtualization, containerization, agentic AI, virtual networking and security, software defined storage, infrastructure and management and control plane products to build and operate enterprise and hybrid clouds, such as VMware by Broadcom, Microsoft, and Red Hat;
providers of public cloud infrastructure and SaaS-based offerings, such as AWS, Google Cloud, Oracle Cloud, and Azure; and
traditional IT systems vendors, such as Dell, Everpure, Inc., Fujitsu, HPE, Hitachi Vantara, Lenovo, Inc., NetApp, Inc., and Huawei Technologies Co., Ltd., many of which offer integrated systems that bundle servers, storage and networking solutions, as well as standalone server and storage products.

Competition generally varies by workload and customer segment, and customers often evaluate multiple alternatives simultaneously. Several of our competitors are also our partners, resellers, or OEMs in certain offerings. As the market in which we compete continues to develop, we expect it will continue to attract new companies as well as existing larger vendors. Some of our competitors may also expand their product and service offerings, acquire or invest in competing businesses or emerging technologies (including agentic AI and AI factories), offer differentiated pricing terms, bundle their products with other products and capabilities (including AI, agentic AI, machine learning, generative AI, and agentic AI capabilities), provide closed technology platforms, partner with other companies to develop joint solutions, or otherwise leverage their scale, brand recognition or ecosystem relationships to gain a competitive advantage. Some of our competitors may also expand their product and service offerings, acquire or invest in competing businesses or emerging technologies, offer lower pricing or aggressive discounting, bundle their products with other products and capabilities (including artificial intelligence, machine learning, generative AI, and emerging agentic AI capabilities), provide closed technology platforms, partner with other companies to develop joint solutions, or otherwise leverage their scale, brand recognition or ecosystem relationships to gain a competitive advantage. Furthermore, as we expand our product offerings, we may expand into new markets, and we may encounter additional competitors in such markets. Additionally, as companies increasingly offer competing solutions, they may be less willing to cooperate with us as an OEM or otherwise. We believe the principal competitive factors in our market include:

platform features and capabilities, including AI capabilities and security;
system scalability, performance and resiliency;
the ecosystem of certified applications, services, and solutions for our platform;
management and operations, including provisioning, troubleshooting, analytics, automation, and upgrades;
total cost of ownership over the lifetime of the technology;
customer freedom of choice over, and product interoperability with, third-party applications, infrastructure software, infrastructure systems, and platforms and public clouds;

8


the ability to compete with incumbent vendors whose deeply integrated solutions and long-term commercial arrangements may limit customer flexibility and increase switching costs;
application mobility across disparate silos of enterprise computing, including public and private cloud infrastructure; and
quality of customer experience, including ease-of-use, support and professional services.

We believe that we are positioned favorably against our competitors based on these factors. However, many of our competitors have substantially greater financial, technical and other resources, greater brand recognition, larger sales forces and marketing budgets, a larger existing customer base, broader distribution, and larger and more mature intellectual property portfolios.

Intellectual Property

Our success depends in part upon our ability to protect and use our core technology and intellectual property. We rely on patents, trademarks, copyrights and trade secret laws, confidentiality procedures, and employee nondisclosure and invention assignment agreements to protect our intellectual property rights. As of July 31, 2026, we had 626 U.S. patents that have been issued and 164 non-provisional patent applications pending in the United States. Our issued U.S. patents expire between 2033 and 2046. We also leverage some open source software in most of our products. See Item 1A, "Risk Factors," for further discussion of risks related to protecting our intellectual property.

Facilities

Our corporate headquarters are located in San Jose, California where, under lease agreements that expire through August 2030, we currently lease approximately 230,000 square feet of space. We also maintain offices in North America, Europe, Asia Pacific, the Middle East, Latin America, and Africa. We lease all of our facilities and do not own any real property. We believe that our facilities are adequate to meet our needs for the immediate future and that, should it be needed, we would be able to lease suitable additional space to accommodate our operations.

Government Regulation

Our business activities are subject to various federal, state, local, and foreign laws, rules and regulations. Compliance with these laws, rules and regulations has not had, and is not expected to have, a material effect on our capital expenditures, results of operations or competitive position as compared to prior periods. Nevertheless, compliance with existing or future governmental regulations, including, but not limited to, those pertaining to global trade, acquisitions, AI-related governance, data protection and data privacy, climate, employment and labor, and taxes could have a material impact on our business in subsequent periods. See Item 1A, "Risk Factors," for further discussion of risks related to the potential impact of government regulation on our business.

Employees and Human Capital

We had approximately 8,350 employees worldwide as of July 31, 2026. None of our employees in the United States are represented by a labor organization or are a party to any collective bargaining arrangement. In certain European countries in which we operate, we are subject to, and comply with, local labor law requirements in relation to the establishment of works councils and/or industry-wide collective bargaining agreements. We are often required to consult and seek the consent or advice of these works councils. We believe that our employee relations are strong and we have not experienced any work stoppages to date.

9


We understand the importance of human capital and prioritize building our culture, talent development, and compensation and benefits. Our human capital objectives include attracting, retaining, and rewarding talent, as well as promoting the development and integration of our existing and new employees. Our human capital resources objectives include attracting, retaining, and rewarding talent, as well as promoting the development and integration of our existing and new employees. The principal objectives of our equity and cash incentive plans are to attract, retain and reward personnel through stock-based and cash-based compensation awards, to drive stockholder value and the success of our company by motivating such individuals to align their work to company goals, and to perform to the best of their abilities and to achieve our objectives.

Culture

Our values are the framework that defines our culture and shape how we engage with one another, approach challenges, and work toward solutions:

Hungry – We are relentlessly driven to innovate, improve, and lead.
Humble – We stay grounded, always learning from each other and our customers.
Honest – Transparency, trust, and integrity guide every interaction.
with Heart – We approach every challenge with empathy, compassion, and a commitment to making a positive impact.

Our culture principles also shape the way we work and define how we engage with each other and with our customers. These principles are designed to drive performance, foster innovation, and ensure that we remain focused on delivering value, both to our employees and our stakeholders:

We Own It – We take accountability for our actions, results, and decisions.
We Work as One Team – Collaboration is key. We work together to achieve common goals and celebrate our collective success.
We Obsess About Our Customers' Success – Our customers’ success is our success. Everything we do is aimed at driving value for them.
We Think Long-Term – We prioritize sustainability, future-focused growth, and enduring impact over short-term wins.

Total Rewards

We believe a robust and competitive Total Rewards portfolio is essential to attracting and retaining diverse talent that moves Nutanix forward. Our comprehensive reward programs offer physical, mental/emotional, and financial support to our employees and their families. We regularly review our programs and encourage employee feedback about the rewards they value most. We tailor rewards programs specifically based on local market practice and the competitive landscape. We provide a range of globally-available support programs, such as an Employee Assistance Program, online health engagement, and child development support.

10


Health, Wellness, and Safety

The health and safety of employees and others on our property are a top priority. We also focus on compliance with all health and safety laws applicable to our business. To that end, appropriate requirements are implemented, as needed, in order to comply with public health or safety obligations. We have a global physical security team that is empowered to protect the safety of our employees in the event of emergencies or disasters. In addition, we work with our employees and facilities management at our office locations to ensure that work areas are kept safe and free of hazardous conditions. Employees are required to be conscientious about workplace safety. In compliance with applicable laws, and to promote the concept of a safe workplace, we maintain an Injury and Illness Prevention Program. We also continue to support the well-being and continued development of our employees by offering well-being days, during which all employees may enjoy private time away from work requirements.

Growth and Development

We challenge our employees to constantly learn, continuously improve and evolve -- and to that end we invest in resources to foster a learning culture throughout our company. We empower our employees to drive their own personal and professional growth by equipping them with onboarding and learning programs. Our learning programs include digital learning, speed coaching, customized learning workshops, manager enablement and skills training for current, new and future managers, training on culture, language learning programs, and employee wellness programs. We believe that by empowering our employees as they strive to grow personally and professionally, we will be able to build a flexible and resilient workforce and maintain and nurture a robust pipeline of talent to fuel our future growth and strategy.

Information about Segment and Geographic Areas

The segment and geographic information required herein is contained in Note 13 of Notes to Consolidated Financial Statements included in Part II, Item 8 of this Annual Report on Form 10-K.

Corporate Information

We were incorporated in Delaware in September 2009 as Nutanix, Inc. Our principal executive offices are located at 1740 Technology Drive, Suite 150, San Jose, California 95110, and our telephone number is (408) 400-3125. We have operations throughout North America, Europe, Asia Pacific, the Middle East, Latin America, and Africa. Our website address is www.nutanix.com. Information contained on or accessible through our website is neither a part of this Annual Report on Form 10-K nor incorporated by reference herein, and any references to our website and the inclusion of our website address in this Annual Report on Form 10-K are intended to be inactive textual references only.

11


Available Information

Our website is located at www.nutanix.com and our investor relations website is located at ir.nutanix.com. We file reports with the Securities and Exchange Commission ("SEC"), which maintains an internet site (http://www.sec.gov) that contains reports, proxy and information statements and other information regarding issuers, including us, that file electronically with the SEC. This Annual Report on Form 10-K, our Quarterly Reports on Form 10-Q, our Current Reports on Form 8-K, and amendments to those reports filed or furnished pursuant to Section 13(a) or 15(d) of the Exchange Act, as amended, are made available free of charge on the investor relations portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the SEC. We also provide a link to the section of the SEC’s website at www.sec.gov that has, or will have, all of our public filings, including this Annual Report on Form 10-K and our Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings. We use our investor relations website as well as social media as channels of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. It is possible that the information we post on social media could be deemed to be material information. Therefore, we encourage investors, the media and others interested in our company to review the information we post on social media channels listed on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters and code of business conduct and ethics, is also available on our investor relations website under the heading "Governance Documents." Information contained on or accessible through our websites is neither a part of nor incorporated by reference into this Annual Report on Form 10-K or any other report or document we file with or furnish to the SEC, and any references to our websites and the inclusion of our website addresses in this Annual Report on Form 10-K are intended to be inactive textual references only.

12


Item 1A. Risk Factors

You should carefully consider the risks and uncertainties described below, together with all of the other information contained in this Annual Report on Form 10-K, including our consolidated financial statements and related notes, before making a decision to invest in our securities. The risks and uncertainties described below are not the only ones we face; additional risks and uncertainties that we are unaware of, or that we currently believe are not material, may also become important factors that affect our business. If any of the following risks occur, our business, financial condition, operating results, cash flows, and prospects could be materially harmed. In that event, the price of our securities could decline, and you could lose part or all of your investment. In addition, the global macroeconomic environment remains uncertain, which may adversely impact our business, operating results, cash flows, and prospects.

Summary Risk Factors

Our business and an investment in our securities are subject to a number of risks, including risks that may prevent us from achieving our business objectives or may adversely affect our business, financial condition, results of operations, cash flows, and prospects. These risks are discussed more fully below and include, but are not limited to, risks related to:

Risks Related to Our Business and Industry

our ability to execute our business strategy, including our growth initiatives, go-to-market strategy, investments in new products and technologies, and efforts to expand our market opportunity;
macroeconomic, geopolitical conditions, trade, supply-chain and other external conditions that may affect customer spending, demand for our products and services, and our operating results;
competition, technological change and shifts in customer preferences, including developments relating to cloud computing, AI and virtualization technologies, and our ability to maintain or improve our competitive position and market share;
our ability to capitalize on opportunities arising from changes within the VMware ecosystem following Broadcom’s acquisition of VMware;
our ability to attract, retain and expand customers, maintain renewals and increase customer adoption of our platform, products and services;
our ability to develop, enhance, support and maintain our platform, solutions, products, services, and technology, including interoperability with third-party technologies, the availability of third-party resources and technologies, and the successful execution of our product roadmaps, including expanding our AI-related capabilities;
our dependence on channel, OEM, ecosystem, cloud, manufacturing and other strategic partners, suppliers and service providers; and
our international operations and ability to manage the operational, regulatory, legal, tax and staffing complexities associated with conducting business globally.

Risks Related to Cybersecurity and Intellectual Property

cybersecurity incidents, data breaches, malicious attacks, vulnerabilities, operational disruptions or other compromises affecting us, our products and services, our customers or third parties on which we rely;
evolving privacy, data protection, cybersecurity and AI laws, regulations, contractual obligations and customer requirements; and

13


our ability to obtain, maintain, protect, enforce and defend our intellectual property rights, and claims alleging that our products, services or technologies infringe the intellectual property rights of others.

Risks Related to Employee Matters

our ability to attract, integrate, develop, motivate and retain qualified employees, executives and other key personnel, and maintain an effective and productive workforce, including our sales organization.

Risks Related to Financial, Accounting, Regulatory, Tax, and Other Legal Matters

our ability to maintain an effective system of internal controls;
litigation, regulatory investigations, enforcement actions, and compliance with applicable laws and regulations, including those relating to anti-corruption, competition, government contracting, trade controls and sanctions; and
changes in tax laws, tax regulations and tax interpretations, including international tax developments, and our ability to manage related tax risks.

Risks Related to Our Convertible Senior Notes and Revolving Credit Facility

our ability to service, refinance, repurchase or repay our indebtedness, including our outstanding convertible notes and any borrowings under our revolving credit facility;
the potential liquidity, accounting, dilution and other impacts arising from conversion, repurchase or settlement of our convertible notes; and
restrictions and obligations contained in our revolving credit facility and other indebtedness.

Risks Related to Ownership of our Securities

volatility in the market price and trading volume of our securities, including due to changes in our operating performance, our ability to meet our publicly announced guidance and other investor expectations, analyst coverage and broader market conditions;
dilution resulting from equity compensation, future equity issuances, sales of our securities, share-settled obligations and conversion of our outstanding convertible notes;
provisions of our organizational documents or under Delaware law that may limit stockholder influence, delay changes in control or restrict stockholders' choice of forum; and
our share repurchase program and our current intention not to pay dividends.

General Risks

natural disasters, extreme weather events, pandemics, geopolitical conflicts and other events outside of our control; and
acquisitions, investments, divestitures and other strategic transactions.

14


Risks Related to Our Business and Industry

Adverse or uncertain macroeconomic or geopolitical conditions or reduced IT spending by our end customers may adversely impact our business, revenues and profitability.

Our business, operations and performance are dependent in part on worldwide market, economic and financial conditions and events that may be outside of our control, such as global, regional, and local economic developments, fiscal, monetary and tax policies, high inflation, elevated interest rates, recessionary pressures, political and social unrest, geopolitical tensions, changes in domestic and international governmental policies and priorities, terrorist attacks, hostilities or the perception that hostilities may be imminent, military conflict, war, including the ongoing military conflict in Ukraine and related sanctions, continuing conflicts in the Middle East, including the conflict involving Iran, malicious human acts, climate change, natural disasters (including extreme weather), pandemics or other major public health concerns, and other similar events.Our business, operations and performance are dependent in part on worldwide market, economic and financial conditions and events that may be outside of our control, such as global, regional, and local economic developments, fiscal, monetary and tax policies, high inflation, elevated interest rates, recessionary pressures, political and social unrest, geopolitical tensions, the evolving policy landscape following the 2024 US elections and related shifts in domestic and international policy, terrorist attacks, hostilities or the perception that hostilities may be imminent, military conflict, war, including the ongoing military conflict in Ukraine and related sanctions, the continuing conflict in the Middle East, malicious human acts, climate change, natural disasters (including extreme weather), pandemics or other major public health concerns, and other similar events. These conditions and events may adversely affect demand for enterprise computing infrastructure solutions and reduce the economic health and IT spending budgets of our current and prospective end customers. The global macroeconomic environment has been, and may continue to be, inconsistent, challenging and unpredictable due to international trade disputes or tensions, the imposition or expansion of tariffs (including those imposed by the U.S. government targeting imports from numerous countries, which may increase the cost of IT products and services and thereby reduce available IT budgets or shift spending priorities away from our solutions), restrictions on sales and technology transfers, elevated interest and inflation rates, uncertainties related to changes in public policies such as domestic and international regulations and fiscal and monetary stimulus measures, and taxes, potential changes to international trade agreements, actual or potential government shutdowns, elections and any related political instability, geopolitical turmoil and civil unrest, instability in the global credit markets, and other disruptions to global and regional economies and markets.

These macroeconomic challenges and uncertainties have, and may continue to, put pressure on global economic conditions and overall IT spending. 14 Table of Contents These macroeconomic challenges and uncertainties have, and may continue to, put pressure on global economic conditions and overall IT spending. As a result, our current and prospective end customers may reprioritize spending, delay or cancel purchasing decisions, extend sales cycles, or seek lower pricing for our solutions. These factors may make it difficult for us to forecast sales and operating results, plan future investments, and could materially and adversely affect our business, operating results and financial condition.

The enterprise IT market is rapidly changing and expanding, and we expect competition to continue to intensify in the future from both established competitors and new market entrants.

We operate in the intensely competitive cloud infrastructure, platform services and enterprise AI markets and compete with a broad range of companies that sell software and hardware to build and operate private clouds, integrated systems, standalone storage and servers, and platforms supporting modern and agentic AI workloads, as well as cloud services providers and managed service providers.We operate in the intensely competitive cloud infrastructure and platform services markets and compete with a broad range of companies that sell software and hardware to build and operate private clouds, integrated systems and standalone storage and servers, as well as cloud services providers and managed service providers. These markets are characterized by constant change, rapid innovation, and evolving licensing and consumption models. Competition generally varies by workload and customer segment, and customers often evaluate multiple alternatives simultaneously.Competition generally varies by workload and customer segment, and customers often evaluate multiple alternatives simultaneously. Several of our competitors are also our partners, resellers, or OEMs in certain offerings. As the market in which we compete continues to develop, we expect it will continue to attract new companies as well as existing larger vendors. Some of our competitors may also expand their product and service offerings, acquire or invest in competing businesses or emerging technologies (including agentic AI and AI factories), offer lower pricing or aggressive discounting, bundle their products with other products and capabilities (including AI, machine learning, generative AI, and agentic AI capabilities), provide closed technology platforms, partner with other companies to develop joint solutions, or otherwise leverage their scale, brand recognition or ecosystem relationships to gain a competitive advantage. Some of our competitors may also expand their product and service offerings, acquire or invest in competing businesses or emerging technologies, offer lower pricing or aggressive discounting, bundle their products with other products and capabilities (including artificial intelligence, machine learning, generative AI, and emerging agentic AI capabilities), provide closed technology platforms, partner with other companies to develop joint solutions, or otherwise leverage their scale, brand recognition or ecosystem relationships to gain a competitive advantage. Furthermore, as we expand our product offerings, we may expand into new markets, and we may encounter additional competitors in such markets. Additionally, as companies increasingly offer competing solutions, they may be less willing to cooperate with us as an OEM or otherwise.

15


Many of our existing competitors have, and some of our potential competitors may have, competitive advantages over us, such as longer operating histories, significantly greater financial, technical, marketing, or other resources, stronger brand awareness and name recognition, larger intellectual property portfolios, and broader global presence and distribution networks. They may be able to devote greater resources to the promotion and sale of products and services than we can, and they may offer heavy discounts, forcing us to compete aggressively on pricing. Moreover, our current or potential competitors may be acquired by third parties with greater available resources and the ability to initiate or withstand substantial price competition, such as the acquisition of VMware by Broadcom in November 2023. Furthermore, some of our competitors have access to larger customer bases and supply a wide variety of products to, and have well-established relationships with, our current and prospective end customers. Some of these competitors have in the past and may in the future take advantage of their existing relationships with end customers, distributors or resellers to provide incentives to such current or prospective end customers that make their products more economically attractive or to interfere with our ability to offer our solutions to our end customers. Our competitors may also be able to offer products or functionality similar to ours at a more attractive price, such as by integrating or bundling their solutions with their other product offerings or those of technology partners or establishing cooperative relationships with other competitors, technology partners or other third parties. Some potential end customers have preferred, and in the future may continue to prefer, to purchase from their existing suppliers rather than a new supplier, especially given the significant investments that they have historically made in their legacy infrastructures. Some of our competitors may also have stronger or broader relationships with technology partners than we do, which could make their products more attractive than ours. We have also ventured into a number of markets that are adjacent to our core HCI market, both through the expansion of HCI in hybrid multicloud environments as well as through our emerging products, and some of our competitors in these adjacent markets have more experience with those markets and more resources targeted at penetration of those markets than we do. As a result, we cannot assure you that our solutions will compete favorably, and any failure to do so could adversely affect our business, operating results and prospects.

In addition, in recent years, an increasing number of customers have been allocating their IT spending toward AI, machine learning, and agentic AI capabilities.In addition, in recent years, an increasing number of customers have been allocating their IT spending toward artificial intelligence, machine learning, and generative AI capabilities. The IT infrastructure market for AI, machine learning, and agentic AI workloads is also expected to be an intensely competitive and rapidly evolving market. The IT infrastructure market for artificial intelligence, machine learning, and generative AI workloads is also expected to be an intensely competitive and rapidly evolving market.

If we fail to anticipate and respond to rapidly evolving technologies, customer requirements and spending priorities, including developments in public cloud, cloud-native and AI technologies, demand for our solutions and our competitive position could be adversely affected.

The markets in which we compete are rapidly evolving. Our performance depends in part on how customers allocate spending among traditional servers, storage and virtualization products; private and hybrid cloud infrastructure; public cloud services; cloud-native technologies; and AI infrastructure and services. Customer demand and adoption rates in these markets are difficult to predict and may differ from our expectations. We must continually develop, commercialize and support new and enhanced solutions that address changing customer requirements for performance, scalability, security, interoperability, application mobility, reliability and cost. Our investments in new markets and technologies, including AI-related products and services, may not produce differentiated offerings, achieve broad market acceptance or generate anticipated returns. Delays in introducing announced solutions, or a failure to anticipate technological changes or evolving industry standards, could harm our reputation, reduce demand and impair our competitive position. If customers in these markets focus their new spending on, or shift their existing spending to, public cloud solutions or other solutions that do not interoperate with our solutions more quickly or more extensively than expected, our solutions may not compete as effectively, if at all. Public cloud providers may become more competitive as a result of lower prices, improved interoperability, performance, security or application compatibility, or increased customer demand for AI capabilities available through public cloud services. These developments could reduce demand for our solutions.

16


We have estimated the size of our total addressable and serviceable available markets based on internally generated data and assumptions, as well as data published by third parties, which we have not independently verified. While we believe these estimates are reasonable, such information is inherently imprecise and subject to a high degree of uncertainty. If our third-party or internally generated data prove to be inaccurate or we make errors in our assumptions based on that data, our actual market may be more limited than our estimates. In addition, these inaccuracies or errors may cause us to misallocate capital and other critical business resources, which could harm our business. Even if our total addressable market meets our size estimates and experiences growth, we may not continue to grow our share of the market.

We may not be able to capitalize on opportunities resulting from Broadcom’s changes to VMware's products, pricing, licensing, business practices and broader ecosystem.We may not be able to capitalize on opportunities arising from Broadcom’s acquisition of VMware and related changes to its product portfolio and business model.

We believe that our opportunity to increase market share has grown since VMware (now known as VMware by Broadcom), one of our main competitors, was acquired by Broadcom in November 2023. Since the acquisition, Broadcom has made changes to VMware’s product portfolio, pricing, partner programs, support models, certification requirements and other aspects of the VMware ecosystem, which have led many VMware customers to evaluate, adopt or consider alternatives to VMware's virtualization and cloud infrastructure solutions.We believe that our opportunity to increase market share has grown since VMware (now known as VMware by Broadcom), one of our main competitors, was acquired by Broadcom in November 2023. Since the acquisition, Broadcom has made changes to VMware by Broadcom’s product portfolio, pricing, and partner programs, which we believe have led many VMware by Broadcom customers to explore alternatives to its virtualization and cloud infrastructure solutions. However, a variety of factors could adversely affect our ability to convert these opportunities and the timing and extent to which we may realize benefits from them. However, a variety of factors could adversely affect the timing and our ability to convert these opportunities. For example, some prospective customers may remain subject to multi-year contractual commitments, defer migration until their next hardware or software refresh cycle, or delay migration initiatives due to budgetary, operational or resource constraints, including the availability, cost and procurement lead times of server hardware and other infrastructure required to support a migration. Because customers’ contract renewal, infrastructure refresh, procurement and migration timelines vary, these opportunities may arise in multiple waves over an extended period and may not result in customer commitments or revenue within the periods we anticipate. In addition, customers evaluating alternative platforms may determine that the anticipated benefits of migration do not justify the associated costs, disruption, resource requirements or implementation risks and may elect to continue operating VMware environments rather than migrate to our platform. Customers may also migrate only a portion of their workloads to our platform, retain existing infrastructure, deploy workloads in public clouds or select other solutions, which could limit our opportunity even where we are selected as a vendor. Our ability to capitalize on these opportunities may also be limited by lengthy enterprise sales and evaluation cycles, the need to support customers’ existing infrastructure investments (including storage platforms and related technologies), hardware availability, the availability of qualified personnel and partner resources to plan and implement migrations, and customers’ prioritization of other technology initiatives. In addition, Broadcom has implemented, and may continue to implement, changes to VMware products, pricing, licensing, support models, technical requirements, certification programs, partner programs, migration tools, interfaces, interoperability resources, commercial terms or other aspects of the VMware ecosystem that may increase migration complexity and costs, delay customer migration projects, influence customer platform decisions, or otherwise reduce our ability to capitalize on these opportunities. Broadcom may continue to compete aggressively for these customers, and we may not be able to compete effectively for these opportunities across customer segments or geographies. In addition, Broadcom may respond aggressively to our pursuit of these opportunities, and we may not be able to compete effectively across customer segments or geographies. If we are unable to capitalize on these opportunities in a timely or cost-effective manner, or if the timing or magnitude of these opportunities differs from our expectations, our business and operating results could be materially and adversely affected. If we are unable to capitalize on these opportunities in a timely or cost-effective manner, our business and operating results could be materially and adversely affected.

17


Our focus on larger enterprise customers and transactions may result in longer and less predictable sales cycles, greater costs and pricing pressure, and increased variability in our operating results.

Over time, our sales pipeline has evolved to include a higher mix of larger deal opportunities. Sales to these end customers involve risks that may not be present, or that are present to a lesser extent, with sales to smaller end customers. Large enterprise transactions generally involve longer and less predictable sales cycles, greater competition, increased customer negotiating leverage, more demanding contractual, implementation, support and acceptance requirements, greater payment flexibility, and increased variability in transaction timing, structure and outcomes. These factors may increase our costs of pursuing and supporting such opportunities and may delay revenue recognition or cash collections.

Large organizations often undertake a significant evaluation process, and customers may evaluate multiple vendors and consumption models simultaneously.Large organizations often undertake a significant evaluation process that results in a lengthy sales cycle. Although we have a channel sales model, our sales representatives typically engage in direct interaction with our prospective end customers as well as our distributors and resellers. We may provide evaluation products and spend substantial time, effort and money without assurance of a sale. Such purchases may be delayed by budget constraints, multiple approvals, unanticipated administrative, processing and other delays, or customers' infrastructure refresh cycles. In addition, large customers often require broader functionality and services, extensive contractual commitments and pricing concessions, which can further extend sales cycles and make it difficult to predict whether and when a transaction will close or when related revenue or cash flows will be recognized. If such a challenge or disagreement were to occur, and our position was not sustained, we could be required to pay additional taxes, interest and penalties, which could result in one-time tax charges, higher effective tax rates, reduced cash flows and lower overall profitability of our operations. If we fail to realize an expected sale from a large end customer in a particular quarter or at all, our business and operating results could be adversely affected.

Our sales of offerings that support external storage may negatively impact sales of our core HCI offering and alter customer purchasing behavior, which could negatively impact our results of operations.

As part of our strategy to expand our addressable market and meet the needs of customers invested in legacy three-tier IT infrastructure, we have expanded our offerings to include support for qualified third-party external storage platforms.As part of our strategy to expand our addressable market and meet the needs of customers invested in legacy three-tier IT infrastructure, we recently expanded our offerings to include support for qualified third-party external storage platforms. While we believe this flexibility may facilitate customer adoption of our platform in brownfield environments and enable longer-term expansion opportunities, it may change the mix, timing or economics of our sales, including by reducing sales of our core HCI offering. While we believe this flexibility may facilitate customer adoption of our platform in brownfield environments and enable longer-term expansion opportunities, it may also negatively impact sales of our core HCI offering. Supporting external storage may increase the complexity of our offerings and require additional resources for integration, testing, and customer success. In addition, support for external storage may increase the complexity of our offerings and require additional resources for integration, testing, and customer success. It also increases our reliance on third-party technologies, over which we have limited control. If these third-party platforms experience performance issues, customer dissatisfaction, or changes in strategic direction that affect interoperability with our solutions, our reputation and customer relationships could be negatively impacted. If customer adoption or the resulting sales mix differs from our expectations, our investment in this capability may not yield the anticipated return, which could adversely affect our operating results.

If we do not effectively manage our operations, resources and investments as our business and product portfolio evolve, we may not achieve our strategic objectives.

We have expanded our overall business and operations significantly in prior periods. As our product portfolio, markets and operations evolve, we must appropriately allocate resources, manage organizational and operational changes, and align our personnel, systems and processes with our strategic priorities. The failure to manage these changes could significantly delay the achievement of our strategic objectives. We must continue to improve our IT and financial infrastructure, management systems and product management and sales processes. We must also continue to improve and expand our IT and financial infrastructure, management systems and product management and sales processes. We may make investments or otherwise incur costs that may not result in anticipated benefits within the expected timeframe or at all.

If we are unable to manage our operations and resources effectively, we may not be able to take advantage of market opportunities, satisfy end customers’ requirements, maintain product quality, execute on our business plan, or respond to competitive pressures, any of which could adversely affect our business, operating results, financial condition, and prospects.

18


If other IT vendors do not cooperate with us to ensure that our solutions interoperate with their products, including by providing us with early access to their new products or information about their new products, our product development efforts may be delayed or impaired, our solutions could become less attractive to end customers and our business, operating results and prospects may be adversely affected.

Our solutions must interoperate with our end customers’ existing hardware and software infrastructure, specifically their networks, servers, software, and operating systems, as well as the applications that they run on this infrastructure, which may be manufactured and provided by a wide variety of vendors and OEMs. As a result, our solutions must interoperate with our end customers’ existing hardware and software infrastructure, specifically their networks, servers, software, and operating systems, as well as the applications that they run on this infrastructure, which may be manufactured and provided by a wide variety of vendors and OEMs. In addition to ensuring that our solutions interoperate with these hardware and software products initially, we must regularly update our software to ensure that our solutions continue to interoperate with new or updated versions of these hardware and software products. Current or future providers of hardware, software applications, hypervisors, or data management tools could make changes that would diminish the ability of our solutions to interoperate with them. Such providers may also modify, limit, discontinue, or impose additional restrictions on access to software tools, interfaces, certifications, technical documentation, support arrangements, or other resources that are important to enabling interoperability with their products. Significant additional time and effort may be necessary to ensure the continued compatibility of our solutions, which might not be possible at all. Even if our solutions are compatible with those of other providers, if they do not certify or support our solutions for their systems or cooperate with us to coordinate troubleshooting and hand off of support cases, end customers may be reluctant to buy our solutions, which could decrease demand for our solutions and harm our ability to achieve a return on the investments and resources that we have dedicated to ensuring compatibility. Developing solutions that interoperate properly requires substantial partnering, capital investment and employee resources, as well as the cooperation of the vendors or developers of the software applications and hypervisors both with respect to product development, certification, and support processes. Vendors may not provide us with early or any access to their technology and products, assist us in these development efforts, certify our solutions, share with or sell to us any application programming interfaces ("APIs"), formats, or protocols we may need, or cooperate with us to support end customers. Vendors may also impose commercial, technical, contractual, certification, licensing, support, or other requirements that increase the complexity, cost, or time required for us to maintain compatibility with their products or support mutual customers. Such requirements may also adversely affect customer migration initiatives, increase switching costs, delay platform-transition decisions or otherwise reduce the attractiveness or practicality of alternative solutions. If they do not provide us with the necessary access, assistance or proprietary technology on a timely basis or at all, we may experience product development delays or be unable to ensure the compatibility of our solutions with such new technology or products. Some of these vendors also sell solutions that compete directly or indirectly with our solutions and therefore may not be incentivized to cooperate with us to ensure interoperability, certify our solutions, or support joint customers. To the extent that vendors develop products that compete with ours, they have in the past, and may again in the future, withhold their cooperation, decline to share access, certify our solutions or sell or make available to us their proprietary APIs, protocols or formats, limit access to interoperability tools or resources, or engage in practices to actively limit the functionality, compatibility, certification, or support of our products. To the extent that vendors develop products that compete with ours, they have in the past, and may again in the future, withhold their cooperation, decline to share access, certify our solutions or sell or make available to us their proprietary APIs, protocols or formats or engage in practices to actively limit the functionality, compatibility, certification, or support of our products. If any of the foregoing occurs, our product development efforts may be delayed or impaired, our solutions could become less attractive to end customers resulting in a decline in sales, which could reduce demand for our solutions, impair our competitive position, and adversely affect our business, operating results, and prospects.

19


Our continued investment in and integration of our AI technologies and capabilities exposes us to operational, legal, and security risks, which, if realized, could adversely impact our business.

We have made, and expect to continue making, investments in our AI technologies and capabilities across our business, products, and services, including efforts to position the Nutanix Cloud Platform as a preferred platform for running enterprise AI workloads.We have made, and expect to continue making, investments in our AI capabilities across our business, products, and services, including efforts to position the Nutanix Cloud Platform as a preferred platform for running enterprise AI workloads. AI technologies are complex, rapidly evolving, and subject to significant uncertainty, including with respect to technical performance, reliability, customer adoption, competitive differentiation, and the legal and regulatory frameworks that may apply to their development, deployment, and use. Increasing competition and the availability or emergence of competing infrastructure, virtualization, and containerization solutions, as well as different consumption models, often result in customers evaluating multiple vendors at the same time, which can further lengthen the sales cycle. Our development, integration, offering or use of AI technologies, including with or in new or existing products and services, may result in new or enhanced governmental or regulatory scrutiny, litigation, privacy, data protection, confidentiality, intellectual property or cybersecurity risks, ethical concerns, legal liability, or other complications that could adversely affect our business, reputation, or financial results. As we integrate more agentic AI workflows into our platform, actions taken or suggested by AI-powered agents acting without human oversight could be incorrect, unintended, unauthorized, or harmful, which could expose us to contractual disputes, indemnity obligations, litigation, regulatory investigations, and reputational harm.

The use of generative AI by our workforce in our operations and code development processes poses ownership and security risks with respect to our codebase, given legal uncertainties surrounding AI-generated works and the potential for security flaws in output code, and may lead to errors in our decision-making and solution development. Furthermore, our internal adoption of AI tools to optimize our own business processes may cause unforeseen operational disruptions, fail to deliver anticipated cost efficiencies, or introduce new vulnerabilities into our internal workflows.

The regulatory landscape governing AI technologies is rapidly evolving and increasingly fragmented across the United States, the European Union, and other jurisdictions and we are subject to an evolving and complicated legislative patchwork governing AI. For example, the European Union has enacted the AI Act and a number of U.S. states have enacted or proposed AI-related laws and regulations, including the Colorado AI Act, the California AI Transparency Act, the Utah Artificial Intelligence Policy Act, the Texas Responsible AI Governance Act, and other laws addressing automated decision-making, transparency, disclosure, risk management, and governance. Additional AI-related laws, regulations, standards, and guidance may be adopted at the federal, state, local, and international levels. These frameworks, laws, and regulations could require us to comply with various requirements depending on the purpose, functionality, and risk categorization of AI, the data processed, and our role. These emerging, changing, or conflicting AI-related compliance obligations may result in expending significant resources and additional costs to comply, change our business practices, or provide additional infrastructure, policies, safeguards and operational controls and testing, and personnel to support the ongoing governance and oversight of such AI technologies, including notice, transparency, and AI risk assessment and mitigation obligations. The current U.S. presidential administration has, and may continue to, issue, modify or rescind existing federal orders and/or administrative policies relating to AI technologies in the future. Any such changes at the federal level could require us to expend significant resources to modify our products, services, or operations to ensure compliance with old frameworks or meet new obligations.

The intellectual property ownership and license rights, including copyright, surrounding AI technologies have not been fully addressed by laws or regulations, and our use or adoption of third-party AI technologies into our business operations, products and services may result in exposure to claims of copyright infringement or other intellectual property misappropriation, as well as potential liability to customers. 23 Table of Contents The intellectual property ownership and license rights, including copyright, surrounding AI technologies have not been fully addressed by laws or regulations, and our use or adoption of third-party AI technologies into our business operations, products and services may result in exposure to claims of copyright infringement or other intellectual property misappropriation, as well as potential liability to customers.

20


AI technologies may use algorithms, datasets, or training methodologies that may be flawed or contain deficiencies that may be difficult to detect during testing. AI technologies, including generative AI, may produce output or create content that appears correct but is factually inaccurate, flawed, biased, misleading, harmful, incomplete, or otherwise hallucinatory. Use of such content may be to the detriment of the user, or it may lead to discriminatory or other adverse outcomes, which may expose us to brand or reputational harm, competitive harm, regulatory scrutiny and fines, and/or legal liability. Our integration of third-party AI models introduces compounding uncertainties, as these providers may change model outputs, capabilities, accuracy, and behavior without advance notice, creating novel risks related to product reliability, data integrity, third-party claims, and regulatory compliance that we may not be able to anticipate or promptly mitigate. Further, AI technologies may repurpose data beyond its original intent or without the consent of an individual where required, or involve unintended cross-border transfers, challenging privacy principles and potentially resulting in privacy-related claims, liability, or regulatory scrutiny. As we expand our use of AI technologies, we may be required to update our agreements, policies, disclosures, governance programs, controls, and risk management processes to address these risks and meet evolving customer, legal, regulatory, and market expectations. As we expand our use of AI technologies, we may be required to update our agreements, policies, and controls to address these risks and meet evolving customer and regulatory expectations. We may not be able to do so in a timely, effective, or cost-efficient manner. If any of the foregoing risks materialize, or if our AI-related practices are perceived as insufficient, unlawful, unreliable, insecure, or inconsistent with customer, regulatory, or public expectations, our business, operations, financial condition, reputation, and prospects could be adversely affected.

Because our business depends on manufacturers of hardware and physical components, including our OEM partners, to timely and cost-effectively produce and ship the hardware platforms on which our software runs, we are susceptible to supply chain disruptions, delays, quality events, and pricing fluctuations, which have adversely affected, and could further adversely affect, our business. 28 Table of Contents Because our business depends on manufacturers of hardware, including our OEM partners, to timely and cost-effectively produce and ship the hardware platforms on which our software runs, we are susceptible to supply chain disruptions, delays, quality events, and pricing fluctuations, which have adversely affected, and could further adversely affect, our business.

Our business depends on manufacturers (including Supermicro and our OEM partners) to assemble and/or produce the hardware platforms on which our software runs (including both the Nutanix-branded NX series hardware platforms and the various third-party hardware platforms that are included on our server hardware compatibility and validation list) as well as various products that are beyond our control or the control of such manufacturers. This reliance exposes us to direct and indirect risks beyond our control, including reduced control over quality assurance, product costs, product availability, supply chain disruptions and delays, and potential reputational harm and brand damage. We may not be able to discover, manage, and/or remediate such risks in a timely manner or at all.

Key components of the server hardware on which our software is validated to run, including those sourced from limited or single-source suppliers, have in the past been, and may in the future be, affected by supply shortages or delivery delays. We generally acquire components only as needed and do not enter into long-term supply contracts for these components. Consequently, if we or our suppliers inaccurately forecast demand for our solutions, our suppliers may have inadequate inventory, which could increase the prices we must pay for substitute components. Our reliance on these suppliers exposes us to risks regarding production and component costs, timely delivery, and capacity constraints. Furthermore, qualifying a new component or changing key suppliers can be expensive and time-consuming, and could cause disruptions. In addition, increases in hardware platform prices, whether due to component shortages or other cost pressures, could reduce customer demand for our software if customers delay or scale back purchases of the hardware platforms that are validated to run our solutions. In addition, increases in hardware prices, whether due to component shortages or other cost pressures, could reduce customer demand for our software if customers delay or scale back purchases of certified hardware platforms needed to run our solutions. Customers may also respond to rising hardware costs by reevaluating their overall IT budgets or seeking to reduce total solution costs, which could adversely affect demand for our software and put pressure on pricing and margins. For example, beginning in the second quarter of fiscal 2026, we have faced constraints affecting the availability of certain hardware components at manufacturers. These constraints have resulted in higher hardware pricing in the market and extended hardware lead times, which vary across hardware vendors. Higher hardware pricing, together with extended hardware lead times, have impacted, and may continue to impact, customers' ability to deploy and consume our software, which may affect the timing of revenue recognition and cash flows from period to period and, in certain instances, may result in some customers delaying projects or otherwise seeking greater flexibility with licensing. Our business and results of operations will be significantly affected by our success in leveraging our relationships with our channel and OEM partners and expanding our network of cloud and ecosystem partners.

21


Furthermore, fulfilling orders for the hardware platforms on which our software runs may not be a priority for such manufacturers in guiding their business decisions and operational commitments. If we fail to manage our relationships with such manufacturers effectively, or if such manufacturers experience delays, disruptions or increased manufacturing lead times, component lead-time disruptions, capacity constraints, or quality control problems in their operations or are unable to address our or our end customers’ requirements for or concerns about timely delivery, our ability to sell our solutions to our end customers could be severely impaired due to the lack of availability of validated physical hardware platforms, and our customers' ability, or willingness, to consume our software may be materially impacted or delayed, which could adversely affect our business and operating results, competitive position, brand and reputation, as well as our relationships with affected customers.

In particular, we rely substantially on Supermicro to manufacture, assemble and test, the Nutanix-branded NX series hardware platforms.In particular, we rely substantially on Supermicro to manufacture, as well as assemble and test, the Nutanix-branded NX series hardware platforms. Our agreement with Supermicro does not contain long-term manufacturing commitments or price assurances, and is subject to annual renewal and termination rights. Increases in component costs, without a corresponding increase in the price of our NX series solutions, could require a reduction to the amount that an end customer pays for our software, thereby adversely affecting our revenue. The inability of Supermicro or other OEM manufacturers to produce adequate supplies of hardware platforms could cause a delay in our customers’ ability to consume our software, adversely impacting our order fulfillment, business, operating results and prospects. The inability of Supermicro or other manufacturers to produce adequate supplies of hardware platforms could cause a delay in customers’ ability to consume our software and our order fulfillment, and our business, operating results and prospects, would be adversely affected. If we are required to change the manufacturer for the assembly and testing of our NX-branded hardware platforms, we may lose revenue, incur increased costs and damage our channel partner and end customer relationships. If we are required to change the manufacturer or contract manufacturers for the assembly and testing of our NX-branded hardware platforms, we may lose revenue, incur increased costs and damage our channel partner and end customer relationships. We may also decide to switch or bring on additional hardware OEM manufacturers for the assembly and testing of our NX-branded hardware platforms in order to better meet our needs. We may also decide to switch or bring on additional contract manufacturers for the assembly and testing of our NX-branded hardware platforms in order to better meet our needs. Switching to or bringing on a new OEM partner and commencing production can be expensive and time-consuming and may cause delays in order fulfillment at our existing OEM partners and contract manufacturer or cause other disruptions. Switching to or bringing on a new OEM partner or contract manufacturer and commencing production can be expensive and time-consuming and may cause delays in order fulfillment at our existing OEM partners and contract manufacturers or cause other disruptions. As of July 31, 2026, we had approximately $163.0 million in the form of guarantees to our contract manufacturer related to certain components. As of July 31, 2025, we had approximately $106.9 million in the form of guarantees to our contract manufacturers related to certain components.

We may not be able to sustain profitability on a GAAP or non-GAAP basis.

Although we generated GAAP net income in fiscal 2025 and 2026 and non-GAAP net income in fiscal 2024, fiscal 2025, and fiscal 2026, we may not be able to sustain profitability in future periods. We intend to continue investing in growth opportunities, including research and development, sales and marketing initiatives, infrastructure and other areas of our business. Balancing growth investments with operating discipline may make it challenging to sustain our current levels of profitability, operating margins, or cash generation over time. These investments may increase our expenses before generating corresponding revenue and may not produce their anticipated benefits. If we fail to grow our revenue, manage our operating expenses effectively, or realize the expected benefits of our investments, we may not be able to sustain profitability on a GAAP or non-GAAP basis. If we are unable to sustain profitability at levels anticipated by analysts or investors, the market price of our securities could decline, potentially significantly. If we are ultimately unable to maintain profitability at the level anticipated by analysts and our stockholders, the price of our securities may decline, potentially significantly.

Our growth depends on our existing end customers renewing or upgrading their subscriptions and support and maintenance agreements and making additional purchases of software licenses and software upgrades, and the failure of our end customers to do so could harm our business and operating results.

Our future success depends on our existing end customers renewing or upgrading their subscription and support and maintenance agreements and making additional purchases of software licenses and software upgrades. If our end customers do not renew or upgrade their subscription and support and maintenance agreements and/or purchase additional software licenses or software upgrades, our revenue may decline, and our operating results may be harmed. In order for us to maintain or improve our operating results, we depend on our existing end customers renewing their subscription agreements as well as their support and maintenance agreements or purchasing additional solutions.

22


End customers may choose not to renew their subscription agreements or support and maintenance agreements, or purchase additional solutions, because of several factors, such as dissatisfaction with our platform, solutions, support, or prices (including relative to competitive offerings), reductions in our end customers’ spending levels or other causes outside of our control. If our existing end customers do not purchase new solutions or renew or upgrade their subscription agreements or support and maintenance agreements, our revenue may grow more slowly than expected or may decline, and our business and operating results may be adversely affected.

We rely primarily on indirect sales channels for the distribution of our solutions, and disruption within these channels or underperformance by our channel partners could adversely affect our business, operating results and cash flows.

We primarily sell our solutions through indirect sales channels, including channel partners, such as distributors, our OEM partners, value added resellers, and system integrators. Our OEM partners may in turn distribute our solutions through their own networks of channel partners with whom we have no direct relationships. We rely, to a significant degree, on our channel partners to select, screen and maintain relationships with their distribution networks and to distribute our solutions in a manner that is consistent with applicable law, regulatory requirements and our quality standards. 24 Table of Contents We rely, to a significant degree, on our channel partners to select, screen and maintain relationships with their distribution networks and to distribute our solutions in a manner that is consistent with applicable law, regulatory requirements and our quality standards. If our channel partners or a partner in their distribution network violates applicable law or regulations, misrepresents the functionality of our solutions, or otherwise engages in conduct that results in regulatory scrutiny or legal action, our reputation and brand could be damaged, and we could be subject to potential liability. Additionally, if we are unable to establish relationships with strong channel partners in key growth regions, our ability to sell our solutions in these regions may be adversely affected. Our agreements with our channel partners are generally non-exclusive, meaning our channel partners may offer end customers the products of several different companies, including products that compete with ours. As a result, our channel partners, including our OEM partners, may not be fully incentivized to prioritize or actively promote our solutions, particularly if they also sell their own products or those of our competitors. In addition, we have limited visibility into and control over the sales efforts and go-to-market strategies of our OEM partners, and their sales performance may not meet our expectations. If our OEM partners or other channel partners do not effectively market and sell our solutions, choose to allocate fewer resources to our solutions, or fail to meet the needs of our end customers, our business, operating results and prospects may be adversely affected. Our channel partners may cease marketing our solutions with limited or no notice and with little or no penalty. The loss of a substantial number of our channel partners, together with our inability to replace them, or the failure to recruit additional channel partners or establish an alternative distribution network could materially and adversely affect our business and operating results. Sales through our top two distributors to our end customers represented 39% of our total revenue for fiscal 2026. In addition, if a channel partner offers its own products or services that are competitive to our solutions, is acquired by a competitor or reorganizes or divests its reseller business units, our revenue derived from that partner may be adversely impacted or eliminated altogether.

Recruiting and retaining qualified channel partners and training them in the use of our technologies requires significant time and resources. If we fail to devote sufficient resources to support and expand our network of channel partners, our business may be adversely affected. Maintaining strong indirect sales channels for our products and effectively leveraging our channel partners and OEMs is important to our strategy, and the failure to effectively manage these relationships may lead to higher costs and reduced revenue. Maintaining strong indirect sales channels for our products and effectively leveraging our channel partners and OEMs is important to our growth strategy, and the failure to effectively manage these relationships may lead to higher costs and reduced revenue. Our reliance on channel partners also may reduce our direct contact with end customers, making it more difficult to forecast demand, understand and respond to customer requirements, support customers and obtain renewals.

23


Substantially all of our sales to government entities have been made indirectly through our channel partners. Government entities may have statutory, contractual or other legal rights to terminate contracts with our channel partners for convenience or due to a default. If a material portion of government contracts becomes subject to renegotiation or termination, any such renegotiation or termination may adversely impact our future operating results. We also sometimes rely on our channel partners to satisfy certain regulatory obligations that we would otherwise have to satisfy if we sold directly to the government entities, and our channel partners may be unable or unwilling to satisfy these obligations in the future. In addition, a channel partner may become restricted in its ability to conduct business with government entities due to its own regulatory or legal issues. If we are unable to transition to another qualified channel partner in a timely manner, our ability to sell to government entities could be negatively impacted. Governments routinely investigate and audit government contractors’ (including subcontractors') administrative processes, and any unfavorable audit could result in the government refusing to continue buying our solutions, our channel partners changing their business models or refusing to continue to sell our solutions under current models, a reduction of revenue or fines, or civil or criminal liability if the audit uncovers improper or illegal activities.

If our indirect distribution channel is disrupted, particularly if we are reliant on a fewer number of channel partners, or if we are required to directly satisfy certain regulatory obligations imposed by government entities as a result of our efforts to expand our sales to government entities, we may be required to devote more time and resources to distribute our solutions directly and support our end customers, which may not be as effective and could lead to higher costs, reduced revenue and growth that is slower than expected.

Our operating results and key financial and performance metrics may fluctuate significantly, which could make our future results difficult to predict and could cause our operating results to fall below expectations.

Our operating results and key financial and performance metrics, including revenue, ARR, and free cash flow, may fluctuate due to a variety of factors, many of which are outside of our control. As a result, comparing our operating results on a period-to-period basis may not be meaningful. If our operating results or any of our key financial and performance metrics in any particular period fall below analyst or investor expectations, the market price of our securities would likely decline, potentially significantly. Our operating results may fluctuate as a result of the timing and magnitude of bookings, license start dates, renewals, contract durations, customer purchasing decisions and the related timing of ARR and revenue recognition, which may not coincide. Demand for our solutions may be affected by customer budgets, purchasing cycles, transaction timing, competitive conditions, pricing pressures, changes in customer preferences and the pace of adoption of new and existing products and services. Our operating results may also be affected by our ability to attract and retain customers, changes in our relationships with channel, OEM, ecosystem and cloud partners, the mix of products and services we sell, the amount and timing of investments, acquisitions, integration activities, stock-based compensation and other expenses, and broader macroeconomic, political, supply-chain, industry and market conditions. Such laws and regulations may require companies to implement new privacy and security policies, conduct transfer and privacy impact assessments, permit individuals to access, correct and delete personal information stored or maintained by such companies, inform individuals of security breaches that affect their personal information, and, among others, obtain individuals’ consent to use personal information for certain purposes. In addition, future accounting pronouncements, changes in accounting policies, and changes in how we define or calculate key performance metrics may affect the comparability of our results between periods.

Any of these factors could negatively affect our operating results in a particular period and cause the price of our securities to decline.

24


Because a significant portion of our revenue is recognized ratably over the term of the contractual service period, downturns or upturns in sales are not immediately reflected in full in our results of operations.

Subscription revenue accounts for the substantial majority of our revenue, comprising 94%, 95%, and 95% of our total revenue for fiscal 2024, 2025, and 2026, respectively.Subscription revenue accounts for the substantial majority of our revenue, comprising 93%, 94%, and 95% of our total revenue for fiscal 2023, 2024, and 2025, respectively. A significant portion of our subscription revenue is revenue from software maintenance subscriptions, support subscriptions and SaaS offerings, which is recognized ratably over the contractual service period. As a result, a significant portion of our revenue that we report for each fiscal quarter represents the recognition of deferred revenue from subscription agreements entered into during previous fiscal quarters. Consequently, any decline in any such subscriptions, whether new subscriptions or renewals, in any given fiscal quarter will not be fully or immediately reflected in our revenue for that quarter. However, any such decline will negatively affect our revenue for future quarters. Our subscription model also makes it more difficult for us to rapidly increase our revenue through additional sales in any period, as a significant portion of our revenue from additional sales must be recognized over the applicable subscription duration.

Our gross and operating margins are impacted by a variety of factors and may be subject to variation from period to period.

Our gross and operating margins may be affected by a variety of factors, including fluctuations in the pricing of our products (including as a result of competitive pricing pressures or increases in component pricing), the degree to which we are successful in selling the value of incremental feature improvements and upgrades, customer renewal rates and the degree to which renewals drive our top-line growth, changes in the mix between direct versus indirect sales, changes in the mix of products sold, and the timing and amount of recognized and deferred revenue, particularly as a result of our subscription-based business model. In addition, operating margin may be affected by changes in our cost structure, including investments in sales and marketing, research and development, and general and administrative functions, as well as the timing of those investments relative to revenue recognition. If we are unable to manage these factors effectively, our gross and operating margins may decline, and fluctuations in these metrics may make it difficult to manage our business and to maintain profitability, which could adversely affect our business and operating results.

Our ability to sell our solutions is dependent in part on ease of use and the quality of our technical support, and any failure to offer high-quality technical support would harm our business, operating results and financial condition.

Once our solutions are deployed, our end customers depend on our support organization to resolve any technical issues relating to our solutions. Furthermore, because of the emerging nature of our solutions, our support organization often provides support for and troubleshoots issues for products of other vendors running on our solutions, even if the issue is unrelated to our solutions. There is no assurance that we can solve issues unrelated to our solutions, or that vendors whose products run on our solutions will not challenge our provision of technical assistance to their products. Our ability to provide effective support is largely dependent on our ability to attract, train and retain personnel who are not only qualified to support our solutions, but also well versed in some of the primary applications and hypervisors that our end customers run on our solutions. Our international operations and expanding product portfolio further increase the complexity of providing timely support. Any failure to maintain high-quality installation and technical support, or a market perception that we do not maintain high-quality support, could harm our reputation and brand, adversely affect our ability to sell our solutions to existing and prospective end customers, and could harm our business, operating results and financial condition. While our support operations focus primarily on our software solutions, certain support offerings include the replacement of hardware parts. We outsource the warehousing and delivery of these parts to third-party logistics providers, and any disruptions or failures by these providers could impact our ability to meet specific support commitments.

25


Our solutions are highly technical and may contain undetected defects, which could cause data unavailability, unauthorized access, disclosure, or loss of customer data, or corruption that might, in turn, result in liability to our end customers and harm to our reputation, brand and business.

Our solutions are highly technical and complex and are often used to store information critical to our end customers’ business operations. Our solutions may contain undetected errors, defects or security vulnerabilities that could result in data unavailability, unauthorized access to or disclosure of, loss, corruption, or other harm to our end customers’ data, including personal or identifying information regarding their employees, customers, and suppliers, as well as their finance and payroll data, and other sensitive business information. Our solutions may contain undetected errors, defects or security vulnerabilities that could result in data unavailability, unauthorized access to, loss, corruption, or other harm to our end customers’ data, including personal or identifying information regarding their employees, customers, and suppliers, as well as their finance and payroll data, and other sensitive business information. As we expand our platform and introduce new cloud-based products that process greater amounts of customer data, the potential impact of any such errors, defects or security vulnerabilities may increase. Some errors or defects in our solutions may only be discovered after they have been installed and used by end customers. In addition, we may make certain commitments to our OEMs regarding the time frames within which we will correct any security vulnerabilities in our software. If hardware or software errors, defects or security vulnerabilities are discovered following commercial release, we may experience lost revenue, delays in developing and deploying corrective measures, increased warranty, support and remediation costs, delays, cancellations or reductions of customer orders, product returns or discounts, loss of customers, OEMs or other channel partners, and damage to our reputation and brand.

In addition, we could face legal claims for breach of contract, product liability, tort, or breach of warranty. While many of our contracts with end customers contain provisions relating to warranty disclaimers and liability limitations, these provisions might not be upheld or might not provide adequate protection if we face such legal claims. Defending such claims could be costly, divert management attention and adversely affect market perceptions of us and our solutions. In addition, our insurance coverage may be inadequate to cover such claims or future coverage may be unavailable on acceptable terms. Any of these events could adversely affect our business, operating results, financial condition and reputation.

Our business depends, in part, on sales to government organizations, and significant changes in the contracting or fiscal policies of such government organizations could have an adverse effect on our business and operating results.

We derive a portion of our revenue from contracts with federal, state, local, and foreign governments, and we believe that the success and growth of our business will continue to depend on our successful procurement of government contracts. Certain government contracts and opportunities require us to maintain facility and personnel security clearances and comply with applicable industrial security requirements relating to the handling, safeguarding and protection of sensitive or classified information. Failure to obtain, maintain, renew or comply with such requirements could limit our ability to compete for, perform, renew or expand certain government contracts and opportunities and could result in increased compliance costs, audits, investigations, contractual remedies, suspension of work, loss of contract opportunities or other adverse consequences. However, demand from government organizations is often difficult to predict, and there can be no assurance that we will be able to maintain or grow our revenue from the public sector. However, demand is often unpredictable from government organizations, and there can be no assurance that we will be able to maintain or grow our revenue from the public sector. Government agencies are subject to budgetary processes and expenditure constraints that could lead to delays or decreased capital expenditures in IT spending, particularly in light of continued uncertainties about government spending levels, such as recent changes to, or failure to appoint new, government leaders.

26


We have also recently experienced longer sales cycles and increased variability in transactions involving federal government agencies, which we believe are due to internal personnel changes and more extensive procurement reviews within these organizations. The budget and approval process for government agencies can be longer than for other end customers, and it may be difficult for us to accurately forecast the impact of these contracts on our future operating results. The budget and approval process for government agencies also experiences a longer sales cycle relative to our other end customers, and it may be difficult for us to accurately forecast the impact of these contracts on our future operating results. If government organizations reduce or shift their capital spending patterns, our business, operating results and prospects may be harmed. Our ability to maintain or increase revenue from government customers may be adversely affected by changes in government funding levels, appropriations, budget priorities, fiscal or contracting policies, government programs, laws and regulations, agency staffing or organizational structures, or procurement practices. Government customers are also subject to evolving requirements relating to software supply chain security, domestic sourcing, cybersecurity, AI and data handling, and compliance with these requirements may require significant resources and increase the cost and complexity of selling to government customers. Selling our solutions to the US government, whether directly or through channel partners, also subjects us to certain regulatory and contractual requirements, including meeting the compliance requirements necessary for maintaining any required security clearances for facilities and employees. In addition, delays associated with procurement reviews, qualifying or maintaining status as a government vendor, or obtaining or maintaining required security clearances and authorizations may impair our ability to compete for or perform government contracts.

Any of these factors could cause government customers to delay, reduce or cancel purchases of our solutions, impair our ability to compete for or perform government contracts, and adversely affect our business, operating results and prospects.

Our international operations expose us to additional risks, and failure to manage those risks could adversely affect our business, operating results and cash flows.

We derive a significant portion of our revenue from end customers and channel partners outside the United States. We derived approximately 45%, 44% and 46% of our total revenue from our international customers based on bill-to location for fiscal 2024, 2025, and 2026, respectively. As of July 31, 2026, approximately 62% of our full-time employees were located outside of the United States. Operating internationally requires significant management attention and exposes us to additional operational, legal, regulatory and financial risks. We are subject to risks associated with having significant worldwide operations, including, but not limited to:

business practices may differ from those in the United States and may require us to include terms other than our standard terms in customer, channel partner, employee, consultant, and other contracts;
political, economic and social instability or uncertainty around the world, including the ongoing military conflict in Ukraine and continued instability in the Middle East, including the conflict involving Iran;
changes in global trade policies, tariffs, sanctions, import and export restrictions, localization requirements and other regulatory requirements that may affect cross-border commerce, supply chains or our ability to sell and support our products internationally;
requirements and costs associated with complying with foreign sustainability, ESG-related reporting and due diligence obligations, including requirements adopted in the European Union;
greater difficulty in enforcing contracts, judgments and arbitration awards in international courts, and in collecting accounts receivable and longer payment and collection periods;
greater risk of a failure of foreign employees, partners, distributors, and resellers to comply with both U.S. and foreign laws, including antitrust regulations, the U.S. Foreign Corrupt Practices Act of 1977, as amended ("FCPA"), the United Kingdom Bribery Act of 2010 ("UK Bribery Act"), U.S. or foreign sanctions regimes and export or import control laws, and any trade regulations ensuring fair trade practices;
heightened risk of unfair or corrupt business practices in certain geographies and of improper or fraudulent sales arrangements that may impact financial results and result in restatements of, or irregularities in, financial statements;

27


requirements to comply with foreign privacy, data protection and information security laws and regulations and the risks and costs of noncompliance, including new and evolving laws governing AI and data privacy, such as the European Union's AI Act;
increased expectations from customers and other stakeholders about our performance relating to environmental, social and governance factors (such as climate-related performance), and requirements to comply with sustainability standards or initiatives, including new sustainability standards and due diligence obligations in the European Union;
reduced or uncertain protection for intellectual property rights in some countries;
impediments to the flow of foreign exchange capital payments and receipts due to exchange controls instituted by certain foreign governments;
difficulties and costs associated with establishing and maintaining international operations, including managing geographically dispersed personnel, attracting and retaining talent, complying with local employment requirements, and coordinating operations across multiple jurisdictions; and
international tax laws, tax audits and changes in tax rules applicable to multinational businesses.

Our success will depend, in large part, on our ability to anticipate and effectively manage these risks. These factors and other factors could harm our ability to maintain international operations and generate international sales and, consequently, materially impact our business, operating results and financial condition. These factors and other factors could harm our ability to gain future international revenue and, consequently, materially impact our business, operating results and financial condition.

Risks Related to Cybersecurity and Intellectual Property

If we are the victim of a cyber attack or other cybersecurity incident and our networks, computer systems or software solutions are breached or unauthorized access to sensitive or proprietary information, including employee or customer data, otherwise occurs, our business operations may be interrupted, our reputation and brand may be damaged, and we may incur significant liabilities.

Cyber attacks designed to gain access to sensitive or proprietary information by breaching mission critical systems of large organizations are constantly evolving, and high-profile electronic security breaches and other cybersecurity incidents leading to the unauthorized release of sensitive or proprietary information, including employee and customer information, have occurred at a number of large companies in recent years. Companies in our industry have reported that they have been subject to such cyber attacks, including attacks potentially from nation-state actors, and we could be subject to similar attempted attacks. More generally, computer malware, viruses, social engineering (predominantly spear phishing attacks), and general hacking have become prevalent in our industry, particularly against cloud services, and we and companies like us can suffer security breaches and other cybersecurity incidents from a variety of causes, whether due to third-party action, software bugs or vulnerabilities or coding errors, physical break-ins, employee error, malfeasance, or otherwise. In addition, retaliatory acts by countries subject to Western sanctions could include cyber attacks that could disrupt the economy or that could also either directly or indirectly impact our operations. We also continue to incorporate AI solutions and features into our platform, which may result in security incidents, jailbreaking, or otherwise increase cybersecurity risks.

Additionally, AI and machine learning may increase the cybersecurity risks we face, including through unauthorized or misuse of public-facing AI features. Threat actors may use generative AI and other AI capabilities to increase the prevalence, frequency, severity, and volume of cyber attacks, including by creating more sophisticated phishing and social engineering attacks (including through the use of impersonation technology), accelerating or automating vulnerability exploitation, and developing more sophisticated malware that can evade conventional detection tools or otherwise overwhelm protection systems faster than we can effectively respond. As AI technologies evolve, we may not be able to recognize, anticipate, prevent, or timely respond to these emerging techniques, which could increase the likelihood and magnitude of harm from a cyber attack or other cybersecurity incident.

28


While we regularly face a wide variety of attempted attacks and other cybersecurity incidents, our preventative and detective security systems and controls have protected us to-date from any such attack or incident having a significant impact on our business. However, there is no assurance that these systems and controls will prevent any future attacks or incidents that may have a significant impact on our business. As we transition to offering more cloud-based solutions, as well as those based on our partnerships with third-party public cloud providers, we and our third-party public cloud providers may increasingly be the target of cyber threats or be exposed to other types of cybersecurity incidents. We also use other third-party platforms and other services, and as a result, we have been exposed to in the past, and may be exposed to in the future, cybersecurity incidents related to such third-party services. Because the techniques used and vulnerabilities exploited to obtain unauthorized access or to sabotage systems change frequently, and generally are not identified until they are launched against a target, we may be unable to anticipate these techniques or vulnerabilities or implement adequate preventative measures.Because the techniques used and vulnerabilities exploited to obtain unauthorized access or to sabotage systems change frequently, and generally are not identified until they are launched against a target, we may be unable to anticipate these techniques or vulnerabilities or implement adequate preventative measures. We may also experience security breaches that may remain undetected for an extended period.

If any unauthorized access to, or security breach of, or other cybersecurity incident affecting, our solutions occurs, such an event could result in the loss of data, loss of intellectual property or trade secrets, loss of business, severe reputational or brand damage adversely affecting end customer or investor confidence, regulatory investigations and orders and other enforcement actions, litigation, indemnity obligations, damages for contract breach, and penalties for violation of cybersecurity, privacy, data protection, AI, and other applicable laws, regulations or contractual obligations. We may also be subject to potentially significant costs for remediation that may include liability for stolen assets or information and repair of system damage that may have been caused or incentives offered to end customers or other business partners in an effort to maintain business relationships after a breach and other liabilities. Additionally, any such event or perceived event could impact our reputation and brand, harm customer confidence, hurt our sales and expansion into existing and new markets, or cause us to lose potential or existing end customers. Any actual, potential or anticipated attack or other cybersecurity incident may cause us to incur increasing costs, including costs to deploy additional personnel and protection technologies, train employees and engage third-party experts and consultants.

Furthermore, a high-profile security breach or incident suffered, or perceived to have been suffered, by an industry peer may entail a general loss of trust in our industry and thereby have a similar adverse impact on our business and financial performance as a direct breach suffered by us. 35 Table of Contents Furthermore, a high-profile security breach or incident suffered, or perceived to have been suffered, by an industry peer may entail a general loss of trust in our industry and thereby have a similar adverse impact on our business and financial performance as a direct breach suffered by us. We could be required to expend significant capital and other resources to alleviate problems caused by such actual or perceived breaches or incidents and to remediate our systems, and comply with legal obligations. We could be required to expend significant capital and other resources to alleviate problems caused by such actual or perceived breaches or incidents and to remediate our systems, we could be exposed to a risk of loss, litigation or regulatory action and possible liability, and our ability to operate our business may be impaired. We could be exposed to a risk of loss, litigation, regulatory actions or fines, or remediation costs associated with such an incident which may include forensic analysis, breach response, notification, and credit monitoring, and possible liability, and our ability to operate our business may be impaired.

In addition, if the security measures of our end customers, partners, vendors, or suppliers are compromised, even without any actual compromise of our own systems or of our solutions used by such end customers, partners, vendors, or suppliers, we may face negative publicity, reputational harm or brand damage if our end customers, partners, vendors, or suppliers or anyone else incorrectly attributes the blame for such incidents to us or our solutions. If end customers believe that our solutions do not provide adequate security for the storage of personal or other sensitive or proprietary information or the transmission of such information over the internet, our business will be harmed. End customers’ concerns about security or privacy may deter them from using our solutions for activities that involve personal or other sensitive information, which may significantly affect our business and operating results.

Moreover, to the extent we acquire or integrate companies, products, services, and technologies, we may be exposed to additional security vulnerabilities, compliance issues or other cybersecurity risks associated with such businesses or technologies. Although we devote resources to identifying and addressing such risks, we may not discover or remediate all issues prior to or following integration, which could adversely affect our business.

29


Third-party claims that we are infringing intellectual property, whether successful or not, could subject us to costly and time-consuming litigation or expensive licenses, and our business could be harmed.

A number of companies, both within and outside of the enterprise and cloud computing infrastructure industry, hold a large number of patents covering aspects of storage, servers, networking, desktop, security, virtualization, containerization, database management, cloud services products, and other technologies relevant to our products. In addition to these patents, participants in these technology and market areas typically also protect their technology through copyrights, as trade secrets and by contractual means. As a result, there is frequent litigation based on allegations of infringement, misappropriation or other violations of intellectual property rights. We have received, and in the future may receive, inquiries from other intellectual property holders and may become subject to allegations and claims, in litigation and outside litigation, that we infringed or are infringing their intellectual property rights, particularly as we expand our presence in the market and face increasing competition. There can be no assurance that we will be successful in defending against these allegations or claims or in reaching a business resolution that is satisfactory to us, which could affect or even preclude our ability to sell our products in the relevant market and subject us to payment of damages and other financial remedies. In addition, parties may claim that the names and branding that we use for our company and our various products and services infringe their trademark rights in certain countries or territories. If such a claim were to prevail, we may have to change the names and branding that we use in the affected countries or territories and we could incur other costs.

We currently have a number of agreements in effect pursuant to which we have agreed to defend, indemnify and hold harmless our end customers, suppliers and channel and other partners from damages and costs which may arise from allegations of infringement, or actual infringement, by our products and services of third-party patents or other intellectual property rights in the United States and/or in other countries. 36 Table of Contents We currently have a number of agreements in effect pursuant to which we have agreed to defend, indemnify and hold harmless our end customers, suppliers and channel and other partners from damages and costs which may arise from allegations of infringement, or actual infringement, by our products and services of third-party patents or other intellectual property rights in the United States and/or in other countries. The scope of these defense and indemnity obligations varies, but may, in some instances, include indemnification for damages and expenses, including attorneys’ fees. A claim that our solutions infringe a third party’s intellectual property rights, even if untrue, could harm our relationships with our end customers and/or channel partners, may deter future end customers from purchasing our solutions and could expose us to costly litigation and settlement expenses. Even if we are not a party to any litigation between a customer and a third party relating to infringement by our products or services, an adverse outcome in any such litigation could make it more difficult for us to defend our solutions against intellectual property infringement claims in any subsequent litigation in which we are a named party. Any of these results could harm our brand and operating results.

Our defense of intellectual property rights claims brought against us or our end customers, suppliers and channel partners, regardless of whether the claims have merit, could be time-consuming, expensive to litigate or settle, divert management resources and attention, and force us to acquire intellectual property rights and licenses, which may involve substantial royalty or other payments. Further, a party making such a claim, if successful, could secure a judgment that requires us to pay substantial damages. An adverse determination also could prevent us from offering or delivering our products and services to our end customers or channel partners and may require that we procure or develop substitute solutions that do not infringe, which could require significant effort and expense. We may have to seek a license for the technology at issue, which may not be available on terms favorable or acceptable to us or at all, and as a result may significantly increase our operating expenses or require us to restrict our business activities in one or more respects. Any of these events could adversely affect our business, operating results, financial condition, and prospects.

30


The success of our business depends in part on our ability to protect and enforce our intellectual property rights.

We rely on a combination of patent, copyright, service mark, trademark, and trade secret laws, as well as confidentiality procedures and contractual restrictions and covenants, to establish and protect our proprietary rights, all of which provide only limited protection. Effective patent, trademark, service mark, copyright, and trade secret protection may not be available in every country in which our solutions are available. We cannot be certain that the steps we have taken will prevent unauthorized use of our technology or the reverse engineering of our technology. Moreover, others may independently develop technologies that are competitive to ours and reduce our sales or market advantages, or infringe our intellectual property. A reduction in our market advantages or an inability to adequately protect and enforce our intellectual property and other proprietary rights could seriously harm our business, operating results, financial condition, and prospects.

We cannot assure you that any patents will be issued with respect to our currently pending patent applications in a manner that gives us adequate defensive protection or competitive advantages, if at all, or that any patents issued to us will not be challenged, invalidated or circumvented. We have filed for patents in the United States and in certain international jurisdictions, but such protections may not be available in all countries in which we operate or in which we seek to enforce our intellectual property rights, or may be difficult to enforce in practice. Our currently issued patents and any patents that may be issued in the future with respect to pending or future patent applications may not provide sufficiently broad protection or they may not prove to be enforceable in actions against alleged infringers.

Protecting against the unauthorized use of our intellectual property, solutions and other proprietary rights is expensive and difficult, particularly internationally. 37 Table of Contents Protecting against the unauthorized use of our intellectual property, solutions and other proprietary rights is expensive and difficult, particularly internationally. Litigation via court proceedings, arbitrations or similar proceedings may be necessary in the future to enforce or defend our intellectual property rights or to determine the validity and scope of the proprietary rights of others. For example, in March 2024, we announced that we filed a lawsuit in U.S. District Court against Tessell, Inc. ("Tessell") alleging that Tessell engaged in willful copyright and patent infringement (including theft of our source code and intellectual property related to our database service offering) and commenced separate arbitration proceedings against Tessell’s founders, and those proceedings remain ongoing. Litigation and arbitration are unpredictable and we may not win a litigation or arbitration even if there is significant evidence supporting our claims and defenses. Further, these proceedings and any other similar proceedings could result in substantial costs and diversion of management resources, either of which could harm our business, operating results and financial condition. Further, many of our current and potential competitors have the ability to dedicate substantially greater resources to defending intellectual property infringement claims and to enforcing their intellectual property rights than we have. Attempts to enforce our rights against third parties could also provoke these third parties to assert their own intellectual property or other rights against us, or result in a holding that invalidates or narrows the scope of our rights, in whole or in part.

A number of our solutions incorporate, use, work with, or are based upon open source software and AI models that we obtained under open source licenses, some of which may restrict or impose certain obligations on how we use or distribute our solutions, subject us to various risks and challenges and could result in increased development expenses, delays or disruptions to the release or distribution of those solutions, an inability to protect our intellectual property rights, and increased competition.A number of our solutions incorporate or are based upon software that we obtained under open source licenses, some of which may restrict or impose certain obligations on how we use or distribute our solutions, subject us to various risks and challenges and could result in increased development expenses, delays or disruptions to the release or distribution of those solutions, an inability to protect our intellectual property rights, and increased competition.

A number of our solutions incorporate, use, work with, or are based upon open source software and AI models, and we may incorporate or base our solutions on them in the future.A number of our solutions incorporate or are based upon open source software, and we may incorporate or base our solutions on open source software in the future. Such open source software and AI models are generally licensed under "permissive" and "copyleft" open source licenses, such as the Apache License 2.0, BSD 2-Clause License, Eclipse Public License 2.0, GNU General Public License, GNU Lesser General Public License, MIT License, the Mozilla Public License 2.0, and other open source licenses. Such open source software is generally licensed under “permissive” and “copyleft” open source licenses, such as the Apache License 2.0, BSD 2-Clause License, Eclipse Public License 2.0, GNU General Public License, GNU Lesser General Public License, MIT License, the Mozilla Public License 2.0, and other open source licenses. The use of open source software and AI models subjects us to a number of risks and challenges, including, but not limited to:

If open source programmers, most of whom we do not employ, do not continue to develop and enhance open source software and AI models, our development expenses could increase and our product release and upgrade schedules could be delayed.

31


Open source software and AI models may be subject to further development or modification by anyone. As a result, others may develop such open source software and AI models to be competitive with our platform and may make such competitive technologies available as open source. As a result, others may develop such software to be competitive with our platform and may make such competitive software available as open source. It is also possible for competitors to develop their own solutions using open source software and AI models, potentially reducing the demand for, and putting price pressure on, our solutions. It is also possible for competitors to develop their own solutions using open source software, potentially reducing the demand for, and putting price pressure on, our solutions.
The licenses under which we license certain open source software and AI models may require that, if we modify and distribute such technology, we are required to make such modifications and potentially related proprietary software of ours, available under the same license terms. In addition, some licenses treat provision of cloud services as triggering the requirement to make proprietary software publicly available. In addition, some open source licenses treat provision of cloud services as triggering the requirement to make proprietary software publicly available. Sometimes, open source licensors may change their license in a way that may require us to change or eliminate the future use of such technology, which may impact functionality and induce costs. Accordingly, we monitor our use of open source software and AI models in an effort to avoid subjecting our proprietary software to such conditions and others we do not intend. Accordingly, we monitor our use of open source software in an effort to avoid subjecting our proprietary software to such conditions and others we do not intend. Although we believe that we have complied with our obligations under the various licenses for open source software and AI models that we use, our processes used to monitor how open source software and AI models are used and what license applies could be subject to error. Although we believe that we have complied with our obligations under the various licenses for open source software that we use, our processes used to monitor how open source software is used and what license applies could be subject to error. In addition, there is little or no legal precedent governing the interpretation of terms in most of these licenses and licensors sometimes change their license terms. Therefore, any improper or unintended usage of open source software and AI models, including a failure to identify changes in license terms, could result in unanticipated obligations regarding our solutions and technologies, which could have an adverse impact on our intellectual property rights and our ability to derive revenue from solutions incorporating or using the open source software and AI models. Therefore, any improper or unintended usage of open source software, including a failure to identify changes in license terms, could result in unanticipated obligations regarding our solutions and technologies, which could have an adverse impact on our intellectual property rights and our ability to derive revenue from solutions incorporating the open source software.
If an author or other third party who distributes such open source software or AI models were to allege that we had not complied with the conditions of one or more of these licenses, we could be required to incur legal expenses defending against such allegations, or engineering expenses in developing a substitute solution.

If we are unable to effectively manage our compliance obligations for open source software and AI model use, our business and operating results could be adversely affected and our development costs may increase.If we are unable to effectively manage our compliance obligations for open source software use, our business and operating results could be adversely affected and our development costs may increase.

Risks Related to Employee Matters

Our business and growth depend on our ability to attract and retain qualified personnel, including our management team and other key personnel, and the inability to attract, hire, integrate, train, retain, or motivate qualified personnel could harm our business and growth.

Our success and growth depend to a significant degree on the skills and continued services of our management team and other key personnel. If we lose the services of any member of management or any key personnel, we may encounter challenges or delays in identifying a suitable or qualified replacement, and we may incur additional expenses to recruit and train a replacement. In recent years, we have experienced changes in our management team resulting from the hiring or departure of executives and other key personnel. While we seek to manage these transitions carefully, these changes may result in a loss of institutional knowledge and may cause disruptions to our business and growth. If we fail to successfully integrate new key personnel into our organization or if key employees are unable to successfully transition into new roles, our business could be adversely affected. In addition, we do not have life insurance policies that cover any of our executive officers or other key employees. The loss of the services of any of our executive officers or key employees, and any failure to have in place and execute an effective succession plan for key executives, could disrupt our business and have a significant negative impact on our operating results, prospects and future growth.

32


In addition, our success and growth also depend substantially on our ability to continue to attract, hire, integrate, train, retain, and adequately motivate qualified and highly skilled personnel, in particular, in sales and engineering. We have invested, and may need to continue to invest, significant amounts of cash and equity to attract and retain employees, and we may never realize returns on these investments. Moreover, ineffective management of any leadership transitions, especially within our sales organization, or the inability of our recently hired sales personnel to effectively ramp to target productivity levels could negatively impact our growth and operating margins. It requires a significant time investment to replace, train, and ramp sales representatives to full productivity. Competition for highly skilled personnel, particularly in sales and engineering, is frequently intense, especially in the San Francisco Bay Area, where we are headquartered and have a substantial need for engineering talent. This competition for highly skilled personnel results in increased costs in the form of cash and stock-based compensation. Furthermore, the industry in which we operate generally experiences periods of high employee attrition.

Although we have entered into employment offer letters with some of our key personnel, these agreements generally do not have a fixed duration or term. Volatility or underperformance in the price of our Class A common stock may also impact our ability to attract and retain key employees. There is no assurance that we will be able to successfully attract or retain qualified personnel. Additionally, potential changes in U.S. immigration and work authorization laws and regulations may make it difficult to renew or obtain visas for any highly skilled personnel that we have hired or are actively recruiting. Our inability to attract and retain the necessary personnel could adversely affect our business, operating results and financial condition.

Moreover, we believe that a key contributor to our success and our ability to retain a highly skilled workforce has been our company culture, which we believe fosters innovation, teamwork, and a passion for our products and customers. As we grow and evolve, we may find it difficult to maintain the beneficial aspects of our company culture globally. These difficulties may be further amplified by our globally distributed workforce, which could have a negative impact on our workplace culture and on the execution of our business plans and operations. An inability to maintain our company culture could adversely affect our ability to attract and retain employees, continue to perform at current levels, or execute on our business strategy.

If we do not effectively structure, compensate, train and motivate our sales force, we may be unable to add new end customers or increase sales to our existing end customers and our business will be adversely affected.If we do not effectively expand, train, motivate, and retain our sales force, we may be unable to add new end customers or increase sales to our existing end customers and our business will be adversely affected.

Although we have a channel sales model, our sales representatives typically engage in direct interaction with our prospective end customers. Therefore, we continue to be substantially dependent on our sales force to obtain new end customers and sell additional solutions to our existing end customers. Our growth depends in large part on our ability to structure our sales force and compensation plans in a way that aligns with our strategic priorities, particularly our focus on driving large orders from major enterprise accounts. We have made, and may continue to make, changes to our sales processes, segmentation, and leadership structures to drive this alignment, but these changes may take longer than anticipated to implement successfully or fail to yield the expected benefits.

There is significant competition for sales personnel with the skills and technical knowledge that we require, especially those experienced in targeting and penetrating large enterprise accounts. Our ability to increase sales will depend, in large part, on our success in structuring, compensating, training and motivating sales personnel. New hires require significant training and may take significant time before they achieve full productivity; we estimate based on past experience that our average sales team members typically do not fully ramp and are not fully productive until around the time of the start of their fourth quarter of employment with us. Our recent hires and planned hires may not become productive as quickly as we expect, and we may be unable to hire or retain sufficient numbers of qualified individuals, particularly individuals who are focused on sales of our solutions to new and existing large enterprises, service providers and government entities, in the markets where we do business or plan to do business. Hiring sales personnel in new countries also requires additional set up, upfront and ongoing costs that we may not recover if the sales personnel fail to achieve full productivity.

33


If our new sales employees, particularly those focused on sales of our solutions to new and existing large enterprises, service providers and government entities, do not become fully productive on the timelines that we have projected, or if we are unable to ensure that our seasoned sales employees remain productive and appropriately incentivized, our sales will not increase at anticipated levels and our ability to achieve long-term projections may be negatively impacted. If we are unable to structure, compensate, train and maintain sufficient numbers of effective sales personnel, or our new or existing sales personnel are not successful in obtaining new end customers, convincing existing customers to renew their subscription-based purchases, or increasing sales to our existing customer base generally, our business, operating results and prospects will be adversely affected. If we are unable to hire, train and maintain sufficient numbers of effective sales personnel, or our new or existing sales personnel are not successful in obtaining new end customers, convincing existing customers to renew their subscription-based purchases, or increasing sales to our existing customer base generally, our business, operating results and prospects will be adversely affected.

Risks Related to Financial, Accounting, Regulatory, Tax, and Other Legal Matters

If we fail to maintain an effective system of internal controls, our ability to produce timely and accurate financial statements or comply with applicable regulations could be impaired.

As a public company, we are subject to the reporting requirements of the Exchange Act, the Sarbanes-Oxley Act of 2002 ("Sarbanes-Oxley Act") and the rules and regulations of the Nasdaq Stock Market. We expect that the requirements of these rules and regulations will continue to increase our legal, accounting and financial compliance costs, make some activities more difficult, time-consuming and costly, and place significant strain on our personnel, systems and resources. The Sarbanes-Oxley Act requires, among other things, that we maintain effective disclosure controls and procedures and internal control over financial reporting.The Sarbanes-Oxley Act requires, among other things, that we maintain effective disclosure controls and procedures and internal control over financial reporting. We are continuing to develop and refine our disclosure controls, internal control over financial reporting and other procedures that are designed to ensure that information required to be disclosed by us in the reports that we will file with the SEC, is recorded, processed, summarized and reported within the time periods specified in SEC rules and forms, and that information required to be disclosed in reports under the Exchange Act is accumulated and communicated to our principal executive and financial officers.

Our current controls and any new controls that we develop may become inadequate because of changes in conditions in our business. Further, weaknesses in our internal controls may be discovered in the future. Any failure to develop or maintain effective controls, or any difficulties encountered in their implementation or improvement, could harm our operating results or cause us to fail to meet our reporting obligations and may result in a restatement of our financial statements for prior periods. Any failure to implement and maintain effective internal controls also could adversely affect the results of periodic management evaluations and annual independent registered public accounting firm attestation reports regarding the effectiveness of our internal control over financial reporting that we are required to include in our periodic reports we will file with the SEC under Section 404 of the Sarbanes-Oxley Act. Ineffective disclosure controls and procedures and internal control over financial reporting could also cause investors to lose confidence in our reported financial and other information, which would likely have a negative effect on the market price of our securities.

In order to maintain and improve the effectiveness of our disclosure controls and procedures and internal control over financial reporting to comply with the SEC rules that implement Sections 302 and 404 of the Sarbanes-Oxley Act, we have expended and anticipate that we may continue to expend significant resources and undertake various actions, including incurring accounting-related costs, implementing new internal controls and procedures, and providing significant management oversight. Any failure to maintain the adequacy of our internal controls, or consequent inability to produce accurate financial statements on a timely basis could increase our operating costs and could materially impair our ability to operate our business and could have a material and adverse effect on our operating results and could cause a decline in the price of our securities. In addition, if we are unable to continue to meet these requirements, we may not be able to maintain our listing on the Nasdaq Global Select Market.

34


Any legal proceedings or claims we may be involved in could be costly and time-consuming to defend and could harm our reputation regardless of their outcome.

We are, and may in the future become, involved in various legal proceedings and claims, including cases involving our IP rights and those of others, commercial matters, employee-related claims, and other actions, including actions that arise in the ordinary course of business. Any litigation, whether meritorious or not, could result in substantial costs, divert our management’s attention and resources from our business, and adversely impact our reputation and brand. This could have an adverse effect on our business, operating results and financial condition. While we maintain insurance coverage for certain types of claims, such insurance coverage may be insufficient to cover all losses or all types of claims that may arise. If we are required to make substantial payments or implement significant changes to our operations as a result of legal proceedings or claims, our business, results of operations and financial condition could be adversely affected.

In addition, companies that experience volatility in their stock price, including us, have historically been subject to securities class action and derivative litigation and we may face similar claims in the future. For example, class action securities lawsuits and shareholder derivative lawsuits were filed against us in February 2019 and March 2023, which have since been resolved. Any such litigation instituted against us, whether meritorious or not, could result in substantial costs, divert management’s attention, and adversely affect our reputation, business, operating results, and financial condition.

Failure to comply with applicable laws and regulations could result in fines, penalties and reputational harm and could also cause us to lose end customers, including in the public sector, or negatively impact our ability to contract with the public sector. 42 Table of Contents Failure to comply with applicable laws and regulations could result in fines, penalties and reputational harm and could also cause us to lose end customers, including in the public sector, or negatively impact our ability to contract with the public sector.

Our business is subject to laws and regulations in the United States and internationally, including those related to employment and labor, antitrust, workplace safety, environmental, consumer protection, anti-bribery laws, import/export controls, trade and economic sanctions, securities, and taxation. In certain jurisdictions, these legal and regulatory requirements may be more stringent than in the United States. Noncompliance with applicable regulations or requirements could subject us to investigations, sanctions, mandatory product recalls, enforcement actions, disgorgement of profits, fines, damages, and civil and criminal penalties or injunctions. If any governmental sanctions are imposed, or if we do not prevail in any possible civil or criminal litigation, our business, reputation, operating results, and financial condition could be adversely affected. In addition, responding to any action will likely result in a significant diversion of management’s attention and resources and an increase in third-party professional fees. Enforcement actions and sanctions could harm our reputation, business, operating results and financial condition.

In addition, we must comply with laws and regulations relating to the formation, administration and performance of contracts with the public sector, including U.S. federal, state and local governmental organizations, which affect how we and our channel partners do business with governmental agencies. Selling our solutions to the U.S. government, whether directly or through channel partners, also subjects us to certain regulatory and contractual requirements, including meeting the compliance requirements necessary for maintaining any required security clearances for facilities and employees. Failure to comply with these requirements by either us or our channel partners could subject us to investigations, fines and other penalties, which could have an adverse effect on our business, operating results, financial condition, and prospects. For example, the U.S. Department of Justice ("DOJ") has identified procurement fraud as an enforcement priority, indicating an ongoing commitment to aggressive enforcement under the False Claims Act and other applicable laws. Violations of certain regulatory and contractual requirements could also result in us being suspended or debarred from future government contracting. Any of these outcomes could have an adverse effect on our revenue, operating results, financial condition, and prospects.

35


These laws and regulations impose added costs on our business, and failure to comply with these or other applicable regulations and requirements, including noncompliance in the past, could lead to claims for damages from our channel partners, penalties, termination of contracts, loss of exclusive rights in our intellectual property, and temporary suspension or permanent debarment from government contracting. Any such damages, penalties, disruptions, or limitations in our ability to do business with the public sector could have an adverse effect on our business and operating results.

We are subject to stringent and rapidly changing laws, regulations, industry standards and frameworks, contractual requirements, and other obligations related to privacy, artificial intelligence, data protection, and information security, and our actual or perceived failure to comply with such obligations could adversely affect our business and operating results.We are subject to stringent and rapidly changing laws, regulations, industry standards and frameworks, and other obligations related to privacy, artificial intelligence, data protection, and information security, and our actual or perceived failure to comply with such obligations could adversely affect our business and operating results. Any inability to comply with such obligations could also impair our efforts to maintain and expand our customer base, lengthen sales cycles, increase costs, and thereby decrease our revenue. Any inability to comply with such obligations could also impair our efforts to maintain and expand our customer base, and thereby decrease our revenue.

Privacy, AI, data protection, and information security are significant issues in the United States and the other jurisdictions where we offer our solutions.Privacy, artificial intelligence, data protection, and information security are significant issues in the United States and the other jurisdictions where we offer our solutions. The regulatory framework for privacy, AI, and security issues worldwide is rapidly evolving and is likely to remain uncertain for the foreseeable future. The regulatory framework for privacy, artificial intelligence, and security issues worldwide is rapidly evolving and is likely to remain uncertain for the foreseeable future. Our handling of data, including customer data, personal data, support data, telemetry, employee data, and other information processed in connection with our products, services, operations, and go-to-market activities, is subject to a variety of global laws and regulations, including regulation by various government agencies, including the U.S. Federal Trade Commission ("FTC") and various state, local and foreign bodies, data protection authorities, and agencies.

The U.S. federal and various state and foreign governments have adopted or proposed limitations on the collection, use, storage, retention, security, disclosure, sale, sharing, and transfer, localization, and deletion of personal information of individuals, including end customers and their personnel, partners, prospects, and employees. In the United States, the FTC, other federal agencies, and many state attorneys general are applying evolving federal and state laws and regulations governing consumer protection, privacy, cybersecurity, and unfair and deceptive trade practices to the online collection, use and dissemination of data, including restrictions on transfers of certain data categories with countries of concern. Additionally, many foreign countries and governmental bodies, including in Australia, Brazil, the European Economic Area ("EEA"), the UK, Switzerland, India, Japan, China, and numerous other jurisdictions in which we operate or conduct our business, have laws and regulations concerning the collection, use, transfer, storage, security, and deletion of personal information obtained from their residents or by businesses operating within their jurisdiction. Additionally, many foreign countries and governmental bodies, including in Australia, Brazil, the European Economic Area ("EEA"), the UK, Switzerland, India, Japan, China, and numerous other jurisdictions in which we operate or conduct our business, have laws and regulations concerning the collection and use of personal information obtained from their residents or by businesses operating within their jurisdiction. These laws and regulations often are more restrictive than those in the United States. For example, the General Data Protection Regulation ("GDPR") the UK General Data Protection Regulation, and Brazil’s Lei Geral de Protecao de Dados ("LGPD"), impose more stringent data protection requirements, provide an enforcement authority which substantially increases compliance costs, and impose large penalties for noncompliance. Such laws and regulations may require companies to implement new privacy, security, retention, data governance and AI policies; conduct privacy, transfer, security, data protection, and AI impact assessments; respond to requests from individuals to access, correct, delete, restrict, port, or opt out of certain uses of personal information; notify individuals, customers, regulators, or other parties of security incidents or personal data breaches; impose restrictions on automated decision-making, profiling or certain AI-enabled uses; and, among others, obtain individuals’ consent or provide opt-out rights to use personal information for certain purposes. In addition, some countries have enacted, or are currently considering, legislation that requires local storage and processing of data to avoid any form of transfer to a third country, or impose sector-specific requirements for regulated industries and public sector customers, or other restrictions on transfer and disclosure of personal data outside of that country which may impact our compliance obligations, potentially exposing us to liability, require changes to our product architecture or service delivery model, and increase the cost and complexity of delivering our products and services. In addition, some countries have enacted, or are currently considering, legislation that requires local storage and processing of data to avoid any form of transfer to a third country, or other restrictions on transfer and disclosure of personal data outside of that country which may impact our compliance obligations, potentially exposing us to liability, and increase the cost and complexity of delivering our products and services.

36


In addition to comprehensive data protection and privacy laws, we are subject, or may become subject, to a growing number of cybersecurity, digital resilience, and product security regulations globally, including the European Union's Network and Information Security Directive ("NIS2"), Cyber Resilience Act ("CRA"), and, indirectly through our customers and business partners, the Digital Operational Resilience Act ("DORA"). Compliance with these requirements may require significant operational, technical, and administrative efforts and could increase our costs and legal obligations. These regulatory frameworks continue to evolve, and their interpretation, implementation, and enforcement remain uncertain, which may create additional compliance risks and challenges.

We also expect that there will continue to be new proposed laws, regulations, enforcement actions, regulatory guidance, industry standards, and case law concerning privacy, AI, data protection, and information security in the United States, the EEA and other jurisdictions, and we cannot yet determine the impact these developments may have on our business.We also expect that there will continue to be new proposed laws, regulations, industry standards, and case law concerning privacy, data protection and information security in the United States, the EEA and other jurisdictions, and we cannot yet determine the impact these developments may have on our business. This includes laws and regulatory frameworks governing AI system development, deployment, transparency, governance, accuracy, bias, explainability, human oversight, prohibited or high-risk AI practices, cybersecurity, critical infrastructure, digital operational resilience, software supply chain security and the handling of sensitive data. These developments increase uncertainty and may require us to change our data and AI internal operations, security controls, and practices and/or change our technology solutions, business model or processes, which may in turn adversely affect demand for our products and services.Our agreement with Supermicro does not contain any price assurances, and increases in component costs, without a corresponding increase in the price of our NX series solutions, could reduce the amount that an end customer pays for our software, thereby adversely affecting our revenue. Additionally, our sales cycles may lengthen due to increasingly rigorous and complex customer-driven security, AI, and privacy assessments as part of customers’ purchasing decisions. Additionally, our sales cycles may lengthen due to increasingly rigorous and complex customer-driven security, artificial intelligence, and privacy assessments as part of customers’ purchasing decisions.

While the EU-U.S. Data Privacy Framework accepted by the European Commission in July 2023 (as well as the UK Extension to the EU-U.S. DPF and Swiss-U.S. DPF) provides us with a transfer mechanism for data from the EEA, data transfers continue to be scrutinized by regulators in the EEA, the UK and other countries with similar transfer restrictions requiring organizations to ensure that the data is protected to a standard that is "essentially equivalent" to that under the GDPR, UK GDPR, Swiss Federal Data Protection Act, and/or other applicable laws and to document this.

As a result of these and future data transfer, localization, and sovereignty developments, we may experience a reluctance from current or prospective customers in the EEA, the UK, Switzerland, and other and jurisdictions with similar transfer restrictions to use our products and services, particularly where customer data, support data, telemetry, logs, metadata or other regulated data may be accessed, transferred, hosted or processed outside the customer’s preferred jurisdiction. We may find it necessary to make changes to our data transfer mechanisms and handling of personal data, including with respect to the provision of our products and services. Such changes may require additional engineering, operational, legal and compliance resources, may limit certain product capabilities or service models, and may adversely impact our business, financial condition, and operating results.

In the United States, more states are adopting their own data protection legislation, creating a complex privacy landscape from state to state. 44 Table of Contents In the United States, more states are adopting their own data protection legislation, creating a complex privacy landscape from state to state. The California Consumer Privacy Act ("CCPA"), among other things, requires covered companies to provide disclosures to California consumers and afford such consumers new abilities to opt out of the sale of their personal information. The California Privacy Rights Act ("CPRA") generally expanded consumers’ privacy rights and protections with respect to their personal information. Various U.S. states have passed privacy legislation now in effect. We cannot yet predict the full impact of these laws on our business or operations, but it may continue to require us to modify our data processing practices and policies and to incur substantial costs and expenses in an effort to comply.

Moreover, as a result of current and proposed data protection and privacy laws addressing the use of personal data for marketing purposes, including the European Commission’s draft ePrivacy Regulation, which is intended to replace the ePrivacy Directive in the EEA, as well as the CCPA/CPRA and other U.S. state privacy laws, we face increased difficulty in marketing to current and potential customers, as these laws impact the ability to use internet-based services and tracking technologies, such as cookies, which impacts our ability to spread awareness of our products and services and, in turn, grow a customer base in some regions. We also expect to incur additional costs to comply with the requirements of these laws.

37


We are positioned as a data processor with respect to the cloud-based services we offer and, as we expand our support offerings, professional services, telemetry-enabled features, and AI-enabled capabilities, we may increasingly act as a data processor, service provider, contractor, subprocessor, or similar regulated role. These roles impose additional obligations under the foregoing and other laws and regulations relating to privacy, cybersecurity, AI and data protection and may increase our compliance burden and liability exposure by operation of law, contract (including contracts with customers in regulated industries), or penalties for noncompliance.As we begin to offer more cloud-based services, we will increasingly be positioned as a data processor, which imposes additional obligations under the foregoing and other laws and regulations relating to privacy and data protection and may increase our liability exposure by operation of law, contract, or penalties for noncompliance. Additionally, we expect that existing laws, regulations and standards may be interpreted in new ways in the future. Current or future laws, regulations, standards, and other obligations, as well as changes in the interpretation of existing laws, regulations, standards, and other obligations could impair our or our customers’ ability to collect, use, disclose, retain, analyze, transfer, or otherwise process information relating to individuals, which could decrease demand for our solutions, require us to restrict our business operations, increase our costs, delay product development or deployment, and impair our ability to maintain and grow our customer base and increase our revenue. Current or future laws, regulations, standards, and other obligations, as well as changes in the interpretation of existing laws, regulations, standards, and other obligations could impair our or our customers’ ability to collect, use or disclose information relating to individuals, which could decrease demand for our solutions, require us to restrict our business operations, increase our costs, and impair our ability to maintain and grow our customer base and increase our revenue.

Although we are working to comply with federal, state and foreign laws and regulations, industry standards, contractual obligations, and other legal obligations that apply to us, those laws, regulations, standards, and obligations are evolving and may be modified, interpreted and applied in an inconsistent manner from one jurisdiction to another, and may conflict with one another, other requirements or legal obligations, our practices or the product features, our use of third-party providers, or the design and operation of our solutions. As such, we cannot assure ongoing compliance with all such laws or regulations, industry standards, contractual obligations, and other legal obligations. Any failure or perceived failure by us or by our vendors, subprocessors, partners, or other third parties to comply with federal, state or foreign laws or regulations, industry standards, contractual obligations, or other legal obligations, or any actual or suspected cyberattack, security vulnerability, ransomware event, supply chain compromise, or other security incident, whether or not resulting in unauthorized access to, or acquisition, release or transfer of personal information, customer data, confidential information, intellectual property, telemetry, logs, metadata, or other data, may result in governmental enforcement actions and prosecutions, private litigation, fines and penalties, or adverse publicity and could cause our customers to lose trust in us, which could have an adverse effect on our reputation, brand and business. If we fail to manage our relationships with such manufacturers effectively, or if such manufacturers experience delays, disruptions or increased manufacturing lead times, component lead-time disruptions, capacity constraints, or quality control problems in their operations or are unable to address our or our end customers’ requirements for or concerns about timely delivery, our ability to sell our solutions to our end customers could be severely impaired due to the lack of availability of certified hardware platforms, and our customers' ability, or willingness, to consume our software may be materially impacted or delayed, which could adversely affect our business and operating results, competitive position, brand and reputation, as well as our relationships with affected customers. Any inability to adequately address privacy, data protection, AI, and security concerns, even if unfounded, or comply with applicable laws, regulations, policies, industry standards, contractual obligations, or other legal obligations could result in additional cost and liability to us, damage our reputation and brand, inhibit sales, delay or prevent deployments, and adversely affect our business and operating results. Any inability to adequately address privacy and security concerns, even if unfounded, or comply with applicable laws, regulations, policies, industry standards, contractual obligations, or other legal obligations could result in additional cost and liability to us, damage our reputation and brand, inhibit sales, and adversely affect our business and operating results.

Failure to comply with anti-corruption and anti-money laundering laws, including the U.S. Foreign Corrupt Practices Act of 1977, as amended, and similar laws associated with our activities outside of the United States could subject us to penalties and other adverse consequences.

We are subject to the FCPA, the U.S. domestic bribery statute contained in 18 U.S.C. § 201, the U.S. Travel Act, the UK Bribery Act, and possibly other anti-bribery and anti-money laundering laws in countries in which we conduct activities. We face significant risks if we fail to comply with the FCPA and other anti-corruption laws that prohibit companies and their employees and third-party intermediaries from authorizing, offering or providing, directly or indirectly, improper payments or benefits to foreign government officials, political parties and private-sector recipients for the purpose of obtaining or retaining business, directing business to any person or securing any advantage. In many foreign countries, particularly in countries with developing economies, it may be a local custom that businesses engage in practices that are prohibited by the FCPA or other applicable laws and regulations. In addition, we use various third parties to sell our solutions and conduct our business abroad. We or our third-party intermediaries may have direct or indirect interactions with officials and employees of government agencies, or state-owned or affiliated entities and we can be held liable for the corrupt or other illegal activities of these third-party intermediaries, our employees, representatives, contractors, partners, and agents, even if we do not explicitly authorize such activities. We continue to update and implement our FCPA/anti-corruption compliance program and no assurance can be given that all of our employees and agents, as well as those companies to which we outsource certain of our business operations, will not take actions in violation of our policies and applicable law, for which we may be ultimately held responsible.

38


Any violation of the FCPA, other applicable anti-corruption laws and anti-money laundering laws could result in whistleblower complaints, adverse media coverage, investigations, loss of export privileges, severe criminal or civil sanctions, and, in the case of the FCPA, suspension or debarment from U.S. government contracts, which could have a material and adverse effect on our reputation, brand, business, operating results, and prospects. In addition, responding to any enforcement action may result in a materially significant diversion of management’s attention and resources and significant defense costs and other third-party professional fees.

We are subject to governmental export and import controls and other trade restrictions that could impair our ability to compete in international markets or subject us to liability if violated.We are subject to governmental export and import controls that could impair our ability to compete in international markets or subject us to liability if we violate the controls.

Our solutions are subject to U.S. export controls, including the Export Administration Regulations and economic sanctions administered by the Office of Foreign Assets Control, and we incorporate encryption technology into certain of our solutions. These encryption products and the underlying technology may be exported outside of the United States only with the required export authorizations, including by license, a license exception or other appropriate government authorizations. Changes in export controls, sanctions, and related regulations, including emerging restrictions targeting AI technologies, may increase compliance costs, restrict access to technologies and AI hardware, or adversely affect our operations.

Furthermore, our activities are subject to U.S. and foreign economic sanctions laws and regulations that prohibit the export of certain products and services without the required export authorizations, including to countries, governments and persons targeted by U.S. or foreign embargoes or sanctions. Additionally, the U.S. government has recently been critical of existing trade agreements and may impose more stringent export and import controls. Obtaining the necessary export license or other authorization for a particular sale may be time-consuming and may result in the delay or loss of sales opportunities even if the export license ultimately may be granted. While we take precautions to prevent our solutions from being exported in violation of these laws, including obtaining authorizations for our encryption products, implementing IP address blocking and screenings against U.S. government and international lists of restricted and prohibited persons, we cannot guarantee that the precautions we take will prevent violations of export control and sanctions laws. Violations of U.S. or foreign sanctions or export control laws can result in significant fines or penalties. In addition, trade restrictions, new or increased tariffs (or the threat thereof), or disruptions affecting suppliers, OEM partners, or logistics providers could increase costs or delay product availability. For example, imports of foreign-origin hardware products into the United States may be subject to new or increased tariffs recently imposed by the U.S. government. In response to these new, increased, or threatened U.S. tariffs, foreign countries may impose retaliatory tariffs on U.S.-origin goods in response, which could also affect our products or business operations. If we fail to comply with applicable tariff laws, we may be subject to monetary fines, denial of import privileges, increased scrutiny, and other penalties.

If our channel, alliance and OEM partners fail to obtain appropriate import, export or re-export licenses or permits, or fail to comply with applicable import and export control laws and regulations, we may also be adversely affected, through reputational harm as well as other negative consequences including government investigations and penalties. 46 Table of Contents We also note that if our channel, alliance and OEM partners fail to obtain appropriate import, export or re-export licenses or permits, we may also be adversely affected, through reputational harm as well as other negative consequences including government investigations and penalties. We presently incorporate export control compliance requirements into our relevant partner agreements; however, no assurance can be given that our partners will, or will be able to, comply with such requirements.

39


Also, various countries, in addition to the United States, regulate the import and export of certain encryption and other technology, including import and export licensing requirements, and have enacted laws that could limit our ability to distribute our solutions or could limit our end customers’ ability to implement our solutions in those countries. Changes in our solutions or future changes in export and import regulations may create delays in the introduction of our solutions in international markets, result in increased licensing requirements, prevent our end customers with international operations from deploying our solutions globally or, in some cases, prevent the export or import of our solutions to certain countries, governments, or persons altogether. Changes in our solutions or future changes in export and import regulations may create delays in the introduction of our solutions in international markets, prevent our end customers with international operations from deploying our solutions globally or, in some cases, prevent the export or import of our solutions to certain countries, governments, or persons altogether. From time to time, various governmental agencies have proposed additional regulation of encryption technology, including the escrow and government recovery of private encryption keys. Any change in export or import regulations, economic sanctions or related legislation, increased export and import controls stemming from U.S. government policies, or change in the countries, governments, persons or technologies targeted by such regulations, could result in decreased use of our solutions by, or in our decreased ability to export or sell our solutions to, existing or potential end customers with international operations. Any decreased use of our solutions or limitation on our ability to export or sell our solutions would adversely affect our business, operating results and prospects.

Taxing authorities may successfully assert that we should have collected or in the future should collect sales and use, value added or similar taxes, and we could be subject to liability with respect to past or future sales, which could adversely affect our operating results.

We do not collect sales and use, value added or similar taxes in all jurisdictions in which we have sales, and we have been advised that such taxes are not applicable to our products and services in certain jurisdictions. Sales and use, value added, and similar tax laws and rates vary greatly by jurisdiction. Certain jurisdictions in which we do not collect such taxes may assert that such taxes are applicable. If we are unsuccessful in collecting such taxes from our end customers, we could be held liable for such costs, which may adversely affect our operating results.

The application of tax laws to services provided electronically is evolving. New sales and use, value added or similar tax laws, statutes, rules, regulations, or ordinances could be enacted at any time. For example, California has recently amended its tax laws to subject certain retail sales of digital prewritten software, cloud-based applications, and software services to sales tax in California, effective January 1, 2027, which may increase the cost to our California-based customers of purchasing our products, and similarly may increase the costs to us of purchasing software products we use in our business.

Our international operations may subject us to potential adverse tax consequences.

We have expanded our international operations and staff to better support our growth into the international markets. Our corporate structure and associated transfer pricing policies contemplate the business flows and future growth into the international markets, and consider the functions, risks and assets of the various entities involved in the intercompany transactions. The amount of taxes we pay in different jurisdictions may depend on the application of the tax laws of the various jurisdictions, including the United States, to our international business activities, changes in tax rates, change in our geographical earnings mix, new or revised tax laws or interpretations of existing tax laws and policies and our ability to operate our business in a manner consistent with our corporate structure and intercompany arrangements. The taxing authorities of the jurisdictions in which we operate may challenge our methodologies for pricing intercompany transactions pursuant to the intercompany arrangements or disagree with our determinations as to the income and expenses attributable to specific jurisdictions. If such a challenge or disagreement were to occur, and our position was not sustained, we could be required to pay additional taxes, interest and penalties, which could result in one-time tax charges, higher effective tax rates, reduced cash flows and lower overall profitability of our operations. Our financial statements could fail to reflect adequate reserves to cover such a contingency.

40


Changes in global tax laws could increase our worldwide tax rate and could have a material adverse effect on our business, cash flow, results of operations or financial conditions.

Global tax developments applicable to multinational businesses may have a material impact on our business, cash flow from operating activities, or financial results. The U.S. Department of Treasury has broad authority to issue regulations and interpretative guidance that may significantly impact how we comply with the law, which could affect our results of operations in the period issued.

The Organisation for Economic Cooperation and Development ("OECD") reached agreement among various countries to implement a global minimum tax framework, commonly referred to as Pillar Two, which imposes a minimum effective tax rate of 15% on certain multinational enterprises. On January 5, 2026, the OECD announced a side-by-side elective safe harbor that would exempt electing U.S.-parented multinationals from certain provisions of Pillar Two for fiscal years beginning on or after January 1, 2026, but does not provide an exemption from the "qualified domestic minimum top-up taxes" that many countries have enacted or begun the process of enacting laws based on Pillar Two proposals. The safe harbor must be adopted into the domestic laws of the relevant jurisdictions and the timing and the degree of adoption may vary by jurisdiction.

In addition, several countries have proposed or enacted digital services taxes, many of which would apply to revenues derived from digital services. We will continue to assess the ongoing impact of these current and pending changes to global tax legislation and the impact on our future financial statements upon the finalization of laws, regulations and additional guidance. In addition, as we continue to evaluate our corporate structure, any changes to the taxation of undistributed foreign earnings could also change our plans regarding reinvestment of such earnings. Due to the large scale of our U.S. and international business activities, many of these enacted and proposed changes to the taxation of our activities could increase our worldwide effective tax rate and have an adverse effect on our operating results, cash flow or financial condition.

We are subject to income taxes as well as non-income-based taxes, in both the U.S. and various foreign jurisdictions. Many judgments are required in determining our worldwide provision for income taxes and other tax liabilities, and we are under audit by various tax authorities, which often do not agree with positions taken by us on our income and non-income-based tax returns. Although we believe that our estimates are reasonable, the ultimate tax outcome may differ from the amounts recorded in our consolidated financial statements and may materially affect our financial results in the period or periods for which such determination is made.

Our ability to use our net operating loss carryforwards and certain other tax attributes may be limited.

In general, under Section 382 of the United States Internal Revenue Code of 1986, as amended (the "Code"), a corporation that undergoes an ownership change is subject to limitations on its ability to utilize its pre-change net operating losses ("NOLs"), and other tax attributes to offset future taxable income. An ownership change occurs when a company’s "five-percent shareholders" (as defined in Section 382 of the Code) collectively increase their ownership in the company by more than 50 percentage points (by value) over a rolling three-year period. Similar limitations may apply for state tax purposes. If our existing NOLs are subject to limitations arising from previous ownership changes, our ability to utilize NOLs could be limited by Section 382 of the Code. We may experience ownership changes in the future as a result of subsequent shifts in our stock ownership. In addition, at the state level, there may be periods during which the use of NOLs is suspended or otherwise limited. In addition, at the state level, there may be periods during which the use of net operating losses is suspended or otherwise limited.

Risks Related to Our Convertible Notes and Credit Facility

As of July 31, 2026, we had outstanding $500.0 million aggregate principal amount of 0.25% convertible senior notes due 2027 (the "2027 Notes") and $862.5 million aggregate principal amount of 0.50% convertible senior notes due 2029 (the “2029 Notes” and together with the 2027 Notes, collectively, the “Notes”). As of July 31, 2026, we also had outstanding a revolving credit agreement (the "Revolver") that provides for a senior secured revolving credit facility in an aggregate principal amount of $500.0 million.

41


Servicing and repaying our indebtedness, including the 2027 Notes, the 2029 Notes and any borrowings under the Revolver, may require a significant amount of cash, and we may not have sufficient cash to pay our indebtedness.

As of July 31, 2026, we had outstanding $500.0 million aggregate principal amount of 2027 Notes and $862.5 million aggregate principal amount of 2029 Notes.As of July 31, 2025, we had outstanding $500.0 million aggregate principal amount of 2027 Notes and $862.5 million aggregate principal amount of 2029 Notes. Our ability to make scheduled payments in respect of, or to refinance, our indebtedness may depend on our future performance, which is subject to economic, financial, competitive, and other factors beyond our control. Our business may not be able to generate cash flows from operations in the future that are sufficient to service our debt and make necessary capital expenditures. If we are unable to generate such cash flows, we may be required to adopt one or more alternatives, such as obtaining additional debt financing or equity capital on terms that may be onerous or highly dilutive, restructuring debt, or selling assets. Any such financing or refinancing may not be available on acceptable terms, or at all, particularly during periods of higher interest rates, reduced credit availability or adverse market conditions. In addition, the Revolver contains restrictive covenants that limit us, and any of our future debt agreements may contain restrictive covenants that may limit or prohibit us, in each case, from adopting any of these alternatives. Our failure to comply with these covenants could result in an event of default, which could result in the acceleration of our debt. Our indebtedness could make us more vulnerable to adverse economic, industry and regulatory developments, limit our flexibility in planning for or responding to changes in our business, restrict our ability to obtain additional financing for working capital, acquisitions or other corporate purposes, expose us to interest-rate risks to the extent applicable, place us at a competitive disadvantage relative to less leveraged competitors, and make an acquisition of our company more difficult. Any of these factors could harm our business, results of operations, and financial condition. Any of these events could adversely affect our business, operating results, financial condition, and prospects. In addition, if we incur additional indebtedness, the risks related to our business and our ability to service or repay our indebtedness would increase.

We may not have sufficient cash or the ability to raise the funds necessary to settle conversions of the Notes in cash, to repay the Notes at maturity, or to repurchase the Notes upon a fundamental change.

Holders of the Notes will have the right to require us to repurchase for cash all or a portion of their Notes upon the occurrence of a fundamental change before the applicable maturity date at a repurchase price equal to 100% of the principal amount of such Notes to be repurchased, plus any accrued and unpaid interest to, but excluding, the fundamental change repurchase date. In addition, upon conversion of the Notes, unless we elect to deliver solely shares of our Class A common stock to settle such conversion (other than paying cash in lieu of delivering any fractional share), we will be required to make cash payments in respect of the Notes being converted. Moreover, we will be required to repay the Notes in cash at their maturity unless earlier converted, redeemed or repurchased. We may not have enough available cash or be able to obtain financing at the time we are required to make repurchases of the Notes of a series surrendered therefor or pay cash with respect to the Notes of such series being converted or at their maturity. In addition, our ability to repurchase the Notes of a series or to pay cash upon conversions of such Notes or at their maturity may be limited by law, regulatory authority or agreements governing our future indebtedness. Our failure to repurchase the Notes of a series at a time when the repurchase is required by the applicable indenture or to pay cash upon conversions of such Notes or at their maturity as required by the applicable indenture would constitute a default under such indenture. A default under the applicable indenture or the fundamental change itself could also lead to a default under agreements governing our future indebtedness. Moreover, the occurrence of a fundamental change under the applicable indenture could constitute an event of default under any such agreement. If the payment of the related indebtedness were to be accelerated after any applicable notice or grace periods, we may not have sufficient funds to repay the indebtedness or to pay cash amounts due upon conversion, upon required repurchase or at maturity of the applicable series of the Notes.

42


The conditional conversion feature of the 2027 Notes or the 2029 Notes, if triggered, may adversely affect our financial condition and operating results.

The 2027 Notes and the 2029 Notes are convertible under the circumstances described in Note 5 of the Notes to Consolidated Financial Statements included in Part II, Item 8 of this Annual Report on Form 10-K. In the event the conditional conversion feature of the 2027 Notes or the 2029 Notes is triggered, holders of such Notes will be entitled to convert their Notes at any time during specified periods at their option. If one or more holders elect to convert their Notes, unless we elect to satisfy our conversion obligation by delivering solely shares of our Class A common stock (other than paying cash in lieu of delivering any fractional share), we would be required to settle a portion or all of our conversion obligation in cash, which could adversely affect our liquidity. In addition, even if holders of the Notes of a series do not elect to convert their Notes, we could be required under applicable accounting rules to reclassify all or a portion of the outstanding principal of the Notes of such series as a current rather than long-term liability, which would result in a material reduction of our net working capital.

The accounting method for the Notes, which may be settled in cash upon conversion, has had, and may continue to have, a material effect on our reported or future financial results.

We utilize the if-converted method for our diluted earnings per share calculation, the effect of which is that the transaction is accounted for as if the outstanding Notes were to be converted into shares of our Class A common stock at the respective conversion rate in the beginning of the respective period, even if the Notes of a series are not yet then convertible and even if, upon any conversion of any Notes of a series, we may elect to settle the conversion using cash or a combination of cash and shares of our Class A common stock. As a result, our diluted earnings per share could be adversely affected.

Our revolving credit facility contains a financial covenant and other covenants that may restrict our actions, and a failure to comply with these covenants could have a material adverse effect on our financial condition. 50 Table of Contents Our revolving credit facility contains a financial covenant and other covenants that may restrict our actions, and a failure to comply with these covenants could have a material adverse effect on our financial condition.

In February 2025, we entered into the Revolver. The Revolver includes covenants that limit our ability to, among other things, incur liens, make investments, incur indebtedness, merge or consolidate with other companies, sell substantially all of our assets, make restricted payments, undergo certain fundamental changes, and prepay subordinated debt. In addition, the Revolver contains a financial covenant that requires us to maintain compliance with a maximum consolidated total leverage ratio, calculated as set forth in the Revolver and tested at the end of each fiscal quarter. As a result of these restrictions, we may be limited in how we conduct business, unable to raise additional debt or equity financing to operate during general economic or business downturns, or unable to compete effectively or to take advantage of new business opportunities. Our ability to comply with these covenants depends on many factors, some of which are beyond our control. The Revolver contains various events of default that include, among others, non-payment of principal, interest or fees, breach of covenants, inaccuracy of representations and warranties, cross defaults to certain other indebtedness, bankruptcy and insolvency events, material judgments, and events constituting a change of control, in each case subject to thresholds and cure periods as set forth in the Revolver. Upon the occurrence and during the continuance of such an event of default, our lenders would have the right to terminate their commitments and accelerate our obligations under the Revolver as well as exercise other rights and remedies provided for under the Revolver, the other loan documents and applicable law. If outstanding borrowings under the Revolver were to be accelerated, we may not have sufficient cash on hand or be able to borrow sufficient funds to refinance the debt or sell sufficient assets to repay the debt, which could immediately adversely affect our business, cash flows, results of operations, and financial condition.

43


Risks Related to Ownership of Our Securities

The market price of our securities may be volatile and may decline, including if we fail to meet our publicly announced financial guidance or other expectations.

The market price of our securities has fluctuated and may continue to fluctuate substantially in response to a number of factors, including those described in this "Risk Factors" section, many of which are beyond our control and may be unrelated to our operating performance. Factors that could cause fluctuations in the market price of our securities include:

price and volume fluctuations in the overall stock market or volatility in the market prices and trading volumes of technology companies;
changes in operating performance and stock market valuations of other technology companies generally, or those in our industry in particular;
changes in financial estimates by any analysts who follow our company or our failure to meet these estimates or the expectations of investors;
announcements regarding actual or anticipated significant business developments by us or our competitors, including new products and solutions, technologies, new or terminated significant contracts, strategic relationships, acquisitions, investments, capital commitments, or other changes in the competitive landscape;
public analyst or investor reaction to our press releases, other public announcements and filings with the Securities and Exchange Commission;
rumors and market speculation involving us or other companies in our industry;
actual or anticipated changes in our operating results, financial condition, business performance, or growth prospects;
actual or threatened litigation involving us, our industry or both, or investigations by regulators into our operations or those of our competitors;
developments or disputes concerning our intellectual property or our solutions, or third-party proprietary rights;
new laws or regulations or new interpretations of existing laws or regulations applicable to our business;
changes in accounting standards, policies, guidelines, interpretations, or principles;
actual or anticipated changes in our management or our board of directors ("Board of Directors" or "Board");
general economic conditions and slow or negative growth of our markets; and
other events or factors which may be outside of our control, such as political and social unrest, terrorist attacks, hostilities, war, malicious human acts, climate change, natural disasters (including extreme weather), pandemics or other major public health concerns, and other similar events, or responses to these events.

44


We periodically provide financial guidance and other expectations regarding our future performance that represents our management’s assumptions and estimates as of the date of release. Some of those key assumptions relate to the macroeconomic environment, including supply chain and military conflicts, which are inherently difficult to predict. Some of those key assumptions relate to the macroeconomic environment, including inflation and interest rates, which are inherently difficult to predict. Other assumptions relate to the timing and structure of customer billings and payments. We may offer customers increased flexibility in payment arrangements, including annual payment schedules, financing arrangements or other payment alternatives. Changes in the mix of annual versus multi-year billings, customer payment preferences, financing arrangements, or other commercial terms could affect billings, deferred revenue, operating cash flow and free cash flow and may make forecasting such metrics more difficult. While presented with numerical specificity, our guidance is inherently speculative and subject to significant uncertainties and changing business assumptions beyond our control, which may cause actual results to vary materially from our projections. Furthermore, analysts and investors may develop and publish their own projections of our business, which may form a consensus about our future performance. Our actual business results may vary significantly from such guidance or that consensus due to a number of factors, many of which are outside of our control, including those described in this "Risk Factors" section, any of which or combination thereof could materially and adversely affect our business and future operating results. Certain financial and operating metrics, including billings, deferred revenue, operating cash flow and free cash flow, may be more sensitive to changes in customer billing and payment structures than revenue. Furthermore, if we make downward revisions to our previously announced guidance, if we withdraw our previously announced guidance, or if our publicly announced guidance regarding future operating results fails to meet expectations of securities analysts, investors or other interested parties, the price of our securities would decline.

In addition, the trading market for technology companies has experienced extreme price and volume volatility that have often been unrelated or disproportionate to the operating performance of those companies.In addition, the stock market in general, and the market for technology companies in particular, has experienced extreme price and volume fluctuations that have often been unrelated or disproportionate to the operating performance of those companies. Broad market and industry factors may seriously affect the market price of our securities, regardless of our actual operating performance. Furthermore, securities analysts may publish reports, forecasts, or recommendations regarding our business, and changes in analyst expectations regarding us or our industry could adversely affect the market price or trading volume of our securities. These fluctuations and conditions could cause you to lose all or part of your investment in our securities. These fluctuations could cause you to lose all or part of your investment in our securities.

Sales of substantial amounts of our Class A common stock in the public markets, or the perception that they might occur, could reduce the price that our securities might otherwise attain and may dilute your voting power and your ownership interest in us. Sales of substantial amounts of our Class A common stock in the public markets, or the perception that they might occur, could reduce the price that our securities might otherwise attain and may dilute your voting power and your ownership interest in us.

Sales of a substantial number of shares of our Class A common stock in the public markets, particularly sales by our directors, executive officers and significant stockholders, or the perception that these sales could occur (including public disclosure of sales contemplated by 10b5-1 trading plans), could adversely affect the market price of our Class A common stock. We have reserved a substantial number of shares of our Class A common stock for issuance upon vesting or exercise of our equity compensation plans and upon conversion of the Notes.We have reserved a substantial number of shares of our Class A common stock for issuance upon vesting or exercise of our equity compensation plans and upon conversion of the Notes. We have also registered the offer and sale of all shares of our Class A common stock that we may issue under our equity compensation plans.We have also registered the offer and sale of all shares of our Class A common stock that we may issue under our equity compensation plans. We may also issue our shares of Class A common stock or additional securities convertible into shares of our Class A common stock from time to time in connection with a financing, acquisition, investments, or otherwise.We may also issue our shares of Class A common stock or additional securities convertible into shares of our Class A common stock from time to time in connection with a financing, acquisition, investments, or otherwise. Any such issuance could result in substantial dilution to our existing stockholders and cause the market price of our Class A common stock to decline.

Conversion of the Notes may dilute the ownership interest of existing stockholders, or may otherwise depress the price of our securities.

The conversion of some or all of the Notes, to the extent we deliver shares upon conversion thereof, will dilute the ownership interests of existing stockholders, reduce our earnings per share and potentially have an adverse effect on the price of our securities. Any sales in the public market of our Class A common stock issuable upon such conversion could adversely affect prevailing market prices of our securities. In addition, the existence of the Notes may encourage short selling by market participants because the conversion of the Notes could be used to satisfy short positions, or anticipated conversion of the Notes into shares of our Class A common stock could depress the price of our securities.

45


We cannot guarantee that our share repurchase program will be fully consummated or that it will enhance long-term stockholder value.

In August 2023, our Board of Directors authorized the repurchase of up to $350.0 million of our Class A common stock. In August 2025 and April 2026, our Board of Directors approved increases of $350.0 million and $750.0 million, respectively, to the share repurchase authorization, of which $728.9 million remained available for future share repurchases as of July 31, 2026. The authorization has no expiration date and does not obligate us to repurchase any minimum number of shares. The timing and amount of share repurchases will depend upon prevailing stock prices, business and market conditions, corporate and regulatory requirements, alternative investment opportunities, and other factors. We cannot guarantee that the share repurchase program will be fully executed or that it will enhance long-term stockholder value. Share repurchases under the program could affect, and increase the volatility of, the price of our Class A common stock and will diminish our cash reserves. In addition, as part of the Inflation Reduction Act signed into law in August 2022, the United States implemented a 1% excise tax on the value of certain stock repurchases by publicly traded companies. This tax may increase the costs to us of any share repurchases. The program may be modified, suspended or discontinued at any time, and any future announcement of a termination of the program could result in a decrease in the price of our Class A common stock.

Certain provisions in our charter documents and under Delaware law could make an acquisition of our company more difficult, limit attempts by our stockholders to replace or remove members of our Board of Directors or current management and may adversely affect the market price of our securities.

Our amended and restated certificate of incorporation and amended and restated bylaws contain provisions that could delay or prevent a change in control of our company. These provisions could also make it difficult for stockholders to elect directors that are not nominated by the current members of our Board of Directors or take other corporate actions, including effecting changes in our management. These provisions include, among other things, the ability of our Board of Directors to issue preferred stock without stockholder approval, restrictions on stockholder action by written consent and the calling of special meetings, advance notice requirements for stockholder nominations and proposals, limitations on the ability of stockholders to fill Board vacancies, and other provisions that may discourage, delay or prevent a change in control transaction or changes in the composition of our Board of Directors or management.

In addition, as a Delaware corporation, we are subject to Section 203 of the Delaware General Corporation Law. Section 203 generally restricts certain business combinations with stockholders owning 15% or more of our outstanding voting stock for a specified period of time, subject to certain exceptions. These provisions could discourage, delay or prevent transactions that stockholders may consider favorable, reduce the market's willingness to pay a premium for our securities, and limit stockholders' ability to influence corporate matters. This team contributes to the development of policies, monitors evolving risks, manages the overall cybersecurity and privacy programs, and reports on these and related topics to our Board's Security and Privacy Committee.

46


Our amended and restated bylaws designate the Court of Chancery of the State of Delaware and, to the extent enforceable, the federal district courts of the United States of America as the exclusive forums for certain disputes between us and our stockholders, which will restrict our stockholders’ ability to choose the judicial forum for disputes with us or our directors, officers, or employees.

Our amended and restated bylaws provide that the Court of Chancery of the State of Delaware is the exclusive forum for certain actions and proceedings under Delaware law, including derivative actions, fiduciary duty claims, claims arising under the Delaware General Corporation Law, our certificate of incorporation or bylaws, and other claims governed by the internal affairs doctrine. This choice of forum provision does not apply to suits brought to enforce a duty or liability created by the Exchange Act or any other claim for which the federal courts have exclusive jurisdiction. Our amended and restated bylaws provide that the federal district courts of the United States of America will be the exclusive forum for resolving any complaint asserting a cause of action arising under the Securities Act. A stockholder may nevertheless seek to bring a claim in a venue other than those designated in the exclusive forum provisions. There can be no assurance that the provisions will be enforced by a court in those other jurisdictions. These choice of forum provisions may limit a stockholder’s ability to bring a claim in a judicial forum that it finds favorable for disputes with us or our directors, officers, or other employees.These choice of forum provisions may limit a stockholder’s ability to bring a claim in a judicial forum that it finds favorable for disputes with us or our directors, officers, or other employees. If a court were to find either provision in our amended and restated bylaws to be inapplicable or unenforceable, we may incur additional costs associated with resolving the dispute in other jurisdictions, which could harm our business. If a court were to find either exclusive-forum provision in our amended and restated bylaws to be inapplicable or unenforceable in an action, we may incur additional costs associated with resolving the dispute in other jurisdictions, which could seriously harm our business.

We do not intend to pay dividends in the foreseeable future. As a result, your ability to achieve a return on your investment will depend on appreciation in the price of our Class A common stock.

We have never declared or paid any cash dividends on our Class A common stock. We do not anticipate paying any dividends on our Class A common stock in the foreseeable future. Any determination to pay dividends in the future will be at the discretion of our Board of Directors. Accordingly, investors must rely on sales of their Class A common stock after price appreciation, which may never occur, as the only way to realize any future gains on their investments.

General Risk Factors

Our business is subject to the risks of natural disasters (including extreme weather), pandemics, man-made problems, and other similar events that may be outside of our control.

Significant natural disasters (such as earthquakes, fires, floods, and extreme weather), man-made problems (such as significant power outages, security breaches, acts of terrorism or war, civil unrest, or geopolitical turmoil), and other similar events that may be outside of our control could have an adverse impact on our business and operating results. For example, despite the implementation of network security measures, our networks also may be vulnerable to computer viruses, break-ins and similar disruptions from unauthorized tampering with our solutions. Further, both our corporate headquarters and our OEM and contract manufacturer are located in the San Francisco Bay Area, a region known for seismic activity. Further, both our corporate headquarters and our contract manufacturer are located in the San Francisco Bay Area, a region known for seismic activity. In addition, natural disasters (including extreme weather) and man-made problems could cause disruptions in our or our end customers’ or channel partners’ businesses, our suppliers’ and manufacturers’ operations or the global economy as a whole. Epidemics, pandemics such as the COVID-19 pandemic, other outbreaks of novel diseases or other major public health concerns could also cause disruptions in our or our end customers’ or channel partners’ businesses, our supply chain, our suppliers’ and manufacturers’ operations, or the global economy as a whole. We also rely on IT systems to communicate among our workforce and with third parties. Any disruption to our communications, whether caused by a natural disaster or by man-made problems, such as power disruptions, could adversely affect our business. To the extent that any such disruptions result in delays or cancellations of orders or impede our suppliers’ or our manufacturers’ ability to timely deliver our solutions and product components, or the deployment of our solutions, our business, operating results and financial condition would be adversely affected. Our business interruption insurance may not adequately cover our losses in the event of a significant disruption in our business.

47


We may further expand through acquisitions of, or investments in, other companies (or vice versa through divestitures), each of which may divert our management’s attention, resulting in additional dilution to our stockholders and consumption of resources that are necessary to sustain and grow our business.

Our business strategy may, from time to time, include acquiring other complementary products, technologies or businesses or divesting certain products. We also may enter into relationships with other businesses in order to expand our solutions, which could involve preferred or exclusive licenses, additional channels of distribution or discount pricing or investments in other companies. Negotiating these transactions can be time-consuming, difficult and expensive, and our ability to close these transactions may be subject to third-party approvals, such as government regulatory approvals, beyond our control. Consequently, we cannot assure that these transactions, once undertaken and announced, will close. Consequently, we can make no assurance that these transactions, once undertaken and announced, will close. Acquisitions, divestitures or investments may result in unforeseen expenditures and operating and integration difficulties, especially if they are more complex in structure and scope, including due to the geographic location of the acquired company. In particular, we may encounter difficulties assimilating or integrating the businesses, technologies, products, personnel, or operations of companies that we may acquire, particularly if the key personnel of the acquired business choose not to work for us. We may have difficulty retaining the customers of any acquired business or the acquired technologies or research and development expectations may prove unsuccessful.

Acquisitions or divestitures may also disrupt our ongoing business, divert our resources, require significant management attention that would otherwise be available for development of our business, and may be viewed negatively by our end customers, investors or securities analysts. We may not successfully evaluate or utilize the acquired technology or personnel, or accurately forecast the financial impact of an acquisition or divestiture transaction, including accounting charges. Any acquisition or investment could expose us to unknown liabilities and risks, and we may incur additional costs and expenses necessary to address an acquired company’s failure to comply with laws and governmental rules and regulations. Moreover, we cannot assure you that the anticipated benefits of any acquisition or investment would be realized in a timely manner, if at all, or that we would not be exposed to unknown liabilities. In connection with these types of transactions, we may issue additional equity securities that would dilute our stockholders, use cash that we may need in the future to operate our business, incur debt on terms unfavorable to us or that we are unable to repay, incur large charges or substantial liabilities, encounter difficulties integrating diverse business cultures, and become subject to adverse tax consequences, substantial depreciation or deferred compensation charges. These challenges related to acquisitions, divestitures or investments could adversely affect our business, operating results, financial condition, and prospects.

We are exposed to fluctuations in currency exchange rates, which could negatively affect our operating results.

Our sales contracts are denominated in U.S. dollars; therefore, substantially all of our revenue is not subject to foreign currency risk. However, any strengthening of the U.S. dollar relative to foreign currencies could increase the effective cost of our solutions for customers outside the United States, which may adversely affect our financial condition and operating results. An increasing portion of our operating expenses is incurred outside the United States and denominated in foreign currencies, including the Euro, Pound Sterling, and Indian Rupee. We also have expenses in other currencies, which are smaller in magnitude but still subject to currency fluctuations. As a result, our total expense base is exposed to foreign exchange volatility. In particular, ongoing geopolitical instability and divergent fiscal and monetary policies across regions have caused, and may continue to cause, significant exchange rate volatility for the foreseeable future. If our exposure to foreign currency fluctuations continues to grow and we are unable to effectively hedge against this risk, our operating results could be negatively impacted. Additionally, such fluctuations may impair our ability to accurately forecast financial performance, particularly with respect to operating expenses and margins. To date, we have not entered into any hedging arrangements or used derivative instruments to manage foreign currency risk. We continue to monitor our exposure and evaluate the potential benefits of implementing a hedging program.

48


Our marketable securities portfolio is subject to credit, liquidity, market, and interest rate risks that could cause its value to decline significantly and materially adversely affect our business, financial condition, results of operations, and prospects.

We maintain a portfolio of marketable securities through a professional investment advisor. The investments in our portfolio are subject to credit, liquidity, market-price, and interest-rate risks that could materially and adversely affect our business, financial condition, results of operations, and prospects. Under our corporate investment policy, we seek to preserve principal, maintain liquidity, avoid excessive credit concentrations, and capture a market rate of return. However, the portfolio’s value may decline due to changes in interest rates, instability in the global financial markets that reduces the liquidity of securities in our portfolio, and other factors. However, the portfolio’s value may decline due to changes in interest rates, instability in the global financial markets that reduces the liquidity of securities in our portfolio, and other factors, including unexpected or unprecedented events such as health epidemics or pandemics. Even with diversification and ongoing risk-profile monitoring, we could experience significant losses or reduced liquidity. If we increase our holdings in these securities, our exposure to such risks would grow, potentially exacerbating any adverse impact.

49


Item 1B. Unresolved Staff Comments

Not Applicable.

Item 1C. Cybersecurity

Cybersecurity is an important component of our overall enterprise risk management strategy. We are committed to protecting our information systems and data from a wide range of cybersecurity threats, including operational risks, intellectual property theft, fraud, extortion, privacy violations, legal risks, and reputational damage. Our approach integrates comprehensive processes and technologies designed to identify, assess, and mitigate these risks.

Risk Management and Strategy

Enterprise Risk Management Integration: Our cybersecurity program is integrated into our broader enterprise risk management program ("ERM"). This integration is designed to ensure that cybersecurity risks, including the cybersecurity risks associated with AI, are evaluated alongside other risks to the organization as part of our overall risk management framework and strategy. Our ERM framework is periodically refreshed and involves collaboration with subject matter experts to assess the severity of potential cybersecurity threats and develop appropriate mitigation strategies.
Cybersecurity Processes: We employ a multi-faceted approach to cybersecurity:
Security and Privacy Reviews: Regular reviews of new features, software, and vendors help us work to identify and address potential risks before they impact our systems.
Security Development Lifecycle: Our internal software development lifecycle process is designed to build our products in part relying upon industry-standard practices and third-party tools and services to test our code and bundled third-party libraries for known security misconfigurations and errors.
Vulnerability Management: We operate a robust vulnerability management program designed to identify and address hardware and software vulnerabilities proactively.
Network and System Monitoring: Our systems are monitored using a range of tools designed to detect suspicious activities and potential breaches in real time.
Threat Intelligence Program: Our threat intelligence program models and researches potential adversaries, enhancing our preparedness against emerging threats.
Monitoring and Mitigation of AI-Enhanced Threats: As AI and machine learning capabilities mature, the cybersecurity threat landscape is evolving to include attacks that may be enhanced or facilitated by AI. As part of our cybersecurity program, we monitor this evolving threat landscape and evaluate protective measures intended to improve our ability to detect, prevent, triage, and respond to AI-enhanced threats.
Training and Simulations: We regularly conduct training and simulations designed to ensure our teams are prepared for a variety of cybersecurity scenarios.
Security Ecosystem: We routinely and regularly engage with consultants, assessors, auditors, and other expert third parties to help us in our understanding, discovery, and response to risks based on their growing impact or likelihood.

50


Frameworks and Standards: Our cybersecurity practices are designed with reference to industry-standard frameworks, including those from the International Organization for Standardization and the National Institute of Standards and Technology and other internationally recognized standards, which can be found here: https://www.nutanix.com/trust/compliance-and-certifications, which link is included as an inactive reference and the content of which is not incorporated by reference into this Annual Report on Form 10-K. We continually work to improve our security controls based on these standards and industry best practices.
Incident Response and Recovery: We have established a comprehensive Privacy and Cybersecurity Incident Response Program to manage and respond to cybersecurity incidents. This program includes processes for triaging, assessing, escalating, containing, investigating, and remediating incidents. We also maintain procedures to comply with legal obligations and mitigate reputational damage. Regular tabletop exercises help us test and strengthen our incident response capabilities. We also have an external bug bounty program to identify and address vulnerabilities before they can be exploited.
Vendor Risk Management: Our vendor risk management program is designed to mitigate risks associated with third-party service providers. This program includes pre-engagement diligence, contractual security, privacy, and AI-related data protection provisions, and ongoing monitoring of third-party compliance with our data protection requirements.

Information on the cybersecurity risks we face is discussed in Part I, Item 1A, “Risk Factors.” We believe that risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected us, including our business strategy, results of operations or financial condition. However, we remain subject to risks from unknown or future cybersecurity threats that could materially affect us, including our business strategy, results of operations or financial condition. We remain vigilant and continue to invest in security technologies and practices to safeguard our systems.

Governance

Board and Committee Oversight: Our Board of Directors (our "Board") plays an active role in overseeing cybersecurity risks. Our Board’s Security and Privacy Committee, which is composed entirely of independent directors, assists our Board in its oversight of our management of technology and information security risks and compliance with data protection and privacy laws. This committee regularly reviews our cybersecurity programs and policies as part of our overall risk management and business strategy discussions, and receives regular updates from management on our data security posture, third-party assessments, and progress toward risk-mitigation goals. The committee also reviews incident response plans and any significant cybersecurity threats or incidents. Our Board's Security and Privacy Committee reports quarterly to our Board regarding its activities in overseeing cybersecurity, AI, data protection and privacy risk management.
Management's Role: Our Chief Information Security Officer ("CISO") partners with a cross-functional leadership team including the Chief Product Security Officer ("CPSO"), Chief Information and Digital Officer ("CIDO"), and Legal and Privacy Counsel, to develop and implement our overall cybersecurity strategy. This team contributes to the development of policies, monitors evolving risks, manages the overall cybersecurity and privacy programs, and reports on these and related topics to our Board's Security and Privacy Committee. Our CISO has served in various roles in information technology and information security for over 25 years, including previously serving as Chief Information Security Officer at two other companies. He holds an undergraduate degree in computer science. Our CPSO also previously held the role at Nutanix and served as the Chief Information Security Officer at Intuit. He holds a PhD in computer science.

51


Incident Management: Our Enterprise and Product Security Team manages our incident response efforts. This team assesses incidents' severity, coordinates the response, and communicates with relevant stakeholders. Our Security and Privacy Management Team, including, as appropriate, our CISO, CIDO, and CPSO, provides additional expertise and support as needed.

Recently Filed
Click on a ticker to see risk factors
Ticker * File Date
NTNX 10 hours ago
FEAM 13 hours ago
UPXI 14 hours ago
PZG 14 hours ago
VBNB 15 hours ago
ALMU 1 day, 13 hours ago
EPM 1 day, 14 hours ago
MBBC 1 day, 23 hours ago
WSBK 2 days, 13 hours ago
KARX 2 days, 13 hours ago
TMGI 2 days, 14 hours ago
ISPR 2 days, 14 hours ago
LDXC 2 days, 14 hours ago
LGVT 2 days, 16 hours ago
FPS 3 days ago
LRDC 3 days, 13 hours ago
RLGT 3 days, 13 hours ago
WEWA 3 days, 15 hours ago
BNTC 3 days, 15 hours ago
HAIN 3 days, 15 hours ago
VRDR 3 days, 22 hours ago
ABAT 3 days, 22 hours ago
UNFI 6 days, 9 hours ago
SMBC 6 days, 14 hours ago
GWRE 6 days, 14 hours ago
HWKE 6 days, 15 hours ago
RSSS 6 days, 15 hours ago
FLWS 6 days, 22 hours ago
ECXJ 6 days, 23 hours ago
LPTH 1 week ago
PLUR 1 week ago
EGAN 1 week ago
IBEX 1 week ago
PANW 1 week ago
AENT 1 week ago
CBKM 1 week ago
MCFT 1 week ago
GOLD 1 week, 1 day ago
AUSI 1 week, 1 day ago
LSAK 1 week, 1 day ago
INM 1 week, 1 day ago
INTU 1 week, 1 day ago
GCBC 1 week, 1 day ago
INNV 1 week, 2 days ago
EVI 1 week, 2 days ago
PAXH 1 week, 6 days ago
TWIN 1 week, 6 days ago
BCCG 1 week, 6 days ago
PKTX 2 weeks ago
MTRX 2 weeks ago

OTHER DATASETS

House Trading

Dashboard

Corporate Flights

Dashboard

App Ratings

Dashboard