RBRK 10-K & 10-Q changes, risk factors and insider trading
Rubrik, Inc. · NYSE · Services-Prepackaged Software · CIK 1943896 · All filings on SEC.gov
At a glance
What changed in the latest 10-K
Risk Factors
New heading “The limited number of contract manufacturers and original equipment manufacturers that produce commodity servers that are compatible with our solutions are susceptible to supply chain disruptions and have recently experienced shortages of key components for their servers, which may adversely affect our ability to accurately forecast demand for these commodity servers or successfully manage the relationship with such manufacturers, and could negatively impact demand for our offerings, and adversely affect our business and financial results.”
New heading “Servicing our debt may require a significant amount of cash. We may not have sufficient cash flow from our business to pay our indebtedness.”
New heading “We may not have enough available cash or the ability to raise the funds necessary to pay cash upon conversion of the Notes or to repurchase the Notes upon a fundamental change.”
New heading “The capped call transactions may affect the market price of the Notes and our Class A common stock.”
New heading “We are subject to counterparty risk with respect to the capped call transactions.”
Removed heading “There are a limited number of contract manufacturers and original equipment manufacturers of commodity servers that are compatible with our data security solutions, and failure to accurately forecast demand for these commodity servers or successfully manage the relationship with such manufacturers could negatively impact the ability to sell our offerings.”
Removed heading “The terms of the financing documents governing our term loan and credit facilities restrict our current and future operations, particularly our ability to respond to changes or to take certain actions.”
Removed heading “We are an “emerging growth company,” and we cannot be certain if the reduced reporting and disclosure requirements applicable to emerging growth companies will make our Class A common stock less attractive to investors.”
Largest changes
“Additionally, the U.S. Department of Justice issued a rule entitled the Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons, which places additional restriction on certain data transactions involving countries of concern (e.g., China, Russia, Iran) and covered persons that may impact certain business activities such as vendor engagements, sale or sharing of data, employment of certain individuals, and investor agreements. Violations of the rule could lead to significant civil and criminal fines and penalties.”see in full comparison
“Our ability to make scheduled payments of the principal of, to pay special interest, if any, on or to refinance the Notes, depends on our future performance, which is subject to economic, financial, competitive and other factors beyond our control. Our business may not continue to generate sufficient cash flow from operations to service our debt and make necessary capital expenditures. …”see in full comparison
We usesee in full comparisongenerativeAI tools in our business, including generative AI and agentic AI, and we expect to usegenerativeAI tools in the future, including to generate code and other materials incorporated into our products, proprietary software, and systems, and for other internal and externaluses.uses,Generativeand we are making investments to expand our generative and agentic AIreferscapabilities,toincludingdeep-learningrecentmodelsandthatfuturecanproductgenerate new data,offerings such astext,Rubrikimages,AgentandCloud,otherwhichcontent,isbydesignedanalyzingtoandaccelerateemulatingenterpriseexistingAIdata.agent deployments. Advanced generative AI tools, which may produce content indistinguishable from that generated by humans, are a relatively novel development, with benefits, risks, and liabilities still unknown. Recent decisions of governmental entities and courts (such as the U.S. Copyright Office, U.S. Patent and Trademark Office, and U.S. Court of Appeals for the Federal Circuit) interpret U.S. copyright and patent law as limited to protecting works and inventions created by human authors and inventors, respectively. We are therefore unlikely to be able to obtain U.S. copyright or patent protection for works or inventions wholly created by a generative AI tool, and our ability to obtain U.S. copyright and patent protection for source code, text, images, inventions, or other materials, which are developed with some use of generative AI tools, may be limited, if available at all. Likewise, the availability of such IP protections in other countries is unclear. In addition, we may have little or no insight into and no control over the content and materials used by vendors and model providers to train these generative AItools.tools, or that otherwise use or incorporate these generative AI tools into their own offerings. There is ongoing litigation over whether the use of copyrighted materials to train the AI models used in these tools is lawful, and the impact of decisions in such litigation on our use of generative AI tools is unknown. Furthermore, our vendors who use generative and agentic AI tools in their own offerings may not meet existing or rapidly evolving regulatory or industry standards, including with respect to the rights of others, privacy and data security. Additionally, our use of open-source and other third-party generative and agentic AItoolstools, including to develop source code, text, images, inventions, or othermaterialsmaterials, may expose us to greater risks than utilizing contracted human developers, asthird-party generativesuch AIvendorstools typically do notprovidecome with warranties or indemnities with respect to the output generated by suchgenerativeAI tools, and generative and agentic AI tools may also hallucinate, providing erroneous outputthatorappearsmakingcorrecterroneousbut is erroneous.decisions. Furthermore, somegenerativeAI tools may be offered under terms that do not protect the confidentiality of the prompts or inputs that users submit to such tools and may use prompts or inputs to train shared AI models, potentially resulting in third-party users receiving outputs containing information from prompts or inputs (including confidential, competitive, proprietary, or personal data) that we submitted to the tool. The disclosure and use of personal data in AI technologies is also subject to various privacy laws and other privacy obligations. Prior to implementingaan AI tool (including generative AItool,tools), our AI governance committee (including leaders from our Engineering, Product, Legal, and Information Security teams) performs an analysis and review oftheeachtool,AI tool for which pre-approval is required according to our policies, including evaluation of potential legal, security, and business risks and steps that can be taken to mitigate any such risks. The selection criteria and analysis include consideration of how use of thegenerativeAI tool could raise issues relating to confidential information, personal data and privacy, customer data and contractual obligations, open source software, copyright and other intellectual property rights, transparency, output accuracy and reliability, and security.Additionally, while we employ practices designed to evaluate, track, and mitigate risk around our use of third-party generative AI tools, our use of such tools may inadvertently violate a third party’s rights, be non-compliant with the applicable terms of use or our other legal obligations, or result in a security or privacy risk or data leakage. Our use of this technology could result in additional compliance costs, regulatory investigations and actions, and lawsuits. For example, we may face claims from third parties claiming infringement of their intellectual property rights or mandatory compliance with open-source software or other license terms with respect to software or other materials or content we believed to be available for use and not subject to license terms or other third-party proprietary rights. Any of these claims could result in legal proceedings and could require us to purchase costly licenses, comply with the requirements of third-party licenses, or limit or cease using the implicated software or other materials or content, unless and until we can re-engineer such software, materials, or content to avoid infringement or change the use of, or remove, the implicated third-party materials, which could reduce or eliminate the value of our technologies and services. Our use of generative AI tools to generate code may also present additional security risks because the generated source code may contain security vulnerabilities. Additionally, the vendors of these generative AI tools may fail to comply with their contractual obligations to us regarding the confidentiality or security of any data or other inputs provided to such vendor or outputs generated by their generative AI tools. Our sensitive information or that of our customers could be leaked, disclosed, or revealed as a result of or in connection with our employees’, personnel’s, or vendors’ use of third-party generative AI technologies.
“A limited number of Manufacturers produce commodity servers that are compatible with our solutions. We do not own or operate any manufacturing facilities and rely on these Manufacturers for such products. These Manufacturers manage the supply chain for these products and, alone or together with us or our distributors and resellers ("Channel Partners"), negotiate component costs. Our reliance on Manufacturers and Channel Partners reduces our control over the assembly process, quality assurance, production costs, and product supply. …”see in full comparison
“A limited number of Manufacturers produce commodity servers that are compatible with our data security solutions. We do not own or operate any manufacturing facilities and rely on these Manufacturers for such products. These Manufacturers manage the supply chain for these products and, alone or together with us or our distributors and resellers ("Channel Partners"), negotiate component costs. Our reliance on Manufacturers and Channel Partners reduces our control over the assembly process, quality assurance, production costs, and product supply. …”see in full comparison
“Additionally, while we employ practices designed to evaluate, track, and mitigate risk around our use of third-party AI tools, our practices may not be error free, and our use of such tools may inadvertently violate a third party’s rights, be non-compliant with the applicable terms of use or our other legal obligations, or result in a security or privacy risk or data leakage. Our use of AI technology could result in additional compliance costs, regulatory investigations and actions, and lawsuits. …”see in full comparison
Full comparison: every changed paragraph (188)
Our revenue was $1.32 billion, $886.5 million, $627.9 million and $599.8$627.9 million for the fiscal years ended January 31, 2025,2026, 20242025 and 2023,2024, respectively. You should not rely on the revenue growth of any prior quarterly or annual period as an indication of our future performance. Even if our revenue continues to increase, we expect that our revenue growth rate will fluctuate in the future as a result of a variety of factors,factors. includingWhile we have largely completed both the sales of Rubrik-branded Appliances transitioning from us to our contract manufacturers in fiscal 2025 and the transition for new and existing customers to sales of RubrikRSC Securityin Cloudfiscal 2026, we expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits ("RSC"),which are customer options that are accounted for whichas anmaterial increasingrights) amountthrough fiscal 2027, although we expect the benefits to significantly reduce sequentially. These business transitions cause fluctuations to our total revenue growth and limit the comparability of our software revenue willwith bepast recognized ratably.performance.
•expand the features and functionality of our data security products as well as increase the amount of data sources protected across enterprise, cloud, SaaS, unstructured data, and SaaSidentity applicationsproviders;
•securely deploy generative AI while delivering exceptional accuracy and efficiency using agentic applications;
We may not successfully accomplish any of these objectives, and as a result, it is difficult for us to forecast our future results of operations. If the assumptions that we use to plan our business are incorrect or if we are unable to maintain consistent revenue or revenue growth, our stock price could be volatile and we may not be able to achieve and maintain profitability. You should not rely on our revenue for any prior quarterly or annual periods as any indication of our future revenue or revenue growth.
•our use and development of AI technologies and tools;
If the market for data security and AI solutions does not grow, our ability to grow our business and our results of operations may be adversely affected.
We believe our future success will depend in large part on the growth, if any, in the market for data security and AI solutions. Traditionally, the cybersecurity industry has been focused on securing information technology infrastructure to prevent, detect, and investigate cyberattacks. Our platform brings a new approach to cybersecurity, which involves protecting our customers’ data across enterprise, cloud, SaaS, unstructured data, and SaaSidentity applications,providers, observing the data itself to proactively identify emergent threats, remediating data security threats, and recovering protected data following a cybersecurity event.event, as well as helping customers manage risks associated with AI agents. The market for data security and AI solutions, such as our platform and data security products, is at an early stage and rapidly evolving. As such, it is difficult to predict this market’s potential growth, if any, customer adoption and retention rates, customer demand for data security platforms, or the success of competitive products. In the past, customer adoption of our platform and data security products has been driven by the need for data resilience due to increasing ransomware activity. We do not know whether the trends of increasing ransomware activity, or of increasing adoption of our platform and data security products such as ours that we have experienced in the past, will continue in the future. Any expansion in this market depends on a number of factors, including the cost, performance, and perceived value associated with our platform and data security products and similar solutions of our competitors, including preference to manage security with existing infrastructure security tools alone, rather than investing in a platform based data security solution. The markets for some of our solutions are new, unproven, and evolving, and our future success depends on growth and expansion of these markets. If our platform and data security products do not achieve widespread adoption or there is a reduction in demand for our platform and data security products due to a lack of customer acceptance, technological challenges, competing products or solutions, privacy concerns, decreases in corporate spending, weakening economic conditions, or otherwise, it could result in early terminations, reduced customer retention rates, or decreased revenue, any of which would adversely affect our business, financial condition, and results of operations. You should consider our business and growth prospects in light of the risks and difficulties we encounter in this new and evolving market.
We have a limited operating history, particularly with respect to our offeringofferings of RSC,RSC and RAC, which makes it difficult to forecast our future results of operations.
Although we were founded in December 2013, we only began offering our products and services in the fiscal year ended January 31, 2016, and we began offering RSC as a cloud native SaaS solution in fiscal 2023, and introduced the RAC suite in fiscal 2026. As a result of our limited operating history, our ability to accurately forecast our future results of operations is limited and subject to a number of uncertainties, including our ability to plan for and forecast future growth. Our historical revenue growth should not be considered indicative of our future performance. Further, in future periods, we expect our revenue growth to fluctuate, slow, and possibly decline for a number of reasons, including mix shifts in our platform and data security products. In future periods, our revenue growth may fluctuate, slow or decline due to a number of factors, including changes in product mix. While we have largely completed both the transition of sales of Rubrik-branded Appliances from us to our contract manufacturers in fiscal 2025 and the transition for new and existing customers to sales of RSC in fiscal 2026, we expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits (which are customer options that are accounted for as material rights) through fiscal 2027, although we expect the benefits to significantly reduce sequentially. These business transitions cause fluctuations to our total revenue growth and limit the comparability of our revenue with past performance.
In addition, we operate in a new market for data security and AI solutions, and as such we have encountered, and will continue to encounter, risks and uncertainties frequently experienced by growing companies in new and rapidly changing markets, such as the risks and uncertainties described throughout this section. Further, our business and growth strategies are also dependent on continued development, and implementation and integration of our AI offerings and initiatives, including RAC, which is designed to accelerate enterprise AI agent deployments. While we have invested significantly in our AI offerings and initiatives and intend to continue doing so in the future, AI technology is expected to continue to rapidly advance. We may not be successful in obtaining and maintaining market acceptance of our AI offerings and initiatives, including RAC, particularly as competitive technologies and solutions are introduced. Any of these outcomes could harm our business, results of operations, and financial condition.
Although we were founded in December 2013, we only began offering our products and services in the fiscal year ended January 31, 2016, and we began offering RSC as a cloud native SaaS solution in fiscal 2023. As a result of our limited operating history, our ability to accurately forecast our future results of operations is limited and subject to a number of uncertainties, including our ability to plan for and forecast future growth. Our historical revenue growth should not be considered indicative of our future performance. Further, in future periods, we expect our revenue growth to fluctuate, slow, and possibly decline for a number of reasons, including mix shifts in our platform and data security products, as well as the impact on our revenue recognition resulting from our transition from selling our products primarily on the basis of subscription term-based licenses to SaaS subscriptions. The timing for this transition and related implications on our revenue recognition and trends will depend on our ability to transition existing customers to RSC in a timely manner. We are implementing certain initiatives to accelerate our existing customers’ migration to RSC as part of our business transition to SaaS, which include enforcement of migration deadlines. These initiatives may be perceived negatively by our customers. For example, these initiatives may require customers to prioritize preparation for their migration over other organizational needs, potentially resulting in diversion of resources. For certain existing customers, the perceived benefits from undertaking the migration may be outweighed by the anticipated time and effort required to prepare for and execute the migration, resulting in potential delays in customers’ transition to RSC. We expect these customers may consume our platform and products through a mix of RSC and a transitional license for Cloud Data Management ("RCDM-T"), for an extended period of time, resulting in the continued recognition of a portion of the associated revenue for some of these customers upfront at the time we transfer control of the license to the customer. Conversely, if some or all of these customers complete their transition to RSC sooner than we expect, less revenue would be recognized upfront during this period, which could cause our revenue to be lower than our estimates or forecasts or even result in a decrease in our revenue growth rates. Any of these factors could result in continued fluctuations in our revenue growth and adversely impact our ability to accurately predict our future revenue.
In addition, we operate in a new market for data security solutions, and as such we have encountered, and will continue to encounter, risks and uncertainties frequently experienced by growing companies in new and rapidly changing markets, such as the risks and uncertainties described throughout this section.
To expand our customer base, we need to convince organizations to allocate a portion of their discretionary budgets to purchase our platform and data security products. Our sales efforts often involve educating organizations about the uses and benefits of our data security and AI solutions. We may have difficulty convincing organizations of the value of adopting our data security solutions. Even if we are successful in convincing organizations that a platform like ours is critical to secure their data, they may not decide to purchase our data security solutions for a variety of reasons, some of which are out of our control. For example, any deterioration in general economic conditions has in the past caused, and may in the future cause, our current and prospective customers to delay or cut their overall security and IT operations spending. Macroeconomic concerns, customer financial difficulties, and constrained spending on security and IT operations may result in decreased revenue and adversely affect our financial condition and results of operations. In particular, uncertainty related to recent global tariffs may impact customer adoption and use of our offerings and revenue from sales of our products and services. Additionally, if the incidence of cyberattacks were to decline, or enterprises or governments perceive that the general level of cyberattacks has declined, our ability to attract new customers could be adversely affected. We may face additional difficulties in attracting organizations that use legacy data management products to purchase our data security products if they believe that these legacy products are more cost-effective or provide a level of IT security that is sufficient to meet their needs. Furthermore, the use of our data security products to manage data security, movement, and restoration across data centers is relatively new, and if we are unable to convince organizations of the benefits of our data security products, then our business, financial condition, and results of operations could be adversely impacted.
We have experienced net losses in each period since inception. We generated net losses of $(1,154.8348.8) million, $(354.21.15) millionbillion and $(277.7354.2) million for the fiscal years ended January 31, 2025,2026, 20242025 and 2023,2024, respectively. As of January 31, 20252026 and January 31, 2024,2025, we had an accumulated deficit of $(2,837.33.19) millionbillion and $(1,682.52.84) million,billion, respectively. While we have experienced rapid revenue growth in recent periods, we are not certain whether or when we will obtain a high enough volume of sales to achieve or maintain profitability in the future. In particular, as we expand the availability of our platform, increase our ability to secure data across multiple different sources, and add more capabilities, our ability to achieve and maintain profitability will be highly dependent on our ability to successfully market our platform and data security products to new and existing customers. We also expect our costs and expenses to increase in future periods, which could negatively affect our future results of operations if our revenue does not increase. In particular, we intend to continue to expend significant funds to further develop our data security products, including by introducing new features and functionality and securing additional applications, and to expand our sales, marketing, and services teams to drive new customer adoption, expand the use of our data security products by existing customers, support international expansion, and implement additional systems and processes to effectively scale operations. We will also face increased compliance costs associated with growth, the planned expansion of our customer base and pipeline, international expansion, and being a public company. In addition, our data security and AI solutions operate on a public cloud infrastructure provided by third-party vendors, including Google Cloud ("GCP"), Microsoft Azure ("Azure"), and Amazon Web Services ("AWS"), and our costs and gross margins are significantly influenced by the prices we are able to negotiate with these public cloud providers. To the extent we are able to drive adoption of our platform and data security products, we may incur increased costs related to our public cloud contracts, which would negatively impact our gross margins. Our efforts to grow our business may be costlier than we expect, or the rate of our growth in revenue may be slower than we expect, and we may not be able to increase our revenue enough to offset our increased operating expenses. In addition, our efforts and investments to implement systems and processes to scale operations may not be sufficient or may not be appropriately executed. As a result, we may incur significant losses in the future for a number of reasons, including the other risks described herein, unforeseen expenses, difficulties, complications, or delays, and other unknown events. If we are unable to achieve and sustain profitability, the value of our business and Class A common stock may significantly decrease.
Furthermore, we have historically sold our products to customers as perpetual licenses with associated maintenance contracts or as subscription term-based licenses with associated support, and with respect to the latter, we recognized a portion of the revenue upfront at the time we transferred control of the subscription term-based license to the customer and deferred the remainder. MovingWe forward, we expect thathave substantially allcompleted our transition to offering our platform primarily through SaaS subscriptions, and a significant majority of our new and existing customers willhave continue to adoptadopted RSC primarily on a SaaS subscription basis. As of the end of fiscal 2024,2026, RSCSaaS subscriptions represented a majority of our total revenue. In addition, weWe have historicallyalso soldlargely Rubrik-branded Appliances to help our customers secure their enterprise data. Incompleted the third quartertransition of fiscal 2023, we began transitioning the salesales of Rubrik-branded Appliances from us to our contract manufacturers,manufacturers in fiscal 2025. We expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits (which are customer options that are accounted for as material rights) through fiscal 2027, although we expect the benefits to significantly reduce sequentially. These business transitions may continue to cause fluctuations to our total revenue growth and as a result,limit the amountcomparability of our revenue wewith recognizepast fromperformance. salesIn ofaddition, Rubrik-brandedthe Appliancesstock-based compensation expense related to our RSUs has resulted in and will continue to declineresult overin time.significant Weincreases expectin theseour transitionsexpenses in future periods, which may negatively impact our ability to adverselyachieve affect our revenue as well as our profitability through the fiscal year ending January 31, 2027. However, this timing will depend in part on when a substantial portion of our existing customers complete their transition to RSC.profitability.
In addition, following the completion of our IPO, the stock-based compensation expense related to our RSUs has resulted in and will continue to result in significant increases in our expenses in future periods, which may negatively impact our ability to achieve profitability.
If our customers do not renew their subscriptions for our platform and data security products or expand their subscriptions to increase the amount of data secured, secure new applications, or include new features or capabilities, our results of operations could be harmed.
In order for us to maintain or improve our results of operations, it is important that our customers renew their subscriptions for our data security solutions, add data security or AI products, and increase the volume of their data protected by our datasolutions. securityOur solutions.AI solutions, including RAC, are relatively new, and customer adoption and expansion of these solutions may be uncertain. We expand our commercial purchase relationships with our existing customers as they increase the volume of their data protected by our data security solutions and secure additional applications and workloads. Our customers have no obligation to renew their subscription for our data security solutions after the expiration of their contractual subscription period, which is generally three years, and in the normal course of business, some customers have elected not to renew their subscriptions. In addition, customers may elect to shorten the term of their subscription, select a lower subscription edition, or purchase less capacity. Our customer retention and expansion may also decline or fluctuate as a result of a number of factors, including our customers’ satisfaction with our data security solutions, our pricing, customer prioritization of security, our customers’ spendingsecurity levels,and IT operations spending, our customers’ ability to procure Rubrik-branded Appliances or other compatible third-party commodity servers to implement our data security products, mergers and acquisitions involving our customers, industry developments, competition, changing regulatory environments, and generalmacroeconomic economicuncertainty conditions.related Ourto strategiesrecent global tariffs, the direct and initiativesindirect to accelerate the transition of our existing customers to RSC, even if executed properly by our sales and support teams, may result in customer dissatisfaction, the loss of customers, or reduced usage of our platform, anyimpact of which wouldcontinues harmto our business, financial condition, and results of operations.evolve. Moreover, customers tend to expand their usage of our data security solutions over time as the amount of data they need to protect grows. As a result, strong customer retention over time generally leads to a higher degree of usage of our data security solutions. Therefore, a decline in customer retention may have a significant impact on our results of operations, including a decline in our average subscription dollar-based net retention rate, which could cause the price of our Class A common stock to decline or fluctuate. If our efforts to maintain and expand our relationships with our existing customers are not successful, our business, financial condition, and results of operations may suffer.
If our data security solutions fail or do not perform as intended or are perceived to have defects, errors, or vulnerabilities, our brand and reputation will be harmed, which would adversely affect our business and results of operations.
Our data security solutions are complex and, like all software, have in the past contained and may in the future contain undetected defects, errors, or vulnerabilities. From time to time, we identify certain vulnerabilities in our information systems. While we take steps designed to mitigate the risks associated with known vulnerabilities, there can be no assurance that any vulnerability mitigation measures will be effective. Moreover, we may also experience delays in developing and deploying remedial measures and patches designed to address any identified vulnerabilities. Real or perceived defects, errors, or vulnerabilities in our data security solutions, the failure of our data security solutions to secure, observe, and restore our customers’ data, misconfiguration of our data security solutions, the exploitation of any known or unknown vulnerabilities, or the failure of customers to deploy our data security solutions in combination with industry best practices could harm our reputation, result in a loss of, or delay in, market acceptance of our data security solutions, result in a loss of existing or potential customers, and adversely affect our business, financial condition, and results of operations. We are continuing to evolve the features and functionality of our data security products through updates and enhancements, and as we do so, we may inadvertently introduce defects, errors, or vulnerabilities that may not be detected until after deployment by our customers. In addition, implementation or use of our data security solutions that is not correct or as intended may result in adverse consequences such as inadequate performance and disruptions in service. Moreover, if we acquire companies or technologies developed by third parties, difficulties integrating such acquired technologies may result in product flaws or software vulnerabilities.
Additionally, we cannot assure you that our data security solutions will prevent all data loss or other types of data security incidents, especially in light of the rapidly changing security threat landscape that our data security solutions seek to address. Due to a variety of both internal and external factors, our data security solutions could become vulnerable to security incidents (both from intentional attacks and accidental causes) that could cause them to fail to adequately secure or observe data or to restore data in the event of a security incident.
Moreover, our data security solutions are adopted by, and part of the supply chain of, a large and increasing number of organizations worldwide, our solutions have been and may in the future be subject to continued, persistent research and reconnaissance by threat actors in order to discover and exploit weaknesses in our technology that can be exploited. If our data security solutions are compromised, a significant number or, in some instances, all,all of our customers and their data could be adversely affected. The potential liability and associated consequences we could suffer as a result of such a large-scale event could be catastrophic and result in irreparable harm. Since our business is focused on providing data security services to our customers, an actual or perceived security incident affecting our data security solutions would be especially detrimental to our reputation and our business.
Because we can access customer data in certain limited circumstances, such as when providing customer support, and such customer data in some cases may contain personal data or confidential information, a security compromise, or an accidental or intentional misconfiguration or malfunction of our platform, could result in personal data and other confidential information being compromised. IfWe aand high-profileour cyberattackservice occursproviders withhave respectbeen subject to cyberattacks that have occurred in the past and may occur in the future, and our customers or another cloud-based security platform or a third-party cloud provider,other organizations may lose trust in SaaS platforms and associated productssolutions such as ours.
Organizations are increasingly subject to a wide variety of cyberattacks on their networks, systems, and data. If any of our customers experience a cyberattack while using our data security solutions and are unable to secure, observe, or restore their data, such customers could discontinue use of our data security solutions, regardless of whether our data security solutions were adequately deployed, configured, or used to protect the data in the customer’s environment. Real or perceived security incidents involving our customers' networks could cause disruption or damage to their networks or other negative consequences and could result in negative publicity to us, damage to our reputation, and other customer relations issues, any of which may adversely affect our revenue and results of operations.
In addition, errors in our data security solutions could cause system failures, loss of data, or other adverse effects for our customers, which may result in the assertion of warranty and other claims for substantial damages against us. The potential liability and associated consequences we could suffer as a result of such an incident could be catastrophic and cause irreparable harm to our reputation and results of operations. Although our agreements with our customers typically contain provisions that are intended to limit our exposure to such claims, it is possible that these provisions may not be effective or enforceable under the laws of some jurisdictions. While we seek to insure against these types of claims, our insurance policies may not adequately limit our exposure. These claims, even if unsuccessful, could be costly and time consuming to defend and could harm our business, financial condition, results of operations, and cash flows.
Organizations, particularly organizations like ours that provide data security solutions, experience and are subject to a wide variety of attacks on their networks, systems, and endpoints, and techniques used to sabotage or to obtain unauthorized access to networks in which data is stored or through which data is transmitted change frequently. For example, in March 2023, we announced that a malicious third party gained unauthorized access to a limited amount of information in one of our non-production information technology testing environments. In addition, in February 2025, we announced that we observed anomalous activity on a server that contained log files, certain of which were accessed by an unauthorized actor. NeitherThis ofincident thesedid incidentsnot resultedresult in access to data that we secure on behalf of customers or access to our internal code, and there was no disruption to our business or financial systems or to other operations. However, there can be no guarantee that any attack in the future will have a similarly minimal impact, should one occur.
Cyberattacks, malicious internet-based activity, online and offline fraud, and other similar activities threaten the confidentiality, integrity, and availability of our Sensitive Information and information technology systems, and those of the third parties with whom we work. Such threats are prevalent, continuing to rise, increasingly difficult to detect, and come from a variety of sources, including traditional computer "hackers," threat actors, "hacktivists," organized criminal threat actors, personnel (such as through theft, misuse, or accidental disclosure), sophisticated nation states, and nation-state-supported actors. Some actors now engage in and are expected to continue to engage in cyberattacks, including without limitation nation-state actors for geopolitical reasons and in conjunction with military conflicts and defense activities. During times of war and other major conflicts, we and the third parties with whom we work, and our customers may be vulnerable to a heightened risk of these attacks, including retaliatory cyberattacks, that could materially disrupt our systems and operations, supply chain, and ability to produce, sell, and distribute our data security solutions. We and the third parties with whom we work are subject to a variety of evolving threats, including but not limited to social-engineering attacks (including through phishing attacks), malicious code (such as viruses and worms), computer generated or altered fraudulent content (i.e., “deep fakes,” which may be increasingly difficult to identify), malware (including as a result of advanced persistent threat intrusions), denial-of-service attacks, credential stuffing attacks, credential harvesting, personnel misconduct or error, other inadvertent compromises of our systems and data (including those arising from process, coding, or human error), ransomware attacks, supply-chain attacks, software bugs, server malfunctions, software or commodity appliance failures, loss of data or other information technology assets, adware, telecommunications failures, attacks enhanced or facilitated by artificial intelligence ("AI"),AI, and other similar threats.
We employ a shared responsibility model where our customers are responsible for using, configuring and otherwise implementing security measures related to our platform, services and products in a manner that meets applicable cybersecurity standards, complies with laws, and addresses their information security risk. As part of this shared responsibility security model, we make certain security features available to our customers that can be implemented at our customers’ discretion or identify security areas or measures for which our customers are responsible. For example, our customers are responsible for adding and enforcing multi-factor authentication to access their accounts. In certain cases where our customers choose not to implement, or incorrectly implement, such features or measures, misuse our services, or otherwise experience their own vulnerabilities, policy violations, credential exposure or security incidents, even if we are not the cause of customer security issue or incident that may result, our customer relationships reputation, and revenue may be adversely impacted. Furthermore, threat actors may also gain access to other networks and systems after a compromise of our networks and systems. For example, threat actors may use an initial compromise of one part of our environment to gain access to other parts of our environment, or leverage a compromise of our networks or systems to gain access to the networks or systems of third parties with whom we work, such as through phishing or supply chain attacks.
Any of the previously identified vulnerabilities or cybersecurity threats couldhave in the past caused and may in the future cause a security incident or other interruption that could resultresulting in consequences such as unauthorized, unlawful, or accidental acquisition, modification, destruction, loss, alteration, encryption, disclosure of, or access to our Sensitive Information or our information technology systems, or those of the third parties upon whom we rely. A security incident or other interruption could partially or fully disrupt our ability (and that of third parties upon whom we rely) to provide our platform. Additionally, our business depends upon the appropriate and successful implementation of our platform by our customers. If our customers fail to use our platform according to our specifications or are unwilling or unable to deploy such patches we make available for vulnerabilities effectively or in a timely manner, our customers may suffer a security incident or other interruptions on their own systems or other adverse consequences. Even if such an incident is unrelated to our security practices, it could result in our incurring significant economic and operational costs in investigating, remediating, and implementing additional measures to further protect our customers from their own security issues or vulnerabilities and could result in reputational harm.
Certain data privacy and security obligations may require us to implement and maintain specific security measures or industry standard, reasonable security measures to protect our information technology systems and sensitive information. Additionally, applicable data privacy and security obligations have in the past required us and may in the future require us, or we may voluntarily choose, to notify relevant stakeholders, including affected individuals, customers, regulators, and investors, of security incidents, or to implement other requirements, such as providing credit monitoring. Such disclosures, and compliance with such requirements, are costly, and the disclosure or the failure to comply with such requirements could lead to adverse consequences. Though we have expended, and anticipate continuing to expend, significant resources to try to protect against security incidents by implementing technical, administrative, and physical measures designed to protect the privacy and security of data running through our, and our third parties’, systems, it is virtually impossible for us to entirely eliminate the risk of such security incidents or interruptions.
If we (or a third party with whom we workwork, including our suppliers) experience a security incident or are perceived to have experienced a security incident, which has happened in the past, we may experience adverse consequences such as government enforcement actions (for example, investigations, fines, penalties, audits, and inspections); additional reporting requirements and/or oversight; restrictions on processing data (including data about individuals); litigation (including class claims); indemnification obligations; negative publicity; reputational harm; monetary fund diversions; diversion of management attention; interruptions in our operations (including availability of data); financial loss; and other similar harms. Security incidents and attendant material consequences may prevent or cause customers to stop purchasing our data security solutions, deter new customers from purchasing our data security solutions, and negatively impact our ability to grow and operate our business. As a data security company, we could be exposed to additional reputational risks should a security incident occur.
The limited number of contract manufacturers and original equipment manufacturers that produce commodity servers that are compatible with our solutions are susceptible to supply chain disruptions and have recently experienced shortages of key components for their servers, which may adversely affect our ability to accurately forecast demand for these commodity servers or successfully manage the relationship with such manufacturers, and could negatively impact demand for our offerings, and adversely affect our business and financial results.
A limited number of Manufacturers produce commodity servers that are compatible with our solutions. We do not own or operate any manufacturing facilities and rely on these Manufacturers for such products. These Manufacturers manage the supply chain for these products and, alone or together with us or our distributors and resellers ("Channel Partners"), negotiate component costs. Our reliance on Manufacturers and Channel Partners reduces our control over the assembly process, quality assurance, production costs, and product supply. If the relationships with Manufacturers are not properly managed or if Manufacturers experience delays, interruptions, or supply-chain disruptions, including due to international conflicts and geopolitical tensions (such as the imposition of new trade restrictions and tariffs due to escalating tensions, hostilities, or trade disputes), health epidemics or pandemics, new trade laws and regulations, capacity constraints, or quality control problems in their operations, the ability for customers to procure compatible commodity servers could be impaired. For example, key components of the commodity servers that are compatible with our solutions have been, and continue to be, adversely affected by global chip shortages and allocation constraints, in part due to elevated industry demand, which in certain cases have resulted in extended lead times and increased server prices. While we have largely completed the sales of Rubrik-branded Appliances transitioning from us to our contract manufacturers in fiscal 2025, such delays, constraints and increased costs may adversely affect our customers’ purchasing decisions and deployment timelines. In response, we may in the future provide commercial accommodations, which could reduce our margins or adversely affect our business if such practices become widespread or prolonged. If such conditions persist or worsen, potential new customers could defer, delay, scale back, or in some cases forego purchases or deployments of our solutions until compatible commodity servers are available or total solution costs decline. Any such disruptions, shortages, or resulting delays may also require us or our Channel Partners to adjust forecasts, reschedule orders, or qualify alternative Manufacturers. If we or our Channel Partners are required to change or qualify a new Manufacturer for any reason, including financial considerations, reduction of manufacturing output made available to us, or the termination of our or our Channel Partners’ contract with the Manufacturers, we may lose revenue and incur increased costs to the extent that we are even able to identify and qualify a new Manufacturer. In addition, our contract manufacturers may terminate the agreement with us or our Channel Partners with prior notice for reasons such as failure to perform a material contractual obligation.
A large majority of the customer enterprise data we secure relies upon Rubrik-branded Appliances, which are currently built on servers supplied and designed by Super Micro Computer, Inc. ("Supermicro"). If we are unable to manage our relationship with Supermicro effectively, or if Supermicro continues to suffer delays or disruptions for any reason, including due to the global chip shortage that the broader industry is currently experiencing, any other component allocation constraints, increased manufacturing lead-times, capacity constraints, quality control problems in its manufacturing operations, or international trade disputes, tariffs or other protectionist measures, or fails to meet our requirements for timely delivery, or if Supermicro no longer produces the servers for our Rubrik-branded Appliances, our indirect costs may increase and our end-customer’s ability to procure Rubrik-branded Appliances in a timely manner would be impaired to the extent that any alternative commodity servers are available at all. Our agreement with Supermicro does not provide long-term price assurances for certain components used in Rubrik-branded Appliances, and increases in component or server costs could increase the total price customers pay to implement our solutions. While we have largely completed the sales of Rubrik-branded Appliances transitioning from us to our contract manufacturers in fiscal 2025, any such cost increases, including those resulting from chip shortages or allocation constraints, could adversely affect customer demand for our offerings or the timing of purchases and deployments. While customers would have the ability to purchase compatible third-party commodity servers from other OEMs, and we have the ability to qualify new commodity servers for Rubrik-branded Appliances, this may create increased costs or delays for our customers and impact their customer experience, which could negatively impact our sales and our business. See the section titled “Business—Manufacturing” in our Annual Report for additional information regarding our contractual relationship with Supermicro.
Certain of our OEMs carry products that compete with our solutions and may not continue producing or supporting compatible commodity servers for our customers in the future. We or our Channel Partners provide forecasts and purchase orders to Manufacturers for compatible commodity servers, and these orders may only be rescheduled or canceled under certain limited conditions. If we inaccurately forecast demand for our solutions and need for compatible commodity servers, our Manufacturers may have excess or inadequate inventory, and we may incur cancellation charges or penalties, which could adversely impact our operating results. If we experience increased demand for compatible commodity servers, then we, our Channel Partners, or Manufacturers may need to increase component purchases, contract manufacturing capacity, or internal test and quality functions. Our customers’ orders may represent a relatively small percentage of the overall orders received by Manufacturers from their customers. As a result, fulfilling our customers’ orders may not be considered a priority in the event Manufacturers are constrained in their ability to fulfill all of their customer obligations in a timely manner. Although we have largely transitioned the sale of Rubrik-branded Appliances from us to our contract manufacturers, if Manufacturers are unable to provide adequate supplies of high-quality products, or if we, our Channel Partners, or Manufacturers are unable to obtain adequate quantities of components, or control the costs of components, it could cause a delay in the fulfillment of our customers’ orders, in which case our business, financial condition, and results of operations could be adversely affected.
Tariffs and other restrictive trade policies, such as those regarding hardware and technology infrastructure from China, have had and may continue to have an indirect impact on the total price customers pay for our products and may also impact production and supply of our Rubrik-branded Appliances and the commodity servers compatible with our solutions. These impacts could negatively affect customer experience, demand, and the attractiveness of our solutions relative to alternatives.
Our use of generative artificialand intelligenceother AI tools may pose risks to business and operations, including our proprietary software and systemssystems, and may subject us to legal liability.
We use generative AI tools in our business, including generative AI and agentic AI, and we expect to use generative AI tools in the future, including to generate code and other materials incorporated into our products, proprietary software, and systems, and for other internal and external uses.uses, Generativeand we are making investments to expand our generative and agentic AI referscapabilities, toincluding deep-learningrecent modelsand thatfuture canproduct generate new data,offerings such as text,Rubrik images,Agent andCloud, otherwhich content,is bydesigned analyzingto andaccelerate emulatingenterprise existingAI data.agent deployments. Advanced generative AI tools, which may produce content indistinguishable from that generated by humans, are a relatively novel development, with benefits, risks, and liabilities still unknown. Recent decisions of governmental entities and courts (such as the U.S. Copyright Office, U.S. Patent and Trademark Office, and U.S. Court of Appeals for the Federal Circuit) interpret U.S. copyright and patent law as limited to protecting works and inventions created by human authors and inventors, respectively. We are therefore unlikely to be able to obtain U.S. copyright or patent protection for works or inventions wholly created by a generative AI tool, and our ability to obtain U.S. copyright and patent protection for source code, text, images, inventions, or other materials, which are developed with some use of generative AI tools, may be limited, if available at all. Likewise, the availability of such IP protections in other countries is unclear. In addition, we may have little or no insight into and no control over the content and materials used by vendors and model providers to train these generative AI tools.tools, or that otherwise use or incorporate these generative AI tools into their own offerings. There is ongoing litigation over whether the use of copyrighted materials to train the AI models used in these tools is lawful, and the impact of decisions in such litigation on our use of generative AI tools is unknown. Furthermore, our vendors who use generative and agentic AI tools in their own offerings may not meet existing or rapidly evolving regulatory or industry standards, including with respect to the rights of others, privacy and data security. Additionally, our use of open-source and other third-party generative and agentic AI toolstools, including to develop source code, text, images, inventions, or other materialsmaterials, may expose us to greater risks than utilizing contracted human developers, as third-party generativesuch AI vendorstools typically do not providecome with warranties or indemnities with respect to the output generated by such generative AI tools, and generative and agentic AI tools may also hallucinate, providing erroneous output thator appearsmaking correcterroneous but is erroneous.decisions. Furthermore, some generative AI tools may be offered under terms that do not protect the confidentiality of the prompts or inputs that users submit to such tools and may use prompts or inputs to train shared AI models, potentially resulting in third-party users receiving outputs containing information from prompts or inputs (including confidential, competitive, proprietary, or personal data) that we submitted to the tool. The disclosure and use of personal data in AI technologies is also subject to various privacy laws and other privacy obligations. Prior to implementing aan AI tool (including generative AI tool,tools), our AI governance committee (including leaders from our Engineering, Product, Legal, and Information Security teams) performs an analysis and review of theeach tool,AI tool for which pre-approval is required according to our policies, including evaluation of potential legal, security, and business risks and steps that can be taken to mitigate any such risks. The selection criteria and analysis include consideration of how use of the generative AI tool could raise issues relating to confidential information, personal data and privacy, customer data and contractual obligations, open source software, copyright and other intellectual property rights, transparency, output accuracy and reliability, and security. Additionally, while we employ practices designed to evaluate, track, and mitigate risk around our use of third-party generative AI tools, our use of such tools may inadvertently violate a third party’s rights, be non-compliant with the applicable terms of use or our other legal obligations, or result in a security or privacy risk or data leakage. Our use of this technology could result in additional compliance costs, regulatory investigations and actions, and lawsuits. For example, we may face claims from third parties claiming infringement of their intellectual property rights or mandatory compliance with open-source software or other license terms with respect to software or other materials or content we believed to be available for use and not subject to license terms or other third-party proprietary rights. Any of these claims could result in legal proceedings and could require us to purchase costly licenses, comply with the requirements of third-party licenses, or limit or cease using the implicated software or other materials or content, unless and until we can re-engineer such software, materials, or content to avoid infringement or change the use of, or remove, the implicated third-party materials, which could reduce or eliminate the value of our technologies and services. Our use of generative AI tools to generate code may also present additional security risks because the generated source code may contain security vulnerabilities. Additionally, the vendors of these generative AI tools may fail to comply with their contractual obligations to us regarding the confidentiality or security of any data or other inputs provided to such vendor or outputs generated by their generative AI tools. Our sensitive information or that of our customers could be leaked, disclosed, or revealed as a result of or in connection with our employees’, personnel’s, or vendors’ use of third-party generative AI technologies.
Additionally, while we employ practices designed to evaluate, track, and mitigate risk around our use of third-party AI tools, our practices may not be error free, and our use of such tools may inadvertently violate a third party’s rights, be non-compliant with the applicable terms of use or our other legal obligations, or result in a security or privacy risk or data leakage. Our use of AI technology could result in additional compliance costs, regulatory investigations and actions, and lawsuits. For example, we may face new or enhanced governmental scrutiny, or claims from third parties claiming infringement of their intellectual property rights or mandatory compliance with open-source software or other license terms with respect to software or other materials or content we believed to be available for use and not subject to license terms or other third-party proprietary rights. Any of these claims could result in legal investigations or proceedings. Furthermore, if we are found to be in violation of third party rights based on our use of AI tools, we could be required to purchase costly licenses, comply with the requirements of third-party licenses, or limit or cease using the implicated software or other materials or content, unless and until we can re-engineer such software, materials, or content to avoid infringement or change the use of, or remove, the implicated third-party materials, which could reduce or eliminate the value of our technologies and services. Our use of generative and agentic AI tools to generate code may also present additional security risks because the generated source code may contain security vulnerabilities. Additionally, vendors of AI tools may fail to comply with their contractual obligations to us regarding the confidentiality or security of any data or other inputs provided to such vendor or outputs generated by their AI tools. Our sensitive information or that of our customers could be leaked, disclosed, or revealed as a result of or in connection with our employees’, personnel’s, or vendors’ use of third-party AI technologies.
We also market some of our own products or features as generative AI tools and AI infrastructure services ("Generative AI Products"). Some of our customers, especially those in highly regulated industries, may be reluctant or unwilling to adopt Generative AI Products. Accordingly, adoption of generative AI features in our products and marketing our products as Generative AI Products could reduce or delay customer adoption. Because generativeAI models and AI modelsagents can hallucinate and provide erroneous output,output or make erroneous decisions, offering Generative AI Products could result in customer dissatisfaction or potentially claims against us arising out of customer reliance on erroneous output toor theirdecisions. detriment.Some Ourof Generativeour AI Products may require us to train or fine-tune AI models using datasets collected by us or from third-party vendors.providers. While we have processes and practices designed to ensure that we and any vendorsthird-party thatproviders we use to sourceof training data have the necessary rights to use such datasets for training our Generative AI Products, we may not in every instance be able to confirm that all of the information contained in such datasets has been obtained with the necessary permissions for us to use for purposes of our Generative AI Products. For example, we may use publicly available data to train our Generative AI Products that containscontain information that was unlawfully acquired from third parties without our knowledge. While we have employed processes designed to help us avoid using any personal data to train or fine-tune our Generative AI Products, it may be difficult for us to avoid or identify all instances where a user might nonetheless submit personal data to our Generative AI Products. Furthermore, if we were to receive claims from third parties asserting rights against our use of certain datasets used to train our Generative AI Products, it may be difficult or impossible for us to disentangle our trained models from the subject matter of the claims.
Our AI Products may also rely on certain third party providers of AI technology. Our success in deploying AI features and tools for our AI Products is reliant on these third parties and their platforms. We cannot control the quality, availability or pricing of such third-party platforms, especially in a highly competitive environment. If any such third-party platforms become incompatible with our offerings or unavailable for use or have degradations in performance, or if the providers of such models unfavorably change the terms on which their AI platforms are offered or terminate their relationship with us, our solutions may become less appealing to our customers. In addition, for any third party providers of AI platforms that host platforms on our behalf any disruption, outage, or loss of information, data breaches, cybersecurity threats or other data loss through such hosted services could disrupt our operations or solutions, damage our reputation, cause a loss of confidence in our solutions, or result in legal claims or proceedings, for which we may be unable to recover damages from the affected provider.
Several jurisdictions around the globe, including in Europe and certain U.S. states,Europe, have proposed, enacted, or are considering laws governing AI tools, including the EU’s AI Act. In the United States, where our operations are headquartered, several states are applying their data and consumer protection laws to AI, and/or have enacted, or are enacting or considering legal frameworks on AI, such as the California Bot Disclosure Law, the Utah Artificial Intelligence Policy Act, the Colorado Artificial Intelligence Act and the ColoradoCCPA’s AIregulations Act.regarding automated decision-making technology. We expect other jurisdictions will adopt similar laws.laws, and, as a result of the rapidly evolving regulatory landscape, implementation standards, enforcement practices, and available scope of protection are likely to remain uncertain for the foreseeable future, and we cannot yet determine the impact future laws, regulations, or standards may have on our business (including our positioning with respect to our competition) and may not always be able to anticipate how to respond to these laws or regulations. Additionally, certain privacy laws extend rights to consumers (such as the right to delete certain personal data) and regulate automated decision making, which may be incompatible with our use of AI. These obligations may make it harder for us to conduct our business using AI, lead to regulatory fines or penalties, require us to disclose or provide greater transparency regarding the nature of our Generative AI Products and the data we have employed to train them, require us to change our business practices, retrain our Generative AI Products, or prevent or limit our use of AI. For example, the FTC has required other companies to delete (or “disgorge”) both the personal data that the FTC alleged were collected in violation of privacy laws as well as the algorithms and other insights that were developed or generated using such data. If we cannot use AI or that use is restricted, our business may be less efficient, or we may be at a competitive disadvantage.
Also, the rapid evolution of AI technologies may require the expenditure of significant resources to design, develop, test and maintain our products and services to help ensure that our AI features and tools are implemented in accordance with applicable law and regulation and in a socially responsible manner and to minimize any real or perceived unintended harmful impacts. We also may need to expend further resources to adjust our business practices, as these laws and regulations evolve, especially where requirements across jurisdictions are inconsistent.
WeChanges expectin our revenue mix andmay certaincause businessfluctuations factors to impact the amount ofin revenue recognized from period to period, which could make period-to-period revenue comparisons not meaningful and difficult to predict.
We expect ourOur revenue mix tomay vary over time due to a number of factors, including the timing of when customers adopt RSC and the mix of our subscriptions for different data security products.products and the timing of remaining customer migrations to RSC or other SaaS offerings. Our subscription revenue includes revenue from sales of subscription term-based licenses, a portion of which is recognized upfront when we transfer control of the subscription term-based license to the customer, and revenue from sales of SaaS subscriptions and support, which is recognized ratably over the contract period. DueAs towe thehave proportionsubstantially ofcompleted our contracts trendingtransition from subscription term-based licenses to SaaS subscriptions,subscriptions theand timingmigrated ofa thesignificant migrationmajority of our existing customers from Cloud Data Management to RSC, the proportion of revenue recognized upfront versus ratably over time has evolved. However, the timing of remaining customer migrations, as well as the estimates and assumptions used to account for certain customers’customer arrangements, including Subscription Credits (which are customer options that are accounted for as definedmaterial belowrights) related to their Refresh RightsRights, (asmay definedcontinue below),to affect the amount and timing of revenue recognized. In addition, future changes in our product offerings, pricing models, contract structures, customer purchasing patterns, or other business initiatives may further affect our revenue may fluctuatemix and period-to-periodthe timing of revenue comparisons may not be meaningful, and our past results may not be indicative of future performance. We cannot be certain how long these factors may persist. For example, as our existing customers prepare to migrate to RSC, we expect certain of them to consume our solutions through a mix of RSC and RCDM-T during which time we will continue recognizing a portion of the associated revenue upfront.recognized. These factors make it challenging to forecast our revenue as the mix of solutions and services, the timing of our customers’ RSC transition, as well as the size of contracts, are difficult to predict.
We rely upon third-party cloud providers to host our data security solutions, and any disruption of, or interference with, our use of third-party cloud products would adversely affect our business, financial condition, and results of operations.
Customers of RSC and our other cloud services need to be able to access our data security solutions at any time, without interruption or degradation of performance, and we provide them with service-level commitments with respect to uptime. We leverage third-party cloud providers for substantially all of the infrastructure that supports our data security solutions. Our cloud services depend on the cloud infrastructure hosted by these third-party providers to support our configuration, architecture, features, and interconnection specifications, as well as secure the information stored in these virtual data centers, which is transmitted through third-party internet service providers. Any limitation on the capacity of our third-party hosting providers, including due to technical failures, shifts in product capabilities or licensing models, natural disasters, fraud, or security attacks, could impede our ability to fulfill our current contractual commitments, onboard new customers, or expand the usage of our existing customers, which could adversely affect our business, financial condition, and results of operations.
•Data management and protection vendors, such as Dell-EMC, IBM, Commvault, Veeam, and Cohesity (which recently acquired Veritas’ data protection business);
•Vendors that provide cyber/ransomware detection and investigation, data security posture management, identity security posture management, Active Directory and Entra ID security and protection, insider threat detection, data classification, and other data security or data governance technologies.
Many of our current and potential competitors have longer operating histories and may have substantially greater financial, technical, sales, marketing, and other resources than we do, as well as larger installed customer bases, greater name recognition, lower labor and development costs, and broader product solutions, including servers. Some of these competitors can devote greater resources to the development, promotion, sale, and support of their data security products than we can. As a result, these competitors may be able to respond more quickly to new or emerging technologies and changes in customer requirements. For example, many of our competitors are also investing in AI technology to improve their data security products, which could enable them to respond more quickly to new or emerging threats and changes in customer requirements.
Our current and potential competitors may establish cooperative relationships among themselves or with third parties or may merge with each other. If so, new competitors, alliances, or merged entities that include our competitors may emerge that could acquire significant market share. In addition, large operating systems, applications, and cloud vendors have introduced products or functionality that include some of the same functions offered by our data security solutions. In the future, further development by these vendors could cause our data security solutions to become redundant, which could seriously harm our business, financial condition, and results of operations.
In addition, we expect to encounter new competitors, including public cloud providers and SaaS companies that build native data security and management solutions, as we expand in current markets or enter new markets. Furthermore, many of our existing competitors are broadening their operating systems platform coverage. We expect that competition will increase as a result of future software industry consolidation. Increased competition could harm our business by causing, among other things, price reductions of our data security solutions, reduced profitability, and loss of market share.
Market opportunity estimates and growth forecasts, whether obtained from third-party sources or developed internally, are subject to significant uncertainty and are based on assumptions and estimates that may not prove to be accurate. The data security market is at an early stage and is rapidly evolving. As we are working to create a market for data security from other existing markets that focused on other elements of cybersecurity, our market is at an early stage and rapidly evolving. As a result, the size and future growth of this market are difficult to accurately estimate and subject to change. In addition, third-party estimates of the addressable market for the security and data management sectors reflect the opportunity available from all participants and potential participants, and we cannot predict with precision our ability to address this demand or the extent of market adoption of our platform and data security products. Moreover, the market segments we are targeting may grow at different rates. The variables that go into the calculation of our market opportunity are subject to change over time, and there is no guarantee that any particular number or percentage of addressable businesses covered by our market opportunity estimates will purchase our data security solutions or generate any particular level of revenue for us. Any expansion in our market opportunity depends on a number of factors, including the cost, performance, and perceived value associated with our data security solutions and the products of our competitors. Even if the areas in which we compete achieve the forecasted growth, our business could fail to grow at similar rates, if at all.
There are a limited number of contract manufacturers and original equipment manufacturers of commodity servers that are compatible with our data security solutions, and failure to accurately forecast demand for these commodity servers or successfully manage the relationship with such manufacturers could negatively impact the ability to sell our offerings.
A limited number of Manufacturers produce commodity servers that are compatible with our data security solutions. We do not own or operate any manufacturing facilities and rely on these Manufacturers for such products. These Manufacturers manage the supply chain for these products and, alone or together with us or our distributors and resellers ("Channel Partners"), negotiate component costs. Our reliance on Manufacturers and Channel Partners reduces our control over the assembly process, quality assurance, production costs, and product supply. If the relationships with Manufacturers are not properly managed or if Manufacturers experience delays, interruptions, or supply-chain disruptions, including due to international conflicts and geopolitical tensions (such as the imposition of new trade restrictions and tariffs due to escalating tensions, hostilities, or trade disputes), health epidemics or pandemics, new trade laws and regulations, capacity constraints, or quality control problems in their operations, the ability for customers to procure compatible commodity servers could be impaired. If we or our Channel Partners are required to change or qualify a new Manufacturer for any reason, including financial considerations, reduction of manufacturing output made available to us, or the termination of our or our Channel Partners’ contract with the Manufacturers, we may lose revenue, incur increased costs, and our customer relationships may be damaged. In addition, our contract manufacturers may terminate the agreement with us or our Channel Partners with prior notice for reasons such as failure to perform a material contractual obligation.
A large majority of the customer enterprise data we secure relies upon Rubrik-branded Appliances, which are currently built on servers supplied and designed by Super Micro Computer, Inc. ("Supermicro"). If we are unable to manage our relationship with Supermicro effectively, or if Supermicro suffers delays or disruptions for any reason, including due to recent reports of challenges at Supermicro, experiences increased manufacturing lead-times, capacity constraints, quality control problems in its manufacturing operations, potential delays or increased costs from international trade disputes, tariffs or other protectionist measures, or fails to meet our requirements for timely delivery, or if Supermicro no longer produces the servers for our Rubrik-branded Appliances, our indirect costs may increase and our end-customer’s ability to procure Rubrik-branded Appliances in a timely manner would be impaired. While customers would have the ability to purchase compatible third-party commodity servers from other OEMs, and we have the ability to qualify new commodity servers for Rubrik-branded Appliances, this may create increased costs or delays for our customers and impact their customer experience, which could negatively impact our sales and our business. See the section titled “Business—Manufacturing” for additional information regarding our contractual relationship with Supermicro.
Certain of our OEMs carry products that compete with our data security solutions and may not continue producing or supporting compatible commodity servers for our customers in the future. We or our Channel Partners provide forecasts and purchase orders to Manufacturers for compatible commodity servers, and these orders may only be rescheduled or canceled under certain limited conditions. If we inaccurately forecast demand for our data security solutions and need for compatible commodity servers, our Manufacturers may have excess or inadequate inventory, and we may incur cancellation charges or penalties, which could adversely impact our operating results. If we experience increased demand for compatible commodity servers, then we, our Channel Partners, or Manufacturers may need to increase component purchases, contract manufacturing capacity, or internal test and quality functions. Our customers’ orders may represent a relatively small percentage of the overall orders received by Manufacturers from their customers. As a result, fulfilling our customers’ orders may not be considered a priority in the event Manufacturers are constrained in their ability to fulfill all of their customer obligations in a timely manner. Although we have largely transitioned the sale of Rubrik-branded Appliances from us to our contract manufacturers, if Manufacturers are unable to provide adequate supplies of high-quality products, or if we, our Channel Partners, or Manufacturers are unable to obtain adequate quantities of components, or control the costs of components, it could cause a delay in the fulfillment of our customers’ orders, in which case our business, financial condition, and results of operations could be adversely affected.
The customer enterprise data we secure relies upon compatible hardware. Historically, we sold Rubrik-branded Appliances produced by contract manufacturers to our customers. We started transitioning the sale of Rubrik-branded Appliances from us to our contract manufacturers in fiscal 2023 and offered limited-time incentivesincentives, ("Subscription Credits" (which are customer options that are accounted for as material rights), upon qualification, to certain existing customers in exchange for historically offered rights to next generation Rubrik-branded Appliances at no cost, which we refer to as Refresh Rights. If customers have not utilized their Subscription Credits before they expire, this could result in customer dissatisfaction or a decision not to purchase our data security solutions, which would have an adverse impact on our results of operations.
From time to time, there may be changes in our senior management team or other key employees resulting from the hiring or departure of these personnel. Our executive officers and certain other key employees are employed on an at-will basis, which means that these personnel could terminate their employment with us at any time. The loss of one or more of our executive officers, or the failure by our executive team to effectively work with our employees and lead our company, could harm our business. We also are dependent on the continued service of our existing software engineers because of the complexity of our data security solutions. In addition, a significant portion of our software engineers are located in Palo Alto, California and Bangalore, India. These locations offer access to a deep pool of highly skilled professionals, which is crucial for the development and maintenance of our complex data security solutions. However, this concentration also exposes us to potential continuity risk if these specific locations are negatively impacted by unforeseen events, such as natural disasters, political unrest, or disruptions in critical infrastructure.
Our growth will depend in large part on our ability to attract new customers and expand sales to existing customers, expand the features and functionality of our platform, hire sufficient sales personnel to support our growth, and decrease the ramp time for our sales personnel. In addition, the success of our business is substantially dependent on the actual and perceived viability, benefits, and advantages of our platform as a preferred provider for data security.platform. As such, market adoption of our platform andplatform, data security productsand agentic AI operations solutions is critical to our continued success. Demand for our platform and data security products is affected by a number of factors, including increased market acceptance by new and existing customers, increased market acceptance of our AI offerings, such as Rubrik Agent Cloud, increased activity by or prevalence of cybersecurity bad actors, including the use of ransomware, effectiveness of our sales and marketing strategy, the extension of our platform to new applications and use cases, the timing of development and release of new capabilities by us and our competitors, technological change, and growth or contraction of the market in which we compete. Failure to successfully address or account for these factors, satisfy customer demands, achieve continued market acceptance over competitors, and achieve growth in sales of our data security products would harm our business, financial condition, results of operations, and growth prospects.
Management's Discussion & Analysis (MD&A)
New heading “Macroeconomic and Supply Chain Conditions”
Removed heading “Maintenance Revenue”
Removed heading “Cost of Maintenance Revenue”
Removed heading “Maintenance Gross Margin”
Removed heading “Common Stock Valuations”
Removed heading “CEO Performance Award”
Removed heading “JOBS Act Accounting Election”
Largest changes
“Our overall performance depends in part on worldwide economic and geopolitical conditions and their impact on customer behavior. Macroeconomic conditions, including inflation, fluctuations in interest rates, foreign currency fluctuations, tariffs or other trade restrictions, geopolitical issues, changes in government policy or spending, and other changes in economic conditions, may adversely affect the buying patterns of our customers and prospective customers. …”see in full comparison
A discussion regarding our financial condition and results of operations for the fiscal year ended January 31,see in full comparison20242026 compared to the fiscal year ended January 31, 2025 is presented below. A discussion regarding our financial condition and results of operations for the fiscal year ended January 31,20232025 compared to the fiscal year ended January 31, 2024 can be found in “Management’s Discussion and Analysis of Financial Condition and Results of Operations” in thefinalAnnualprospectusReport on Form 10-K forourtheinitialfiscalpublicyearofferingended(“IPO”)Januarydated31,as of April 24, 2024 and2025 filed with theSecurities and Exchange Commission (“SEC”) pursuant to Rule 424(b)(4)onAprilMarch26,20,2024.2025.
“In fiscal 2026, we launched RAC, our AI agent operations suite, to accelerate enterprise AI transformation without introducing added risk. RAC is designed to monitor and audit agentic actions, enforce real-time guardrails for agentic changes, fine-tune agents for accuracy and, finally, undo agent mistakes. Built on our unique architecture that understands data, identity and application contexts, RAC is designed to give customers security, accuracy, and efficiency as they transform their organizations into AI enterprises. …”see in full comparison
“In August 2023, we amended and restated the Prior Credit Facility (the "Amended Credit Facility"), to increase the total borrowing capacity thereunder to $330.0 million, consisting of initial term loans in an aggregate principal amount of approximately $289.5 million and delayed draw term loan commitments in an aggregate principal amount of approximately $40.5 million. The Amended Credit Facility will mature in August 2028. …”see in full comparison
“We are an emerging growth company, as defined in the JOBS Act. The JOBS Act provides that an emerging growth company can take advantage of an extended transition period for complying with new or revised accounting standards. This provision allows an emerging growth company to delay the adoption of some accounting standards until those standards would otherwise apply to private companies. …”see in full comparison
Full comparison: every changed paragraph (99)
A discussion regarding our financial condition and results of operations for the fiscal year ended January 31, 20242026 compared to the fiscal year ended January 31, 2025 is presented below. A discussion regarding our financial condition and results of operations for the fiscal year ended January 31, 20232025 compared to the fiscal year ended January 31, 2024 can be found in “Management’s Discussion and Analysis of Financial Condition and Results of Operations” in the finalAnnual prospectusReport on Form 10-K for ourthe initialfiscal publicyear offeringended (“IPO”)January dated31, as of April 24, 2024 and2025 filed with the Securities and Exchange Commission (“SEC”) pursuant to Rule 424(b)(4) on AprilMarch 26,20, 2024.2025.
We are on a mission to secure and accelerate the world’s data.AI transformation.
Cyberattacks are inevitable. Prevention and detection are not enough. Realizing that cyberattacks ultimately target data, we created Zero Trust Data Security to deliver cyber resilience so that organizations can secure their data across the cloud and recover from cyberattacks. As enterprises embrace the forthcoming AI transformation, they are grappling with a threat landscape that is now amplified at an AI-scale. We believe that cyber resilience will result in AI resilience and that the future of cybersecurity is data security—if your data is secure, your business is resilient.
We built the Rubrik Security Cloud ("“RSC"”) suite with Zero Trust design principles to secure data across enterprise, cloud, SaaS, unstructured data, and SaaSidentity applications.providers. RSC delivers a cloud native SaaS platform that detects, analyzes, and remediates data security risks and unauthorized user activities. Our platform is architected to help organizations achieve cyber resilience, which encompasses cyber posture and cyber recovery. We enable organizations to confidently accelerate digital transformation and leverage the cloud to realize business agility.
We launched our first enterprise software product, Converged Data Management, in fiscal 2016, which combined data and metadata together into a single layer of software to offer Zero Trust data protection, and sold it as a perpetual license along with associated maintenance contracts. In fiscal 2019, we extended data protection to cloud native applications and rebranded Converged Data Management to Cloud Data Management ("CDM"). Data protection for cloud native applications are sold as a SaaS subscription product. In addition, we began offering new SaaS subscription products, Anomaly Detection and Sensitive Data Monitoring. In fiscal 2020, we continued our business evolution to a subscription pricing model by offering our CDM platform as a subscription term-based license with associated support. Included in this subscription term-based license was the right to next generation Rubrik-branded commodity servers ("Rubrik-branded Appliances") at no cost for qualified customers ("Refresh Rights"). As of February 1, 2022, we stopped offering CDM as a perpetual license.
In fiscal 2023, to meet customer demands for data security and a single, unified cloud-based control plane, we launched RSC, a suite built on top of our comprehensive Zero Trust Data Security platform. RSC culminates our early vision of providing one point of control to secure data across enterprise, cloud, SaaS, unstructured data, and SaaSidentity applications.providers. RSC is primarily adopted by our customers as a cloud-native, fully managed SaaS solution. It is also available as an enterprise-ready, self-managed version ("RSC-Private"), for a few select customers that are subject to stringent data control policies. For U.S. public sector organizations, we also offer a specialized cloud-native fully managed SaaS solution called RSC-Government.
We began transitioning customers from our legacy CDM capabilities to RSC, which is offered on a subscription basis, in fiscal 2023. As part of this business transition, we began transitioning the sale of Rubrik-branded Appliances from us to our contract manufacturers and stopped offering the Refresh Rights as part of our subscription offerings. In lieu of offering Refresh Rights, we offeroffered Subscription Credits to qualifying customers.customers (which are customer options that are accounted for as material rights). We recognize ratable revenue upon utilization or upfront revenue upon expiration of Subscription Credits, and utilization of Subscription Credits also offsets Subscription ARR for the applicable period. As ofSince the end of fiscal 2024, RSC has represented a majority of our total revenue.
We recognize revenue from the sales of our RSC platformsuite (excluding RSC-Private) ratably over the term of the subscription. We recognize a portion of revenue from sales of RSC-Private upon delivery and the remainder ratably over the term of the subscription. The majority of sales of our subscriptions are for three-year terms with upfront payment, and renewals are typically for one-year terms.
We expect newNew and existing customers tohave continuelargely to adoptadopted RSC. Our new customersWe have generallylargely been rapidly adopting the RSC platform. We are actively migratingmigrated our existing customers from our legacy CDM capabilities to RSC. As part ofDuring this migration, we expect certain existing customers to consumeconsumed our platform and products through a mix of RSC and a transitional CDM license ("RCDM-T"), during which time we expect to continue recognizingrecognized a portion of the associated revenue from these customers upfront at the time we transfertransferred control of the license to the customer.customer, Weand cannotwe predicthave howlargely long these customers will usecompleted this mixtransition beforein theyfiscal complete their transition.2026. In addition, we expect our subscription revenue willto fluctuatecontinue whento qualifiedbenefit from customers choose to exerciseexercising or forfeitforfeiting their Subscription Credits (whichthrough arefiscal customer2027, optionsalthough thatwe areexpect accountedthe forbenefits asto materialsignificantly rights)reduce upon their associated expiration date.sequentially.
In fiscal 2026, we launched RAC, our AI agent operations suite, to accelerate enterprise AI transformation without introducing added risk. RAC is designed to monitor and audit agentic actions, enforce real-time guardrails for agentic changes, fine-tune agents for accuracy and, finally, undo agent mistakes. Built on our unique architecture that understands data, identity and application contexts, RAC is designed to give customers security, accuracy, and efficiency as they transform their organizations into AI enterprises. As RAC only became commercially available in February of 2026, we expect the RSC suite to continue to be the majority of our revenue in fiscal 2027 and the main driver for ARR growth.
Key Factors Affecting Our Performance
Our future success depends in part on the market adoption of our approach to Zero Trust Data Security. Many organizations have focused on preventing cyberattacks instead of protecting their data and having a plan to recover it in case of a cyberattack. We believe that the existing security ecosystem lacks a data security platform that will secure a customer’s data, wherever it lives, across enterprise, cloud, SaaS, unstructured data, and SaaSidentity applications.providers. RSC is our Zero Trust Data Security platform that addresses the growing demand from organizations of virtually any size, across a wide range of industries, to address data security and cyberattack risks. As the data security market continues to evolve, we expect to continuously innovate our platform and product functionality to keep us in a strong position to capture the large opportunity ahead.
Our ability to retain customers and expand within existing customers is integral to our growth and future success. Our growing base of customers represents a significant opportunity for further expansion across our platform. Our customers typically start with securing data in one or more applications on our platform, and then expand by securing additional applications and increasing the amount of data secured. They further extend their use of our platform through adoption of additional security products. Several of our largest customers have deployed our platform to protect enterprise, unstructured data, cloud, and SaaS applications, securingsecure large amounts of their data.data across enterprise, cloud, SaaS, unstructured data, and identity providers. Our ability to expand and extend within our customer base depends on, and has been impacted by, a number of factors, including platform performance, our customers’ satisfaction with our platform, competitive offerings, pricing, overall changes in our customers’ spending levels, and the effectiveness of our efforts to help our customers realize the benefits of our platform.
Macroeconomic and Supply Chain Conditions
Our overall performance depends in part on worldwide economic and geopolitical conditions and their impact on customer behavior. Macroeconomic conditions, including inflation, fluctuations in interest rates, foreign currency fluctuations, tariffs or other trade restrictions, geopolitical issues, changes in government policy or spending, and other changes in economic conditions, may adversely affect the buying patterns of our customers and prospective customers. For example, in light of current macroeconomic conditions, such as higher cost-consciousness around information technology budgets, as well as constraints affecting the availability or pricing of compatible commodity servers needed to deploy our solutions, we have observed a lengthening of our sales cycles. Additionally, key components of the commodity servers that are compatible with our solutions have been, and continue to be, adversely affected by global chip shortages and allocation constraints, in part due to elevated industry demand, which in certain cases have resulted in extended lead times and increased server prices. While we have largely completed the sales of Rubrik-branded Appliances transitioning from us to our contract manufacturers in fiscal 2025, such delays, constraints and increased costs may adversely affect our customers’ purchasing decisions and deployment timelines. In response, we may in the future provide commercial accommodations, which could reduce our margins or adversely affect our revenue and operating results if such practices become widespread or prolonged. Due to our subscription-focused business model, any impact of the current macroeconomic environment and supply chain constraints on our business may not be fully reflected in our results of operations until future periods. As we continue to monitor the direct and indirect impacts of the current environment, the broader implications of macroeconomic conditions and supply chain constraints on our business, results of operations and financial condition, particularly in the long term, remain uncertain.
Subscription ARR is calculated as the annualized value of our active subscription contractssubscriptions as of the measurement date, based on our customers’ total contract value, and assuming any contract that expires during the next 12 months is renewed on existing terms. Subscription contractsSubscriptions include offerings for our RSC platformsuite and related data security SaaS solutions, term-based licenses for our RSC-Private platformsuite and related products, prior sales of CDM sold as a subscription term-based license with associated support and related SaaS products, and standalone sales of our SaaS subscription products like Anomaly Detection and Sensitive Data Monitoring. We believe Subscription ARR illustrates our success in acquiring new subscription customers and maintaining and expanding our relationships with existing subscription customers.
Subscription ARR does not include any maintenance revenue associated with perpetual licenses, which we generally no longer offer. Of the 39%34% and 47%39% growth, approximately 21 percentage pointspoint and 42 percentage points of growth for the twelve months ended January 31, 20252026 and 2024,2025, respectively, were a result of transitioning our existing maintenance customers to our subscription editions. We expect the contributionsContributions to growth from these transitions towere subsidelargely completed in fiscal 2026.
Cloud ARR is calculated as the annualized value of our active cloud-based subscription contractssubscriptions as of the measurement date, based on our customers’ total contract value, and assuming any contract that expires during the next 12 months is renewed on existing terms. Our cloud-based subscription contractssubscriptions include RSC and RSC-Government (excluding RSC-Private). Cloud ARR also includes SaaS subscription products like Anomaly Detection and Sensitive Data Monitoring, which are sold standalone or with prior sales of term-based license offerings of CDM. We believe that Cloud ARR provides important information on new and existing customers purchasing new RSC subscription offerings and existing subscription term-based license customers renewing with RSC subscription offerings.
Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by (used in) operating activities less cash used for purchases of property and equipment and capitalized internal-use software. We believe that free cash flow is a helpful indicator of liquidity that provides information to management and investors about the amount of cash generated or used by our operations that, after the investments in property and equipment and capitalized internal-use software, can be used for strategic initiatives, including investing in our business and strengthening our financial position. The limitation of free cash flow is that it does not reflect our future contractual commitments and may fluctuate due to the timing of cash payments received from our customers and payments relative to expenses, including discretionary cash payments of our debt interest expense pursuant to the terms of our Amended Credit Facility andFacility, prepayments of other spend.spend, including hosting prepayments, and charitable donations. Additionally, free cash flow is not a substitute for cash provided by (used in) operating activities, and the utility of free cash flow as a measure of our liquidity is further limited as it does not represent the total increase or decrease in our cash balance for a given period.
Free cash flow was $21.6$237.8 million, $(24.5)$21.6 million and $(15.024.5) million for the fiscal yearyears ended January 31, 2025,2026, 20242025 and 2023,2024, respectively. Free cash flow for the fiscal year ended January 31, 2025 includes a cash outlay of $22.8 million for employer payroll taxes due to the vesting of certain equity awards in conjunction with the initial public offering. The improvement in free cash flow was primarily due to higher sales that were offset by higher expensessales, including expenses from Laminar operations, which was acquired in August 2023, a decrease in contract term due to the growthtiming of ourrenewals, Cloudimproved operating leverage and SaaSoptimizing products,our andcapital an increasing mix of annual and consumption payments from customers.structure. This trend when combined with changes in new business growth, may result in free cash flow volatility across periods.
In the longer term, we view continued Subscription ARR growthgrowth, operating leverage, and the mix of annual versus upfront payment terms on our multi-year cash collectioncontracts as primary drivers of free cash flow. See the risk factor titled “We expect fluctuations in our financial results, making it difficult to project future results, and if we fail to meet the expectations of securities analysts or investors with respect to our results of operations, our stock price and the value of your investment could decline” in the section titled “Risk Factors.”
The following table presents a reconciliation of free cash flow to net cash provided by (used in) operating activities for the periods presented:
Subscription ARR Contribution Margin was 12%, 2%, (12)%, and (3812)% for the 12 months ended January 31, 2025,2026, 20242025 and 2023,2024, respectively. ForThe increase in Subscription ARR Contribution Margin was primarily driven by the strong year-over-year Subscription ARR growth outpacing the year-over-year growth in non-GAAP subscription costs of sales and non-GAAP operating expenses. In addition, for the 12 months ended January 31, 2025, the non-GAAP expenses includesincluded the one-time recognition of $22.8 million for employer payroll taxes due to the vesting of certain equity awards in conjunction with the initial public offering. The increase in Subscription ARR Contribution Margin was primarily driven by the strong year-over-year growth in Subscription ARR, compared to year-over-year growth in non-GAAP subscription costs of sales and non-GAAP operating expenses. We believe that this increase in Subscription ARR Contribution Margin reflects increased operating leverage in our business.
The following table presents the calculation of Subscription ARR Contribution Margin for the periods presented as well as a reconciliation of (i) non-GAAP subscription cost of revenue to subscription cost of revenue and (ii) non-GAAP operating expenses to operating expenses.expenses:
OurWhile revenuewe willhave fluctuatelargely basedcompleted onboth the timingsales of Rubrik-branded Appliances transitioning from us to our contract manufacturers in fiscal 2025 and the transition for transitioningnew ourand existing customers to RSC, including the RCDM-T licenses offered to existing customers, sales of RSC-Private,RSC andin whenfiscal qualified2026, we expect our subscription revenue to continue to benefit from customers choose to exerciseexercising or forfeitforfeiting their Subscription Credits,Credits the(which are customer options that are accounted for as material rights.rights) through fiscal 2027, although we expect the benefits to significantly reduce sequentially. These expectedbusiness trends, when combined with the transition of the sale of Rubrik-branded Appliances from us to our contract manufacturers, will limit andtransitions cause fluctuations to our total revenue growth throughand fiscallimit 2027.the comparability of our revenue with past performance. We primarily measure our business on the basis of Subscription ARR, as we believe it best reflects our actual growth and our growth prospects.
Certain prior period amounts reported in the consolidated financial statements and notes have been reclassified to conform to the current year presentation. For the years ended January 31, 2026, 2025 and 2024, the Company combined maintenance revenue and other revenue into “Other” on the consolidated statements of operations. The presentation of cost of revenue has been conformed to reflect the changes related to the presentation of revenues. Such reclassifications related to the presentation of revenue and cost of revenue did not impact total revenue, loss from operations or net loss.
SaaS includes SaaS subscription products like Anomaly Detection and Sensitive Data Monitoring sold standalone or with prior sales of term-based license offerings of CDM prior to the launch of the RSC platformsuite as well as sales of RSC. RSC is offered as a fully-hosted subscription or a hybrid cloud subscription. RSC is a fully-hosted subscription in the case of protection of cloud, SaaS, unstructured data, and unstructuredidentity data applications.providers. When RSC is securing enterprise applications, it is a hybrid cloud subscription which includes software hosted from the cloud (as a service) and an on-premise license for securing enterprise applications. The hybrid cloud subscription is accounted for as a single performance obligation because the software hosted from the cloud (as a service) and the on-premise software licenses are not separately identifiable and serve together to fulfill our promise to the customer, which is to provide a single, unified data security solution. Our RSC subscription capabilities are primarily sold as editions which bundle multiple products and include the Foundation Edition, Business Edition, Enterprise Edition, and Enterprise Proactive Edition. Subscription revenue related to SaaS is recognized ratably over the subscription period.
As customers continue to adoptadopted or transitiontransitioned to RSC, we expect the ratable portion of our subscription revenue tohas increase.increased. WeDuring expectthe transition, certain customers to consumeconsumed our platform and products through a mix of RSC and RCDM-T as they completecompleted the migration, which will resultresulted in a recognition of a portion of the associated revenue for these customers upfront. Furthermore, ourOur subscription revenue will also fluctuate when qualified customers choose to exercise or forfeit their customer options that are accounted for as material rights. InWe have experienced revenue growth benefits from the non-recurring revenue associated with material rights; however, we expect these benefits to decline over the course of fiscal 2025, subscription revenue saw some modest benefits as customers exercise or forfeit their Subscription Credits. We expect to see some further benefits through fiscal 2027 that we do not expect to continue in the long-term.2027. The combination of both of these factors willmay continue to limit and cause fluctuations in our subscription revenue growth throughduring fiscal 2027, depending in part on the timing of our existing customers’ transition to RSC.RSC and exercises or forfeitures of Subscription Credits (which are customer options that are accounted for as material rights).
Maintenance Revenue
Maintenance revenue represents fees earned from software updates on a when-and-if-available basis, telephone support, integrated web-based support, and Rubrik-branded Appliance maintenance relating to our perpetual licenses. Maintenance revenue is recognized ratably over the term of the service period. We expect our maintenance revenue to decrease as we drive adoption of RSC for existing maintenance customers and the transition to be largely completed by the end of fiscal 2026.
Other revenue representsincludes fees earned from sales of Rubrik-brandedprofessional Appliancesservices, software updates on a when-and-if-available basis, telephone and professionalintegrated services.web-based support, Rubrik-branded Appliance maintenance relating to our perpetual licenses, and Rubrik-branded Appliances. Revenue for Rubrik-branded Appliances is recognized when shipped to the customer. When we sell our software license with our Rubrik-branded Appliances, revenue for both the Rubrik-branded Appliances and software licenses are recognized at the same time. Revenue related to professional services is typically recognized as the services are performed. In the third quarter of fiscal 2023, we began transitioning the sale of Rubrik-branded Appliances from us to our contract manufacturers and this was largely completed in fiscal 2025. We expect other revenue to be largely driven by sales of professional services in the future and as a percentage of total revenue to decrease over time.
Cost of Maintenance Revenue
Cost of maintenance revenue primarily includes employee compensation and related expenses associated with customer support from our perpetual licenses. Over the long-term, we expect our cost of maintenance revenue to decrease as our maintenance revenue decreases.
Cost of other revenue primarily includes the cost of Rubrik-brandedprofessional Appliancesservices, employee compensation and professionalrelated services.expenses associated with customer support from our perpetual licenses, and the cost of Rubrik-branded Appliances. We expect cost of other revenue as a percentage of total cost of revenue to decrease due toas the transition of sales of Rubrik-branded Appliances transitioning from us to our contract manufacturers which was largely completed in fiscal 2025. Over the long-term, we expect the cost of other revenue to be largely driven by sales of professional services.
With increased adoption of RSC, we expect SaaS revenue to increase as a percentage of total revenue, which we expect will result in an increase in associated hosting costs. As customers adopt RSC, we expect our subscription gross margin to fluctuate through fiscal 2027. This is due to the revenue being recognized ratably over the subscription term rather than a portion being recognized upfront from subscription term-based licenses and associated increases in hosting costs for our SaaS solutions. We expect our subscription gross margin to fluctuate as customers adopt data security SaaS solutions on the RSC platform.suite.
Maintenance Gross Margin
We expect maintenance revenue to decrease as a percentage of total revenue, which we expect will result in a decrease in maintenance costs. We expect our maintenance margin to fluctuate until the end of fiscal 2026 as maintenance revenue and related costs decline as customers adopt RSC.
We expect other gross margin to decrease as a percentage of total revenue, which we expect will result in a decrease in cost of other revenue. We expect sales of Rubrik-branded Appliances to decrease as we transition the sale from us to contract manufacturers, which will result in a decrease in associated Rubrik-branded Appliance costs. The transition of the salesales of Rubrik-branded Appliances from us to our contract manufacturers was largely completed in fiscal 2025. Over the long-term, we expect other gross margin to be largely driven by sales of professional services.
Other non-operating income (expense) consists primarily of interest income, interest expense, loss on debt extinguishment, and foreign exchange gains and losses.
Growth in subscription revenue for the fiscal year ended January 31, 2026 was driven by growth in Subscription ARR and some benefits as customers exercised or forfeited their Subscription Credits. For the fiscal year ended January 31, 2026, non-recurring revenue related to material rights associated with Subscription Credits accounted for approximately $70.2 million. We expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits through fiscal 2027, although we expect the benefits to significantly reduce sequentially.
Growth in subscription revenue was driven by growth in Subscription ARR and modest benefits as customers exercised or forfeited their Subscription Credits but also benefited from the fiscal 2024 revenue headwind related to the transition to RSC and higher than expected upfront and non-recurring revenue. The higher than expected upfront and non-recurring revenue is also due to higher new sales and renewals of RSC-Private from regulated and government verticals in fiscal 2025 as well as the extension of RCDM-T to some of our customers, as they progress through their adoption of RSC.
Our Subscription ARR grew from $784.0$1.09 millionbillion as of January 31, 20242025 to $1,092.6$1.46 millionbillion as of January 31, 2025,2026, representing a 39%34% increase. Of the increase in Subscription ARR, 2approximately 1 percentage pointspoint areis a result of transitioning our existing maintenance customers to our subscription editions. A further indication of our ability to expand revenue from existing customers is through our average subscription dollar-based net retention rate which was greater thanover 120% as of January 31, 2025.2026. We had 2,2462,805 customers with $100,000 or more in Subscription ARR as of January 31, 2025,2026, increasing from 1,7422,246 as of January 31, 2024.2025.
MaintenanceOther revenuerevenue, associatedwhich withconsists primarily of sales of perpetual licenses of our legacy CDM productproduct, Rubrik-branded Appliances and professional services, decreased for the fiscal year ended January 31, 2025.2026. MaintenanceOther revenue represented 3%4% and 6%7% of total revenue for the fiscal yearyears ended January 31, 20252026 and 2024,2025, respectively. We expect theThe transition of existing maintenance customers adopting RSC subscription offerings to bewas largely completed by the end ofin fiscal 2026. We expect our other revenue as a percentage of total revenue to continue to decrease.
Other revenue, which consists primarily of sales of Rubrik-branded Appliances and professional services, decreased for the fiscal year ended January 31, 2025. Sales of Rubrik-branded Appliances decreased by $10.4 million for the fiscal year ended January 31, 2025, as the transition of sales of our Rubrik-branded Appliances from us to our contract manufacturers is largely complete. We expect our other revenue as a percentage of total revenue to continue to decrease.
Cost of subscription revenue increased for the fiscal year ended January 31, 20252026 primarily duedriven to the recognition of stock-based compensation expense of $49.5 million after and as a result of the completion of our IPO,by an increase inof $48.5$26.9 million in hosting costs due to the launch and adoption of more SaaS products by our customers, and an increase of $10.6$12.3 million from growth in our customer support organization.organization, an increase of $4.1 million of amortization of capitalized internal-use software and an increase of $3.8 million of amortization of acquired technology, partially offset by $33.1 million decrease in stock-based compensation expense as a result of higher RSU expense in the prior year related to the recognition of cumulative stock-based compensation expense upon our IPO.
Cost of maintenance revenue decreased for the fiscal year ended January 31, 2025 primarily due to $3.1 million decrease in our customer support organization costs relating to maintenance revenue as we no longer offer new perpetual licenses and as existing maintenance customers adopted RSC subscription offerings, offset by an increase of $3.1 million in stock-based compensation expense we recognized after and as a result of the completion of our IPO.
Cost of other revenue increaseddecreased for the fiscal year ended January 31, 20252026 primarily duedriven toby $14.5a $15.0 million decrease in stock-based compensation expense we recognized after andexpense, as a result of higher RSU expense in the completionprior period related to the recognition of cumulative stock-based compensation expense upon our IPO,IPO. partiallyThe offset by aremaining decrease inis due to lower costs associated with decreased sales of Rubrik-branded AppliancesAppliances, costsas the transition of $10.9 million as we are transitioning the salesales of Rubrik-branded Appliances from us to our contract manufacturers.manufacturers was largely completed in fiscal 2025.
Subscription gross margin decreasedincreased for the fiscal year ended January 31, 2025 due to the stock-based compensation expense we recognized after and2026 as a result of higher RSU expense in the completionprior periods related to the recognition of cumulative stock-based compensation expense upon our IPOIPO, andpartially offset by an increase in hosting costs associated with our development and launch of more SaaS products.
Maintenance gross margin decreased for the fiscal year ended January 31, 2025 due to the stock-based compensation expense we recognized after and as a result of the completion of our IPO.
Other gross margin decreasedincreased for the fiscal year ended January 31, 2025 due to the stock-based compensation expense we recognized after and2026 as a result of higher RSU expense in the completionprior periods related to the recognition of cumulative stock-based compensation expense upon our IPO.
Research and development expenses decreased for the fiscal year ended January 31, 2026 primarily driven by a decrease of $194.3 million in stock-based compensation expense as a result of higher RSU expense in the prior periods related to the recognition of cumulative stock-based compensation expense upon our IPO in April 2024. The decrease was partially offset by an increase of $22.8 million in employee related costs driven by an increase in headcount, an increase of $5.6 million in hosting and software expense and $5.4 million in consulting services expense to support the Company’s growth.
Research and development expenses increased for the fiscal year ended January 31, 2025. Employee compensation and related expenses increased by $318.2 million due to $293.5 million of stock-based compensation expense we recognized after and as a result of the completion of our IPO and increases in headcount as we continued to develop new products and enhance the functionalities of our existing products.
Sales and marketing expenses decreased for the fiscal year ended January 31, 2026 primarily driven by a decrease of $214.6 million in stock-based compensation expense as a result of higher RSU expense in the prior periods related to the recognition of cumulative stock-based compensation expense upon our IPO in April 2024. The decrease was partially offset by an increase of $60.7 million in marketing expense as a result of advertising costs, marketing events and related costs to promote and expand our market presence, and an increase of $49.1 million in employee related costs driven by an increase in headcount.
Sales and marketing expenses increased for the fiscal year ended January 31, 2025. Employee compensation and related expenses increased by $366.5 million due to $329.1 million of stock-based compensation expense we recognized after and as a result of the completion of our IPO and increases in headcount.
General and administrative expenses decreased for the fiscal year ended January 31, 2026 primarily driven by a decrease of $127.5 million in stock-based compensation expense as a result of higher RSU expense in the prior periods related to the recognition of cumulative stock-based compensation expense upon our IPO in April 2024. The decrease is offset by an increase of $11.8 million in charitable donations, an increase of $8.3 million in consulting services expense, an increase of $3.5 million in hosting and software expense and an increase of $2.7 million in employee related costs driven by an increase in headcount.
General and administrative expenses increased for the fiscal year ended January 31, 2025. Employee compensation and related expenses increased by $232.4 million due to $218.6 million of stock-based compensation expense we recognized after and as a result of the completion of our IPO and increases in headcount.
Interest expense increaseddecreased for the fiscal year ended January 31, 20252026 primarily due toas our Prior Credit Facility and Amended Credit Facility (eachwas asfully definedrepaid below).in June 2025.
Loss on debt extinguishment increased for the fiscal year ended January 31, 2026 due to the write-off of unamortized debt discount and issuance costs and prepayment premium paid upon the full repayment of borrowings under our Amended Credit Facility.
Other income (expense), net includes foreign exchange gains and losses and fluctuations are driven by the strengthening or weakening of the US dollar against foreign currencies on our foreign-denominated intercompany payables.
Our income tax expense increased for the fiscal year ended January 31, 2026 due to increased profits in our foreign subsidiaries, mainly due to non-deductible stock-based compensation.
What changed in the latest 10-Q
Risk Factors
Largest changes
Several jurisdictions around the globe, including in Europe, have proposed, enacted, or are considering laws governing AI tools, including the EU’s AIsee in full comparisonAct.Act, which is now in force and being enforced on a phased basis. In the United States, where our operations are headquartered, there is no single comprehensive federal AI law, but several states are applying their data and consumer protection laws to AI, and/or have enacted, or are enactingor consideringAI-specific legalframeworks on AI,frameworks, such asthelaws in California, Utah, Colorado and New York addressing AI transparency, automated decision-making, and consumer protection. CaliforniaBothasDisclosurealsoLaw,finalized regulations under theUtahCCPAArtificial Intelligence Policy Act, the Colorado Artificial Intelligence Act and the CCPA’s regulations regardinggoverning automated decision-making technology.WeThe volume of state AI legislation continues to increase, and we expect other jurisdictions will adopt similarlaws,laws.and, asAs a result of the rapidly evolving regulatory landscape, implementation standards, enforcement practices, and available scope of protection are likely to remain uncertain for the foreseeable future, and we cannot yet determine the impact future laws, regulations, or standards may have on our business (including our positioning with respect to our competition) and may not always be able to anticipate how to respond to these laws or regulations. Additionally, certain privacy laws extend rights to consumers (such as the right to delete certain personal data) and regulate automated decision making, which may be incompatible with our use of AI. These obligations may make it harder for us to conduct our business using AI, lead to regulatory fines or penalties, require us to disclose or provide greater transparency regarding the nature of our AI Products and the data we have employed to train them, require us to change our business practices, retrain our AI Products, or prevent or limit our use of AI. For example, the FTC has required other companies to delete (or “disgorge”) both the personal data that the FTC alleged were collected in violation of privacy laws as well as the algorithms and other insights that were developed or generated using such data. If we cannot use AI or that use is restricted, our business may be less efficient, or we may be at a competitive disadvantage.
In January 2025, the current administration began issuing executive orders identifying new government policy and directing U.S. federal agencies to evaluate their current actions, including certain spending, to ensure that such actions are consistent with the new administration’s priorities. Some of those executive orders as well as other agency designations, such as supply-chain risk designations,see in full comparisonarehavethebeensubjectschallengedofinpendinglitigationlitigation,and may be subject to injunctions or other judicial review, and there remains significant uncertainty aboutthetheirways in which agencies will implement the new executive ordersimplementation andagencyultimatedesignations.effect. Such implementation could negatively affect our current and future business with U.S. government agencies.
Also, the rapid evolution of AI technologies may require the expenditure of significant resources to design, develop, test and maintain our products and services to help ensure that our AI features and tools are implemented in accordance with applicable law and regulation and in a socially responsible manner and to minimize any real or perceived unintended harmful impacts. Our increasing adoption and use of AI technologies across our business may also result in increased operating expenses, including costs associated with third-party AI tools and related computing resources. We also may need to expend further resources to adjust our business practices, as these laws and regulations evolve, especially where requirements across jurisdictions are inconsistent.see in full comparison
“This may also harm our competitive position against larger enterprises whose competitive data security solutions are certified. Further, there can be no assurance that we will secure commitments or contracts with government entities even following such certifications, which could harm our margins, business, financial condition, and results of operations. …”see in full comparison
We believe our future success will depend in large part on the growth, if any, in the market for data security and AI solutions. Traditionally, the cybersecurity industry has been focused on securing information technology infrastructure to prevent, detect, and investigate cyberattacks. Our platform brings a new approach to cybersecurity, which involves protecting our customers’ data across enterprise, cloud, SaaS, unstructured data, and identity providers, observing the data itself to proactively identify emergent threats, remediating data security threats, and recovering protected data following a cybersecurity event, as well as helping customers manage risks associated with AI agents. The market for data security and AI solutions, such as our platform and data security products, is at an early stage and rapidly evolving. As such, it is difficult to predict this market’s potential growth, if any, customer adoption and retention rates, customer demand for data security platforms, or the success of competitive products. In the past, customer adoption of our platform and data security products has been driven by the need for data resilience due to increasing ransomware activity. We do not know whether the trends of increasing ransomware activity, or of increasing adoption of our platform and data security products such as ours that we have experienced in the past, will continue in the future. Any expansion in this market depends on a number of factors, including the adoption of AI agents and demand for solutions to monitor and govern their activity, the cost, performance, and perceived value associated with our platform and data security products and similar solutions of our competitors, including preference to manage security with existing infrastructure security tools alone, rather than investing in a platform based solution. The markets for some of our solutions are new, unproven, and evolving, and our future success depends on growth and expansion of these markets. If our platform and data security products do not achieve widespread adoption or there is a reduction in demand for our platform and data security products due to a lack of customer acceptance, technological challenges, competing products or solutions, privacy concerns, decreases in corporate spending, weakening economic conditions, or otherwise, it could result in early terminations, reduced customer retention rates, or decreased revenue, any of which would adversely affect our business, financial condition, and results of operations. You should consider our business and growth prospects in light of the risks and difficulties we encounter in this new and evolving market.see in full comparison
We sell to U.S. federal, state, and local, as well as foreign governmental agency customers. Sales to such entities are subject to a number of challenges and risks. Selling to such entities can be highly competitive, expensive, and time-consuming, often requiring significant upfront time and expense without any assurance that these efforts will generate a sale. Government contracting requirements may change and in doing so restrict our ability to sell into the government sector until we have obtained any required government certifications. Further, achieving and maintaining government certifications, such as U.S. Federal Risk and Authorization Management Program (“FedRAMP”) certification for our data security solutions, may require significant upfront and ongoing cost, time, and resources. If we do not maintain our existing FedRAMP certification or obtain additional certifications for our data security solutions, we may not be able to sell certain solutions to the U.S. federal government and public sector customers as well as eligible private sector customers that require such certification for their intended use cases, which could harm our growth, business, and results of operations.see in full comparisonThis may also harm our competitive position against larger enterprises whose competitive data security solutions are certified. Further, there can be no assurance that we will secure commitments or contracts with government entities even following such certifications, which could harm our margins, business, financial condition, and results of operations. Government demand and payment for our data security solutions are affected by public sector budgetary cycles, procurement policies and funding authorizations, with funding reductions or delays, including in connection with an extended government shutdown, adversely affecting public sector demand for our data security solutions.
Full comparison: every changed paragraph (27)
Our revenue was $387.1$814.3 million and $278.5$588.3 million for the threesix months ended AprilJuly 30,31, 2026 and 2025, respectively. You should not rely on the revenue growth of any prior period as an indication of our future performance. Even if our revenue continues to increase, we expect that our revenue growth rate will fluctuate in the future as a result of a variety of factors. While we have largely completed both the sales of Rubrik-branded Appliances transitioning from us to our contract manufacturers in fiscal 2025 and the transition for new and existing customers to sales of RSC in fiscal 2026, we expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits (which are customer options that are accounted for as material rights) through fiscal 2027,, although we expect the benefits to significantlycontinue reduceto sequentially.decline. These business transitions cause fluctuations to our total revenue growth and limit the comparability of our revenue with past performance.
We believe our future success will depend in large part on the growth, if any, in the market for data security and AI solutions. Traditionally, the cybersecurity industry has been focused on securing information technology infrastructure to prevent, detect, and investigate cyberattacks. Our platform brings a new approach to cybersecurity, which involves protecting our customers’ data across enterprise, cloud, SaaS, unstructured data, and identity providers, observing the data itself to proactively identify emergent threats, remediating data security threats, and recovering protected data following a cybersecurity event, as well as helping customers manage risks associated with AI agents. The market for data security and AI solutions, such as our platform and data security products, is at an early stage and rapidly evolving. As such, it is difficult to predict this market’s potential growth, if any, customer adoption and retention rates, customer demand for data security platforms, or the success of competitive products. In the past, customer adoption of our platform and data security products has been driven by the need for data resilience due to increasing ransomware activity. We do not know whether the trends of increasing ransomware activity, or of increasing adoption of our platform and data security products such as ours that we have experienced in the past, will continue in the future. Any expansion in this market depends on a number of factors, including the adoption of AI agents and demand for solutions to monitor and govern their activity, the cost, performance, and perceived value associated with our platform and data security products and similar solutions of our competitors, including preference to manage security with existing infrastructure security tools alone, rather than investing in a platform based solution. The markets for some of our solutions are new, unproven, and evolving, and our future success depends on growth and expansion of these markets. If our platform and data security products do not achieve widespread adoption or there is a reduction in demand for our platform and data security products due to a lack of customer acceptance, technological challenges, competing products or solutions, privacy concerns, decreases in corporate spending, weakening economic conditions, or otherwise, it could result in early terminations, reduced customer retention rates, or decreased revenue, any of which would adversely affect our business, financial condition, and results of operations. You should consider our business and growth prospects in light of the risks and difficulties we encounter in this new and evolving market.
Although we were founded in December 2013, we only began offering our products and services in the fiscal year ended January 31, 2016, and we began offering RSC as a cloud native SaaS solution in fiscal 2023 and introduced the RAC suite in fiscal 2026. As a result of our limited operating history, our ability to accurately forecast our future results of operations is limited and subject to a number of uncertainties, including our ability to plan for and forecast future growth. Our historical revenue growth should not be considered indicative of our future performance. In future periods, our revenue growth may fluctuate, slow or decline due to a number of factors, including changes in product mix. While we have largely completed both the transition of sales of Rubrik-branded Appliances from us to our contract manufacturers in fiscal 2025 and the transition for new and existing customers to sales of RSC in fiscal 2026, we expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits (which are customer options that are accounted for as material rights) through fiscal 2027,, although we expect the benefits to significantlycontinue reduceto sequentially.decline. These business transitions cause fluctuations to our total revenue growth and limit the comparability of our revenue with past performance.
We have experienced net losses in each period since inception. We generated net losses of $(41.9103.6) million and $(102.1198.0) million for the threesix months ended AprilJuly 30,31, 2026 and 2025, respectively. As of AprilJuly 30,31, 2026 and January 31, 2026, we had an accumulated deficit of $(3.233.29) billion and $(3.19) billion, respectively. While we have experienced rapid revenue growth in recent periods, we are not certain whether or when we will obtain a high enough volume of sales to achieve or maintain profitability in the future. In particular, as we expand the availability of our platform, increase our ability to secure data across multiple different sources, and add more capabilities, our ability to achieve and maintain profitability will be highly dependent on our ability to successfully market our platform and data security products to new and existing customers. We also expect our costs and expenses to increase in future periods, which could negatively affect our future results of operations if our revenue does not increase. In particular, we intend to continue to expend significant funds to further develop our offerings, including by introducing new features and functionality and securing additional applications, and to expand our sales, marketing, and services teams to drive new customer adoption, expand the use of our data security products by existing customers, support international expansion, and implement additional systems and processes to effectively scale operations. We will also face increased compliance costs associated with growth, the planned expansion of our customer base and pipeline, international expansion, and being a public company. In addition, our data security and AI solutions operate on a public cloud infrastructure provided by third-party vendors, including Google Cloud (“GCP”), Microsoft Azure (“Azure”), and Amazon Web Services (“AWS”), and our costs and gross margins are significantly influenced by the prices we are able to negotiate with these public cloud providers. To the extent we are able to drive adoption of our platform and data security products, we may incur increased costs related to our public cloud contracts, which would negatively impact our gross margins. Our efforts to grow our business may be costlier than we expect, or the rate of our growth in revenue may be slower than we expect, and we may not be able to increase our revenue enough to offset our increased operating expenses. In addition, our efforts and investments to implement systems and processes to scale operations may not be sufficient or may not be appropriately executed.executed, or may be costlier than we expect. As a result, we may incur significant losses in the future for a number of reasons, including the other risks described herein, unforeseen expenses, difficulties, complications, or delays, and other unknown events. If we are unable to achieve and sustain profitability, the value of our business and Class A common stock may significantly decrease.
Furthermore, we have historically sold our products to customers as perpetual licenses with associated maintenance contracts or as subscription term-based licenses with associated support, and with respect to the latter, we recognized a portion of the revenue upfront at the time we transferred control of the subscription term-based license to the customer and deferred the remainder. We have substantially completed our transition to offering our platform primarily through SaaS subscriptions, and a significant majority of our new and existing customers have adopted RSC on a SaaS subscription basis. As of the end of fiscal 2026, SaaS subscriptions represented a majority of our total revenue. We have also largely completed the transition of sales of Rubrik-branded Appliances from us to our contract manufacturers in fiscal 2025. We expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits (which are customer options that are accounted for as material rights) through fiscal 2027,, although we expect the benefits to significantlycontinue reduceto sequentially.decline. These business transitions may continue to cause fluctuations to our total revenue growth and limit the comparability of our revenue with past performance. In addition, the stock-based compensation expense related to our RSUs has resulted in and will continue to result in significant increases in our expenses in future periods, which may negatively impact our ability to achieve profitability.
Our solutions are complex and, like all software, have in the past contained and may in the future contain undetected defects, errors, or vulnerabilities. From time to time, we identify certain vulnerabilities in our information systems. While we take steps designed to mitigate the risks associated with known vulnerabilities, there can be no assurance that any vulnerability mitigation measures will be effective. Moreover, we may also experience delays in developing and deploying remedial measures and patches designed to address any identified vulnerabilities. Real or perceived defects, errors, or vulnerabilities in our solutions, the failure of our solutions to secure, observe, and restore our customers’ data,data or to monitor, govern, or remediate AI agent activity, misconfiguration of our solutions, the exploitation of any known or unknown vulnerabilities, or the failure of customers to deploy our solutions in combination with industry best practices could harm our reputation, result in a loss of, or delay in, market acceptance of our solutions, result in a loss of existing or potential customers, and adversely affect our business, financial condition, and results of operations. We are continuing to evolve the features and functionality of our products through updates and enhancements, and as we do so, we may inadvertently introduce defects, errors, or vulnerabilities that may not be detected until after deployment by our customers. In addition, implementation or use of our solutions that is not correct or as intended may result in adverse consequences such as inadequate performance and disruptions in service. Moreover, if we acquire companies or technologies developed by third parties, difficulties integrating such acquired technologies may result in product flaws or software vulnerabilities.
Cyberattacks, malicious internet-based activity, online and offline fraud, and other similar activities threaten the confidentiality, integrity, and availability of our Sensitive Information and information technology systems, and those of the third parties with whom we work. Such threats are prevalent, continuing to rise, increasingly difficult to detect, and come from a variety of sources, including traditional computer “hackers,” threat actors, “hacktivists,” organized criminal threat actors, personnel (such as through theft, misuse, or accidental disclosure), sophisticated nation states, and nation-state-supported actors. Some actors now engage in and are expected to continue to engage in cyberattacks, including without limitation nation-state actors for geopolitical reasons and in conjunction with military conflicts and defense activities. During times of war and other major conflicts, we and the third parties with whom we work, and our customers may be vulnerable to a heightened risk of these attacks, including retaliatory cyberattacks, that could materially disrupt our systems and operations, supply chain, and ability to produce, sell, and distribute our solutions. We and the third parties with whom we work are subject to a variety of evolving threats, including but not limited to social-engineering attacks (including through phishing attacks), malicious code (such as viruses and worms), computer generated or altered fraudulent content (i.e., “deep fakes,” which may be increasingly difficult to identify), malware (including as a result of advanced persistent threat intrusions), denial-of-service attacks, credential stuffing attacks, credential harvesting, personnel misconduct or error, other inadvertent compromises of our systems and data (including those arising from process, coding, or human error), ransomware attacks, supply-chain attacks, software bugs, server malfunctions, software or commodity appliance failures, loss of data or other information technology assets, adware, telecommunications failures, attacks enhanced or facilitated by AI, including autonomous AI agents, and other similar threats.
We use and increasingly rely upon AI tools in our business, including generative AI and agentic AI, including to generate code and other materials incorporated into our products, proprietary software, and systems, and for other internal and external uses, and we are making investments to expand our generative and agentic AI capabilities, including recent and future product offerings such as Rubrik Agent Cloud, which is designed to accelerate enterprise AI agent deployments. Advanced generative AI tools, which may produce content indistinguishable from that generated by humans, are a relatively novel development, with benefits, risks, and liabilities still unknown. Recent decisions of governmental entities and courts (such as the U.S. Copyright Office, U.S. Patent and Trademark Office, and U.S. Court of Appeals for the Federal Circuit) interpret U.S. copyright and patent law as limited to protecting works and inventions created by human authors and inventors, respectively. We are therefore unlikely to be able to obtain U.S. copyright or patent protection for works or inventions wholly created by a generative AI tool,tool. andWhile our ability to obtain U.S. copyright and patent protection for source code, text, images, inventions, or other materials, which are developed with some use of generative AI tools, is not categorically barred, the scope of such protection may bedepend limited,on ifthe availablenature atand all.extent of human contribution, and the law in this area continues to develop. Likewise, the availability of such IP protections in other countries is unclear. In addition, we may have little or no insight into and no control over the content and materials used by vendors and model providers to train these generative AI tools, or that otherwise use or incorporate these generative AI tools into their own offerings. There is ongoing litigation over whether the use of copyrighted materials to train the AI models used in these tools is lawful, and the impact of decisions in such litigation on our use of generative AI tools is unknown. Furthermore, our vendors who use generative and agentic AI tools in their own offerings may not meet existing or rapidly evolving regulatory or industry standards, including with respect to the rights of others, privacy and data security. Additionally, our use of open-source and other third-party generative and agentic AI tools, including to develop source code, text, images, inventions, or other materials, may expose us to greater risks than utilizing contracted human developers, as such AI tools typically do not come with warranties or indemnities with respect to the output generated by such AI tools, and generative and agentic AI tools may also hallucinate, providing erroneous output or making erroneous decisions. Furthermore, some AI tools may be offered under terms that do not protect the confidentiality of the prompts or inputs that users submit to such tools and may use prompts or inputs to train shared AI models, potentially resulting in third-party users receiving outputs containing information from prompts or inputs (including confidential, competitive, proprietary, or personal data) that we submitted to the tool. The disclosure and use of personal data in AI technologies is also subject to various privacy laws and other privacy obligations. Prior to implementing an AI tool (including generative AI tools), our AI governance committee (including leaders from our Engineering, Product, Legal, and Information Security teams) performs an analysis and review of each AI tool for which pre-approval is required according to our policies, including evaluation of potential legal, security, and business risks and steps that can be taken to mitigate any such risks. The selection criteria and analysis include consideration of how use of the AI tool could raise issues relating to confidential information, personal data and privacy, customer data and contractual obligations, open source software, copyright and other intellectual property rights, transparency, output accuracy and reliability, and security.
Several jurisdictions around the globe, including in Europe, have proposed, enacted, or are considering laws governing AI tools, including the EU’s AI Act.Act, which is now in force and being enforced on a phased basis. In the United States, where our operations are headquartered, there is no single comprehensive federal AI law, but several states are applying their data and consumer protection laws to AI, and/or have enacted, or are enacting or consideringAI-specific legal frameworks on AI,frameworks, such as thelaws in California, Utah, Colorado and New York addressing AI transparency, automated decision-making, and consumer protection. California Bothas Disclosurealso Law,finalized regulations under the UtahCCPA Artificial Intelligence Policy Act, the Colorado Artificial Intelligence Act and the CCPA’s regulations regardinggoverning automated decision-making technology. WeThe volume of state AI legislation continues to increase, and we expect other jurisdictions will adopt similar laws,laws. and, asAs a result of the rapidly evolving regulatory landscape, implementation standards, enforcement practices, and available scope of protection are likely to remain uncertain for the foreseeable future, and we cannot yet determine the impact future laws, regulations, or standards may have on our business (including our positioning with respect to our competition) and may not always be able to anticipate how to respond to these laws or regulations. Additionally, certain privacy laws extend rights to consumers (such as the right to delete certain personal data) and regulate automated decision making, which may be incompatible with our use of AI. These obligations may make it harder for us to conduct our business using AI, lead to regulatory fines or penalties, require us to disclose or provide greater transparency regarding the nature of our AI Products and the data we have employed to train them, require us to change our business practices, retrain our AI Products, or prevent or limit our use of AI. For example, the FTC has required other companies to delete (or “disgorge”) both the personal data that the FTC alleged were collected in violation of privacy laws as well as the algorithms and other insights that were developed or generated using such data. If we cannot use AI or that use is restricted, our business may be less efficient, or we may be at a competitive disadvantage.
Also, the rapid evolution of AI technologies may require the expenditure of significant resources to design, develop, test and maintain our products and services to help ensure that our AI features and tools are implemented in accordance with applicable law and regulation and in a socially responsible manner and to minimize any real or perceived unintended harmful impacts. Our increasing adoption and use of AI technologies across our business may also result in increased operating expenses, including costs associated with third-party AI tools and related computing resources. We also may need to expend further resources to adjust our business practices, as these laws and regulations evolve, especially where requirements across jurisdictions are inconsistent.
Our revenue mix may vary over time due to a number of factors, including the mix of our subscriptions for different data security products and the timingestimates ofand remainingassumptions used to account for certain customer migrationsarrangements, toincluding RSCSubscription or other SaaS offerings.Credits. Our subscription revenue includes revenue from sales of subscription term-based licenses, a portion of which is recognized upfront when we transfer control of the subscription term-based license to the customer, and revenue from sales of SaaS subscriptions and support, which is recognized ratably over the contract period. As we have substantially completed our transition from subscription term-based licenses to SaaS subscriptions and migrated a significant majority of our existing customers to RSC, the proportion of revenue recognized upfront versus ratably over time has evolved. However, the timing of remaining customer migrations, as well as the estimates and assumptions used to account for certain customer arrangements, including Subscription Credits (which are customer options that are accounted for as material rights) related to Refresh Rights, may continue to affect the amount and timing of revenue recognized. In addition, future changes in our product offerings, pricing models, contract structures, customer purchasing patterns, or other business initiatives may further affect our revenue mix and the timing of revenue recognized. These factors make it challenging to forecast our revenue as the mix of solutions and services, the timing of our customers’ RSC transition, as well as the size of contracts, are difficult to predict.
•Cloud and SaaS data management vendors with products that compete in some of our markets; and
•Vendors that provide cyber/ransomware detection and investigation, data security posture management, identity security posture management, Active Directory and Entra ID security and protection, insider threat detection, data classification, and other data security or data governance technologies.technologies; and
•Vendors that provide agent security, including observability, governance, identity, and posture.
•margin impact due to increased cost of the Rubrik-branded Appliances that are not yet transitioned from us to our contract manufacturers;
•our ability to control costs, including hosting costs and our operating expenses including investments in AI tools;
Our revenue may fluctuate because of the length and unpredictability of the sales cycle for our solutions, particularly with respect to large organizations and government entities. For example, in light of current macroeconomic conditions, such as higher cost-consciousness around information technology budgets, as well as constraints affecting the availability or pricing of compatible commodity servers needed to deploy our solutions, including as a result of global chip shortages or allocation constraints, we have observed a lengthening of our sales cycles. Customers often view the subscription to our platform as a significant strategic decision and, as a result, frequently require considerable time to evaluate, test, and qualify our platform, including from a security and privacy perspective, prior to entering into or expanding a relationship with us. Large enterprises and government entities in particular often undertake a significant evaluation process that further lengthens our sales cycle. Additionally, RSCour hosted SaaS and other SaaSAI solutions may elongate our sales cycles as a result of additional customer security and privacy evaluations.
We sell to U.S. federal, state, and local, as well as foreign governmental agency customers. Sales to such entities are subject to a number of challenges and risks. Selling to such entities can be highly competitive, expensive, and time-consuming, often requiring significant upfront time and expense without any assurance that these efforts will generate a sale. Government contracting requirements may change and in doing so restrict our ability to sell into the government sector until we have obtained any required government certifications. Further, achieving and maintaining government certifications, such as U.S. Federal Risk and Authorization Management Program (“FedRAMP”) certification for our data security solutions, may require significant upfront and ongoing cost, time, and resources. If we do not maintain our existing FedRAMP certification or obtain additional certifications for our data security solutions, we may not be able to sell certain solutions to the U.S. federal government and public sector customers as well as eligible private sector customers that require such certification for their intended use cases, which could harm our growth, business, and results of operations. This may also harm our competitive position against larger enterprises whose competitive data security solutions are certified. Further, there can be no assurance that we will secure commitments or contracts with government entities even following such certifications, which could harm our margins, business, financial condition, and results of operations. Government demand and payment for our data security solutions are affected by public sector budgetary cycles, procurement policies and funding authorizations, with funding reductions or delays, including in connection with an extended government shutdown, adversely affecting public sector demand for our data security solutions.
This may also harm our competitive position against larger enterprises whose competitive data security solutions are certified. Further, there can be no assurance that we will secure commitments or contracts with government entities even following such certifications, which could harm our margins, business, financial condition, and results of operations. Government demand and payment for our data security solutions are affected by public sector budgetary cycles, procurement policies and funding authorizations, with funding reductions or delays, including in connection with an extended government shutdown, adversely affecting public sector demand for our data security solutions.
In January 2025, the current administration began issuing executive orders identifying new government policy and directing U.S. federal agencies to evaluate their current actions, including certain spending, to ensure that such actions are consistent with the new administration’s priorities. Some of those executive orders as well as other agency designations, such as supply-chain risk designations, arehave thebeen subjectschallenged ofin pendinglitigation litigation,and may be subject to injunctions or other judicial review, and there remains significant uncertainty about thetheir ways in which agencies will implement the new executive ordersimplementation and agencyultimate designations.effect. Such implementation could negatively affect our current and future business with U.S. government agencies.
If customers or other third parties with whom we do business make intellectual property infringement or other indemnification claims against us, we will incur significant legal expenses and may have to pay damages,damages or license fees, or stop using technology found to be in violation of a third party’s rights. We may also have to seek a license for the technology. Such licenses may not be available on reasonable terms, if at all, and may significantly increase our operating expenses or may require us to restrict our business activities and limit our ability to deliver certain solutions or features. We may also be required to develop alternative non-infringing technology, which could either require significant effort and expense or cause us to alter our solutions, or both, which could harm our business. Large indemnity obligations, whether for intellectual property or in certain limited circumstances, other claims, would harm our business, financial condition, and results of operations.
Large indemnity obligations, whether for intellectual property or in certain limited circumstances, other claims, would harm our business, financial condition, and results of operations.
The tax regimes to which we are subject or under which we operate, including income and non-income taxes, are unsettled in certain respects and may be subject to significant change. Changes in tax laws or regulations, or changes in interpretations of existing laws and regulations, could materially affect our financial condition and results of operations. Legislation commonly referred to as the One Big Beautiful Bill Act (the “OBBBA”), as well as the Tax Cuts and Jobs Act (the “Tax Act”), the Coronavirus Aid, Relief, and Economic Security Act, and the Inflation Reduction Act made many significant changes to the U.S. tax laws. For example, for tax years beginning after December 31, 2024, the OBBBA restores the deductibility of domestic research and development expenses in the year incurred, which expenses had been required under the Tax Act to be capitalized and subsequently amortized over five years. The OBBBA did not change the tax treatment of expenses incurred in research and development activities conducted outside the United States, which expenses continue to be required to be capitalized and amortized over 15 years. The Tax Act also includes certain U.S. tax base anti-erosion provisions, the global intangible low-taxed income (“GILTI”) provisions, and the base erosion anti-abuse tax (“BEAT”) provisions. The GILTI provisions require us to include in our U.S. taxable income foreign subsidiary earnings in excess of an allowable return on the foreign subsidiary’s tangible assets. The OBBBA modified the GILTI provisions to refer to net CFC tested income (“NCTI”), eliminate the allowable return on the foreign subsidiary’s tangible assets for taxable years beginning after December 31, 2025, and increase but make permanent the effective tax rate on NCTI. We currently have no foreign subsidiaries with material earnings. Therefore, this provision currently has no material impact on us. The BEAT provisions apply to companies with average annual gross receipts of $500 million or more for the prior three-year period, eliminate the deduction of certain base-erosion payments made to related foreign corporations, and impose a minimum tax if greater than regular tax. We are evaluating the BEAT rules and do not currently expect the BEAT rules to have a material impact on U.S. tax expense in the near term; however, the potential impact of the BEAT rules on us in the future is not certain.
Our Class B common stock has 20 votes per share, whereas our Class A common stock has one vote per share. As a result, as of AprilJuly 30,31, 2026, holders of our Class B common stock, including our executive officers and directors and their affiliates, together hold approximately 85%83% of the voting power of our outstanding capital stock, and our directors, executive officers, and affiliated stockholders beneficially own approximately 22%19% of our outstanding classes of common stock as a whole, but control approximately 81%78% of the voting power of our outstanding common stock. As a result, our executive officers, directors, and other affiliates have significant influence over our management and affairs and over all matters requiring stockholder approval, including election of directors and significant corporate transactions, such as a merger or other sale of the company or our assets, for the foreseeable future.
Sales of a substantial number of shares of our Class A common stock in the public market following our IPO, or the perception that these sales might occur, could depress the market price of our Class A common stock and could impair our ability to raise capital through the sale of additional equity securities. Many of our equity holders have substantial unrecognized gains on the value of the equity they hold, and therefore, they may take steps to sell their shares or otherwise secure the unrecognized gains on those shares. We are unable to predict the timing of or the effect that such sales may have on the prevailing market price of our Class A common stock.
We are unable to predict the timing of or the effect that such sales may have on the prevailing market price of our Class A common stock.
In addition, as of AprilJuly 30,31, 2026, there were 8,817,6938,657,126 shares of Class B common stock issuable upon the exercise of options and 6,199,6765,094,302 restricted stock units (“RSUs”), to be settled in shares of our Class B common stock. We have registered all of the shares of Class A common stock issuable upon exercise of outstanding options, the vesting and settlement of outstanding RSUs, and other equity incentives we may grant in the future, for public resale under the Securities Act. The shares of Class A common stock will become eligible for sale in the public market to the extent such options are exercised or RSUs are vested and settled, subject to compliance with applicable securities laws.
Management's Discussion & Analysis (MD&A)
Largest changes
Cost of other revenue includes the cost of professional services, employee compensation and related expenses associated with customer support from our perpetual licenses, and the cost of Rubrik-branded Appliances.see in full comparisonWe expect cost of other revenue as a percentage of total cost of revenue to decrease asAlthough the transition of sales of Rubrik-branded Appliances from us to our contract manufacturers was largely completed in fiscal2025.2025,Overa small portion of thelong-term,salesweremains with us, primarily in the APAC region. Cost of other revenue may fluctuate in the near term from the remaining portion of sales of Rubrik-branded Appliances that remains with us as well as from supply chain conditions, resulting from global chip shortages and increases in server prices. We expect the cost of other revenuetoasbealargely driven by salespercentage ofprofessionaltotalservices.cost of revenue to decrease over the long term.
“For the six months ended July 31, 2025, net cash provided by operating activities of $104.4 million resulted primarily from a net loss of $198.0 million, partially offset by $162.0 million of stock-based compensation, $50.9 million of amortization of deferred commissions, $16.5 million for depreciation and amortization, $6.7 million of loss on debt extinguishment, and $66.9 million of net cash inflow from changes in operating assets and liabilities. …”see in full comparison
“For the three months ended April 30, 2026, net cash provided by operating activities of $81.7 million resulted primarily from a net loss of $41.9 million, partially offset by $73.4 million of stock-based compensation, $29.3 million of amortization of deferred commissions, $12.1 million for depreciation and amortization, and $6.4 million of net cash inflow from changes in operating assets and liabilities. …”see in full comparison
For thesee in full comparisonthreesix months endedAprilJuly30,31,2025,2026, net cash provided by operating activities of$39.7$158.5 million resulted primarily from a net loss of$102.1$103.6 million, partially offset by$73.5$174.4 million of stock-based compensation,$24.8$59.5 million of amortization of deferred commissions,$8.1$24.6 million for depreciation and amortization, and$35.1$0.8 million of net cash inflow from changes in operating assets and liabilities. The net cash inflow from changes in operating assets and liabilities was primarily the result of a$89.7$84.5 million increase in deferred revenue from increasedbillingsbillings, and a$12.0$34.3 million decrease inaccountsprepaidreceivable.expenses and other assets. The cash inflow was partially offset by a$36.8$12.4 million increase in accounts receivable, a $69.1 million increase in deferred commissions, and a $43.2 million decrease in accrued expenses and othercurrent liabilities, a $21.4 million increase in deferred commissions, and a $7.8 million increase in prepaid expense and other assets.liabilities.
“Other revenue, which consists primarily of sales of perpetual licenses of our legacy CDM product, Rubrik-branded Appliances and professional services, was relatively flat for the three months ended April 30, 2026. Other revenue represented 3% and 5% of total revenue for the three months ended April 30, 2026 and 2025, respectively. The transition of existing maintenance customers adopting RSC subscription offerings was largely completed in fiscal 2026. We expect our other revenue as a percentage of total revenue to continue to decrease.”see in full comparison
“Subscription ARR Contribution Margin was 13% and 8% for the 12 months ended April 30, 2026 and 2025, respectively. The increase in Subscription ARR Contribution Margin was primarily driven by the strong year-over-year Subscription ARR growth outpacing the year-over-year growth in non-GAAP subscription costs of sales and non-GAAP operating expenses. We believe that this increase in Subscription ARR Contribution Margin reflects increased operating leverage in our business.”see in full comparison
Full comparison: every changed paragraph (55)
We began transitioning customers from our legacy CDM capabilities to RSC, which is offered on a subscription basis, in fiscal 2023. As part of this business transition, we began transitioning the sale of Rubrik-branded Appliances from us to our contract manufacturersmanufacturers, while still offering support services, and stopped offering the Refresh Rights as part of our subscription offerings. In lieu of offering Refresh Rights, we offered Subscription Credits to qualifying customers (which are customer options that are accounted for as material rights). We recognize ratable revenue upon utilization or upfront revenue upon expiration of Subscription Credits, and utilization of Subscription Credits also offsets Subscription ARR for the applicable period. Since the end of fiscal 2024, RSC has represented a majority of our total revenue.
New and existing customers have largely adopted RSC. We have largely migrated our existing customers from our legacy CDM capabilities to RSC. During this migration, certain existing customers consumed our platform and products through a mix of RSC and a transitional CDM license (“RCDM-T”), during which time we recognized a portion of the associated revenue from these customers upfront at the time we transferred control of the license to the customer, and we have largely completed this transition in fiscal 2026. In addition, we expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits through fiscal 2027,Credits, although we expect the benefits to significantlycontinue declineto sequentially.decline.
In the first quarter of fiscal 2027, we started offering the Resilience Guardian as a term-based subscription licensesupport program,service offering, which provides customers with dedicated resilience managers to design and implement a cyber resilience strategy that maps to business outcomes. This includes proactive security and health checks, detection and resolution of emerging issues, upgrade planning and assistance, and adoption excellence and value realization.
Our overall performance depends in part on worldwide economic and geopolitical conditions and their impact on customer behavior. Macroeconomic conditions, including inflation, fluctuations in interest rates, foreign currency fluctuations, tariffs or other trade restrictions, geopolitical issues, changes in government policy or spending, and other changes in economic conditions, may adversely affect the buying patterns of our customers and prospective customers. For example, in light of current macroeconomic conditions, such as higher cost-consciousness around information technology budgets, as well as constraints affecting the availability or pricing of compatible commodity servers needed to deploy our solutions, we have observed a lengthening of our sales cycles.cycles could fluctuate. Additionally, key components of the commodity servers that are compatible with our solutions have been, and continue to be, affected by global chip shortages and allocation constraints, in part due to elevated industry demand, which in certain cases have resulted in extended lead times and increased server prices. Such delays, constraints and increased costs may affect our customers’ purchasing decisions and deployment timelines, in some cases delaying customer purchases and in other cases resulting in customers pulling software purchases forward to lock in hardware prices. In response, we may in the future provide certain commercial accommodations, which could reduce our margins or adversely affect our revenue and operating results if such practices become widespread or prolonged. Due to our subscription-focused business model, any impact of the current macroeconomic environment and supply chain constraints on our business may not be fully reflected in our results of operations until future periods. As we continue to monitor the direct and indirect impacts of the current environment, the broader implications of macroeconomic conditions and supply chain constraints on our business, results of operations and financial condition, particularly in the long term, remain uncertain.
Subscription ARR is calculated as the annualized value of our active subscriptions as of the measurement date, based on our customers’ total contract value, and assuming any contract that expires during the next 12 months is renewed on existing terms. Subscriptions include offerings for our RSC suite and related data security SaaS solutions, term-based licenses for our RSC-Private suite and related products, prior sales of CDM sold as a subscription term-based license with associated support and related SaaS products, other subscription support service offerings, and standalone sales of our SaaS subscription offerings like Anomaly Detection, and Sensitive Data Monitoring and Resilience Guardian.Monitoring. We believe Subscription ARR illustrates our success in acquiring new subscription customers and maintaining and expanding our relationships with existing subscription customers.
Subscription ARR does not include any maintenance revenue associated with perpetual licenses, which we generally no longer offer.
Subscription ARR does not include any maintenance revenue associated with perpetual licenses, which we generally no longer offer. Of the 32% and 38% growth, approximately 0.4 percentage points and 2 percentage points of growth for the three months ended April 30, 2026 and 2025, respectively, were a result of transitioning our existing maintenance customers to our subscription editions. Contributions to growth from these transitions were largely completed in fiscal 2026.
Cloud ARR is calculated as the annualized value of our active cloud-based subscriptions as of the measurement date, based on our customers’ total contract value, and assuming any contract that expires during the next 12 months is renewed on existing terms. Our cloud-based subscriptions include RSC and RSC-Government (excluding RSC-Private). Cloud ARR also includes SaaS subscription offerings like Anomaly Detection and Sensitive Data Monitoring, which are sold standalone or with prior sales of term-based license offerings of CDM. Cloud ARR excludes our self-managed products for customers that are subject to stringent data control policies, such as RSC-Private and legacy CDM products, as well as other subscription support service offerings, which are included in Subscription ARR. We believe that Cloud ARR provides important information on new and existing customers purchasing new RSC subscription offerings and existing subscription term-based license customers renewing with RSC subscription offerings.
Free cash flow is a non-GAAP financial measure that we calculate as net cash provided by (used in) operating activities less cash used for purchases of property and equipment and capitalized internal-use software. We believe that free cash flow is a helpful indicator of liquidity that provides information to management and investors about the amount of cash generated or used by our operations that, after the investments in property and equipment and capitalized internal-use software, can be used for strategic initiatives, including investing in our business and strengthening our financial position. The limitation of free cash flow is that it does not reflect our future contractual commitments and may fluctuate due to the timing of cash payments received from our customers and payments relative to expenses, prepayments of other spend, including hosting prepayments, and charitable donations. Additionally, free cash flow is not a substitute for cash provided by (used in) operating activities, and the utility of free cash flow as a measure of our liquidity is further limited as it does not represent the total increase or decrease in our cash balance for a given period.
Free cash flow was $73.6 million and $33.3 million for the three months ended April 30, 2026 and 2025, respectively. The improvement in free cash flow was primarily due to higher sales, including timing of renewals, improved operating leverage and optimizing our capital structure. This trend when combined with changes in new business growth, may result in free cash flow volatility across periods.
Free cash flow was $139.3 million and $90.9 million for the six months ended July 31, 2026 and 2025, respectively. The improvement in free cash flow was primarily due to higher sales, including timing of renewals, improved operating leverage and optimizing our capital structure. This trend when combined with changes in new business growth, may result in free cash flow volatility across periods.
We define Subscription ARR Contribution Margin as the Subscription ARR Contribution (as defined below) divided by Subscription ARR at the end of the period. We define Subscription ARR Contribution as Subscription ARR at the end of the period less: (i) our non-GAAP subscription cost of revenue and (ii) our non-GAAP operating expenses for the prior 12-month period ending on that date. In fiscal 2023, we began transitioning customers from our legacy CDM capabilities to our subscription-based RSC offerings. As a result of differing revenue recognition treatment between CDM and RSC, including the RCDM-T licenses offered to existing customers, and as qualified customers choose to exercise or forfeit their Subscription Credits,Credits (which are customer options that are accounted for as material rights), these business transitions cause fluctuations to our total revenue growth and limit the comparability of our revenue with past performance.performance, although we expect these benefits to continue to significantly decline sequentially. As a result, we measure the performance of our business on the basis of Subscription ARR. We believe that Subscription ARR Contribution Margin is a helpful indicator of operating leverage during this business transition. One limitation of Subscription ARR Contribution Margin is that the factors that impact Subscription ARR will vary from those that impact subscription revenue and, as such, may not provide an accurate indication of our actual or future GAAP results. Additionally, the historical expenses in this calculation may not accurately reflect the costs associated with future commitments.
Subscription ARR Contribution Margin was 13% and 8% for the 12 months ended April 30, 2026 and 2025, respectively. The increase in Subscription ARR Contribution Margin was primarily driven by the strong year-over-year Subscription ARR growth outpacing the year-over-year growth in non-GAAP subscription costs of sales and non-GAAP operating expenses. We believe that this increase in Subscription ARR Contribution Margin reflects increased operating leverage in our business.
Subscription ARR Contribution Margin was 14% and 9% for the 12 months ended July 31, 2026 and 2025, respectively. The increase in Subscription ARR Contribution Margin was primarily driven by the strong year-over-year Subscription ARR growth outpacing the year-over-year growth in non-GAAP subscription costs of sales and non-GAAP operating expenses. We believe that this increase in Subscription ARR Contribution Margin reflects increased operating leverage in our business.
While we have largely completed both the sales of Rubrik-branded Appliances transitioning from us to our contract manufacturers in fiscal 2025 and the transition for new and existing customers to sales of RSC in fiscal 2026, we expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits (which are customer options that are accounted for as material rights) through fiscal 2027,, although we expect the benefits to significantlycontinue declineto sequentially.decline. These business transitions cause fluctuations to our total revenue growth and limit the comparability of our revenue with past performance. We primarily measure our business on the basis of Subscription ARR, as we believe it best reflects our actual growth and our growth prospects.
Certain prior period amounts reported in the unaudited condensed consolidated financial statements and notes have been reclassified to conform to the current year presentation. For the three and six months ended AprilJuly 30,31, 2026 and 2025, the Company combined maintenance revenue and other revenue into “Other” on the unaudited condensed consolidated statements of operations. The presentation of cost of revenue has been conformed to reflect the changes related to the presentation of revenues. Such reclassifications related to the presentation of revenue and cost of revenue did not impact total revenue, loss from operations or net loss.
Our subscription revenue consists of SaaS subscriptionssubscriptions, subscription support service offerings, and subscription term-based licenses with related support services.
Subscription term-based licenses provide our customer with a right to use the software for a fixed term commencing upon delivery of the license to our customer. Support services are bundled with each subscription term-based license for the term of the subscription.
Subscription term-based licenses provide our customer with a right to use the software for a fixed term commencing upon delivery of the license to our customer. Support services are bundled with each subscription term-based license for the term of the subscription. Subscription revenue related to subscription term-based licenses includes upfront revenue recognized at the later of the start date of the subscription term-based license and the date when the subscription term-based license is delivered. The remainder of the revenue is recognized ratably over the subscription period for support services, commencing with the date the service is made available to customers. Support services revenue are recognized ratably over the subscription period.
Our subscription revenue will fluctuate when qualified customers choose to exercise or forfeit their customer options that are accounted for as material rights. We have experienced revenue growth benefits from the non-recurring revenue associated with material rights; however, we expect these benefits to continue to significantly decline over the course of fiscal 2027. The combination of both of these factors may continue to limit and cause fluctuations in our subscription revenue growth during fiscal 2027, depending in part on the timing of our existing customers’ transition to RSC and exercises or forfeitures of Subscription Credits (which are customer options that are accounted for as material rights).
Other revenue includes fees earned from sales of professional and other services, software updates on a when-and-if-available basis, telephone and integrated web-based support, Rubrik-branded Appliance maintenance relating to our perpetual licenses, and Rubrik-branded Appliances. Revenue for Rubrik-branded Appliances is recognized when shipped to the customer. When we sell our software license with our Rubrik-branded Appliances, revenue for both the Rubrik-branded Appliances and software licenses are recognized at the same time. Revenue related to professional services is typically recognized as the services are performed. WeAlthough expectwe have largely completed the transition of sales of Rubrik-branded Appliances from us to our contract manufacturers in fiscal 2025, other revenue may fluctuate due to besupply largelychain drivenconditions, byresulting salesfrom ofglobal professionalchip servicesshortages and increases in theserver future and as a percentage of total revenue to decrease over time.prices.
Cost of subscription revenue primarily includes employee compensation and related expenses associated with customer support for our subscription offerings,offerings and support services, certain hosting costs, amortization of capitalized internal-use software, and amortization of finite-lived intangible assets. We expect our cost of subscription revenue to increase as our subscription revenue increases.
Cost of other revenue includes the cost of professional services, employee compensation and related expenses associated with customer support from our perpetual licenses, and the cost of Rubrik-branded Appliances. We expect cost of other revenue as a percentage of total cost of revenue to decrease asAlthough the transition of sales of Rubrik-branded Appliances from us to our contract manufacturers was largely completed in fiscal 2025.2025, Overa small portion of the long-term,sales weremains with us, primarily in the APAC region. Cost of other revenue may fluctuate in the near term from the remaining portion of sales of Rubrik-branded Appliances that remains with us as well as from supply chain conditions, resulting from global chip shortages and increases in server prices. We expect the cost of other revenue toas bea largely driven by salespercentage of professionaltotal services.cost of revenue to decrease over the long term.
We expect other gross margin to fluctuate as a percentage of total other revenue over the near term due to the factors set forth under “Cost of Other Revenue”. We expect other gross margin to generally decrease as a percentage of total other revenue over the long term.
We expect other gross margin to decrease as a percentage of total revenue, which we expect will result in a decrease in cost of other revenue. We expect sales of Rubrik-branded Appliances to decrease as the transition of sales of Rubrik-branded Appliances from us to our contract manufacturers was largely completed in fiscal 2025. Over the long-term, we expect other gross margin to be largely driven by sales of professional services.
Our operating expenses consist of research and development, sales and marketing, and general and administrative expenses. Personnel costs are the most significant component of operating expenses. We also incur other non-personnel costs such as colocation and certain AI and hosting costs, office space costs, fees for third-party professional services, and costs associated with software and subscription services. We expect our operating expenses will continue to increase as our business grows. We also expect our operating expenses, exclusive of stock-based compensation, as a percentage of revenue to generally decrease over the long term.
Research and development expenses consist primarily of employee compensation and related expenses, net of capitalized amounts, and colocation and certain AI and hosting costs. To capture share in the ever-growing data security market, we expect to continuously innovate our platform and product functionality and will continue to invest in research and development. We expect our research and development expenses will continue to increase as our business grows. We also expect our research and development expenses, exclusive of stock-based compensation, as a percentage of revenue to generally decrease over the long term.
Comparison of the Three and Six Months Ended AprilJuly 30,31, 2026 and 2025
Growth in subscription revenue for the three and six months ended AprilJuly 30,31, 2026 was driven by growth in Subscription ARR and somehigher benefitsupfront asrevenue customers exercised or forfeited their Subscription Credits. Forfrom the threeterm-based months ended April 30, 2026, non-recurring revenue related to material rights associated with Subscription Credits accountedlicenses for approximatelyour $8.5RSC-Private million of subscription revenue.suite. We expect our subscription revenue to continue to benefit from customers exercising or forfeiting their Subscription Credits through(which fiscalare 2027,customer options that are accounted for as material rights), although we expect the benefits to significantlycontinue declineto sequentially.decline.
Our Subscription ARR grew from $1.18$1.25 billion as of AprilJuly 30,31, 2025 to $1.57$1.66 billion as of AprilJuly 30,31, 2026, representing a 32%33% increase. Of the increase in Subscription ARR, approximately 0.4 percentage points are a result of transitioning our existing maintenance customers to our subscription editions. A further indication of our ability to expand revenue from existing customers is through our average subscription dollar-based net retention rate which was approximatelyover 120%119% as of AprilJuly 30,31, 2026. We had 2,9463,084 customers with $100,000 or more in Subscription ARR as of AprilJuly 30,31, 2026, increasing from 2,3812,505 as of AprilJuly 30,31, 2025.
Other revenue consists primarily of sales of Rubrik-branded Appliances and professional services. Growth in other revenue for the three and six months ended July 31, 2026 was primarily driven by higher hardware sales in international regions such as APAC, that have not fully been transitioned to our contract manufacturers.
Other revenue, which consists primarily of sales of perpetual licenses of our legacy CDM product, Rubrik-branded Appliances and professional services, was relatively flat for the three months ended April 30, 2026. Other revenue represented 3% and 5% of total revenue for the three months ended April 30, 2026 and 2025, respectively. The transition of existing maintenance customers adopting RSC subscription offerings was largely completed in fiscal 2026. We expect our other revenue as a percentage of total revenue to continue to decrease.
Cost of subscription revenue increased for the three months ended AprilJuly 30,31, 2026 primarily drivendue byto ana $7.9 million increase of $8.5 million in hosting costs duedriven toby the launch and adoption of moreadditional SaaS offerings by our customers, ana $5.1 million increase of $2.7 million from growth in our customer support organization, ana $2.0 million increase of $1.8 million ofin amortization of acquired technology and ana $1.4 million increase of $1.5 million ofin amortization of capitalized internal-use software.
Cost of subscription revenue increased for the six months ended July 31, 2026 primarily due to a $16.5 million increase in hosting costs, driven by the launch and adoption of more SaaS offerings by our customers, a $7.8 million increase from growth in our customer support organization, a $3.8 million increase in amortization of acquired technology and a $2.9 million increase in amortization of capitalized internal-use software.
Cost of other revenue increased for the three months ended July 31, 2026 primarily due to a $9.2 million increase in hardware sales in some regions such as APAC. Cost of other revenue increased for the six months ended July 31, 2026 primarily due to a $9.7 million increase in hardware costs and more hardware sales.
Subscription gross margin increased for the three and six months ended AprilJuly 30,31, 2026, primarily driven by economies of scale as our subscription revenue base expanded faster than our associated cost of revenue.
Other gross margin decreased for the three and six months ended July 31, 2026, due to increases in hardware costs.
Research and development expenses increased for the three months ended AprilJuly 30,31, 2026 primarily due to ana $19.8 million increase of $19.9 million in employee related costs driven by an increase in headcount, of which $13.2included a $11.8 million is an increase in stock-based compensation expense. In addition, hostingexpenses related to AI, hosting, and software expensessubscription services increased by $9.8$13.7 million.
Research and development expenses increased for the six months ended July 31, 2026 which was primarily attributable to a $39.7 million increase in employee related costs driven by an increase in headcount, which included a $25.1 million increase in stock-based compensation expense. In addition, expenses related to AI, hosting, and software subscription services increased by $23.5 million.
Sales and marketing expenses increased for the three months ended AprilJuly 30,31, 2026 primarily due to ana increase of $11.5$21.6 million in marketing expense as a result of advertising costs, marketing events and related costs to promote and expand our market presence, and an increase of $7.0 million in employee related costs driven by anheadcount growth, along with a $15.3 million increase inreflecting headcount.higher advertising spend and event costs to support brand awareness and market expansion.
Sales and marketing expenses increased for the six months ended July 31, 2026 primarily due to a $28.6 million increase in employee related costs driven by headcount growth, as well as a $26.8 million increase in marketing expense associated with advertising campaigns, events, and related initiatives to drive market penetration.
General and administrative expenses decreased by $11.0 million for the three months ended AprilJuly 30,31, 20262026, primarily drivendue byto a decrease ofin $6.0employee-related millioncosts inassociated with stock-based compensation expenseexpense, mainly related to performance-based equity awards.awards, Theas decreasewell isas offseta by an increase of $1.5 million in employeerelease related coststo drivena bypreviously andisclosed increaselegal in headcount and an increase of $1.3 million in third-party consulting and professional services expenses.matter.
General and administrative expenses decreased by $13.3 million for the six months ended July 31, 2026, primarily due to a decrease in employee-related costs associated with stock-based compensation expense, mainly related to performance-based equity awards, as well as a release related to a previously disclosed legal matter.
Interest income increased for the three and six months ended AprilJuly 30,31, 2026 due to higher cash, cash equivalents, and investment balances.
Interest expense decreased for the three and six months ended AprilJuly 30,31, 2026 as our 2023 Amended Credit Facility with Goldman Sachs BDC, Inc. and the other lenders party thereto was fully repaid in June 2025.
Our income tax expense increased for the three and six months ended AprilJuly 30,31, 2026 due to increased profits in our foreign subsidiaries.
As of AprilJuly 30,31, 2026, we had cash, cash equivalents, and short-term investments of $1.75 billion. Our cash equivalents and investments primarily consist of money market funds, certificate of deposit, U.S. treasuries, commercial paper, corporate bonds, and U.S. government agencies securities. We have generated significant operating losses from our operations as reflected in our accumulated deficit of $3.23$3.29 billion as of AprilJuly 30,31, 2026. We expect to continue to incur operating losses, and our operating cash flows may fluctuate between positive and negative amounts for the foreseeable future. As a result, we may require additional capital resources to execute strategic initiatives to grow our business.
In June 2025, we completed a private offering to qualified institutional buyers of $1.15 billion aggregate principal amount of 0.00% convertible senior notes due 2030. The Convertible Notes are general unsecured obligations of the Company and will mature on June 15, 2030, unless earlier converted, redeemed or repurchased. Net proceeds from the issuance of the Convertible Notes were approximately $1.13 billion. The outstanding principal of the Convertible Notes was $1.15 billion as of AprilJuly 30,31, 2026.
For the three months ended April 30, 2026, net cash provided by operating activities of $81.7 million resulted primarily from a net loss of $41.9 million, partially offset by $73.4 million of stock-based compensation, $29.3 million of amortization of deferred commissions, $12.1 million for depreciation and amortization, and $6.4 million of net cash inflow from changes in operating assets and liabilities. The net cash inflow from changes in operating assets and liabilities was primarily the result of a $57.4 million decrease in accounts receivable, a $43.1 million increase in deferred revenue from increased billings, and a $13.8 million decrease in prepaid expenses and other assets. The cash inflow was partially offset by a $80.4 million decrease in accrued expenses and other liabilities, and a $26.6 million increase in deferred commissions.
For the threesix months ended AprilJuly 30,31, 2025,2026, net cash provided by operating activities of $39.7$158.5 million resulted primarily from a net loss of $102.1$103.6 million, partially offset by $73.5$174.4 million of stock-based compensation, $24.8$59.5 million of amortization of deferred commissions, $8.1$24.6 million for depreciation and amortization, and $35.1$0.8 million of net cash inflow from changes in operating assets and liabilities. The net cash inflow from changes in operating assets and liabilities was primarily the result of a $89.7$84.5 million increase in deferred revenue from increased billingsbillings, and a $12.0$34.3 million decrease in accountsprepaid receivable.expenses and other assets. The cash inflow was partially offset by a $36.8$12.4 million increase in accounts receivable, a $69.1 million increase in deferred commissions, and a $43.2 million decrease in accrued expenses and other current liabilities, a $21.4 million increase in deferred commissions, and a $7.8 million increase in prepaid expense and other assets.liabilities.
For the six months ended July 31, 2025, net cash provided by operating activities of $104.4 million resulted primarily from a net loss of $198.0 million, partially offset by $162.0 million of stock-based compensation, $50.9 million of amortization of deferred commissions, $16.5 million for depreciation and amortization, $6.7 million of loss on debt extinguishment, and $66.9 million of net cash inflow from changes in operating assets and liabilities. The net cash inflow from changes in operating assets and liabilities was primarily the result of a $165.9 million increase in deferred revenue from increased billings. The cash inflow was partially offset by a $49.2 million increase in deferred commissions, a $40.1 million increase in accounts receivable, a $8.0 million decrease in accrued expenses and other current liabilities, and a $4.7 million increase in prepaid expenses and other assets.
For the threesix months ended AprilJuly 30,31, 2026, net cash used in investing activities of $36.2$83.8 million resulted from $292.0$492.9 million in purchases of investments, $3.8$24.2 million paid for acquisitions, $9.4 million in capitalized internal-use software, and $4.3$9.9 million in purchases of property and equipment, partially offset by $263.9$452.6 million in proceeds from maturities of investments.
For the threesix months ended AprilJuly 30,31, 2025, net cash providedused byin investing activities of $34.2$701.7 million resulted from $162.6 million in proceeds from maturities and sales of investments, partially offset by $120.2$998.0 million in purchases of investments, $3.5$10.2 million paid for acquisitions, $7.1 million in capitalized internal-use software, and $2.8$6.3 million in purchases of property and equipment.equipment, partially offset by $319.9 million in proceeds from maturities of investments.
For the threesix months ended AprilJuly 30,31, 2026, net cash providedused byin financing activities of $17.2$35.2 million resulted primarily from $53.3 million in tax paid related to net share settlement of equity awards, offset by $16.6 million in proceeds from issuance of common stock under employee stock purchase plan and $0.6$1.5 million from the exercise of stock options.
For the threesix months ended AprilJuly 30,31, 2025, net cash provided by financing activities of $15.3$727.1 million resulted primarily from $800.2 million in proceeds from issuance of the Convertible Notes, net of full repayment of our 2023 Amended Credit Facility, $13.5 million in proceeds from issuance of common stock under employee stock purchase plan and $1.8$3.1 million from the exercise of stock options.options, partially offset by $88.6 million paid to purchase Capped Calls.
RBRK insider buying and selling (Form 4)
Since 2026-04-11, insiders reported open-market purchases in 0 Form 4 filings and open-market sales in 23 filings (5 insiders, 28 trade dates, 523,004 shares, about $45.8M; 21 of these filings say the sales were made under a Rule 10b5-1 trading plan). Net open-market shares: -523,004 (purchases minus sales); net value about -$45.8M.Totals add up every open-market (code P and S) line in those filings, using the prices reported in the filings. Awards, option exercises, tax withholding and gifts are listed below but not counted.
| Trade date | Insider | Transaction | Shares | Price | Value |
|---|---|---|---|---|---|
| 2026-10-07 | Nithrakashyap Arvind |
Conversion |
12,820 | — | — |
| 2026-10-07 | Nithrakashyap Arvind |
Open-market sale |
1,478 | $123.32 | $182.3K |
| 2026-10-07 | Nithrakashyap Arvind |
Open-market sale |
8,274 | $124.05 | $1.0M |
| 2026-10-07 | Nithrakashyap Arvind |
Open-market sale |
3,055 | $124.79 | $381.2K |
| 2026-10-07 | Nithrakashyap Arvind |
Open-market sale |
13 | $125.57 | $1.6K |
| 2026-10-06 | Nithrakashyap Arvind |
Conversion |
12,820 | — | — |
| 2026-10-06 | Nithrakashyap Arvind |
Open-market sale |
582 | $125.35 | $73.0K |
| 2026-10-06 | Nithrakashyap Arvind |
Open-market sale |
11,101 | $126.14 | $1.4M |
| 2026-10-06 | Nithrakashyap Arvind |
Open-market sale |
1,069 | $126.87 | $135.6K |
| 2026-10-06 | Nithrakashyap Arvind |
Open-market sale |
68 | $127.70 | $8.7K |
| 2026-10-05 | Nithrakashyap Arvind |
Conversion |
2,501 | — | — |
| 2026-10-05 | Nithrakashyap Arvind |
Open-market sale |
495 | $118.92 | $58.9K |
| 2026-10-05 | Nithrakashyap Arvind |
Open-market sale |
110 | $120.26 | $13.2K |
| 2026-10-05 | Nithrakashyap Arvind |
Open-market sale |
901 | $121.20 | $109.2K |
| 2026-10-05 | Nithrakashyap Arvind |
Open-market sale |
2,801 | $121.95 | $341.6K |
| 2026-10-05 | Nithrakashyap Arvind |
Open-market sale |
5,600 | $122.99 | $688.7K |
| 2026-10-05 | Nithrakashyap Arvind |
Open-market sale |
2,913 | $123.80 | $360.6K |
| 2026-10-05 | Wassenaar Yvonne |
Open-market sale |
721 | $119.00 | $85.8K |
| 2026-10-01 | Thompson John Wendell |
Open-market sale |
300 | $114.68 | $34.4K |
| 2026-10-01 | Thompson John Wendell |
Open-market sale |
1,700 | $115.62 | $196.6K |
| 2026-10-01 | Thompson John Wendell |
Open-market sale |
500 | $116.47 | $58.2K |
| 2026-10-01 | Thompson John Wendell |
Conversion |
11,000 | — | — |
| 2026-10-01 | Thompson John Wendell |
Open-market sale |
896 | $114.71 | $102.8K |
| 2026-10-01 | Thompson John Wendell |
Open-market sale |
7,710 | $115.57 | $891.0K |
| 2026-10-01 | Thompson John Wendell |
Open-market sale |
2,394 | $116.46 | $278.8K |
| 2026-09-25 | Sinha Bipul |
Gift | 55,000 | — | — |
| 2026-09-24 | Sinha Bipul |
Conversion | 500,000 | — | — |
| 2026-09-24 | Sinha Bipul |
Conversion | 55,000 | — | — |
| 2026-09-17 | Choudary Kiran Kumar |
Open-market sale |
2,572 | $108.05 | $277.9K |
| 2026-09-17 | Choudary Kiran Kumar |
Open-market sale |
200 | $102.05 | $20.4K |
| 2026-09-17 | Choudary Kiran Kumar |
Open-market sale |
200 | $103.86 | $20.8K |
| 2026-09-17 | Choudary Kiran Kumar |
Open-market sale |
300 | $105.98 | $31.8K |
| 2026-09-17 | Choudary Kiran Kumar |
Open-market sale |
2,728 | $107.42 | $293.0K |
| 2026-09-15 | Nithrakashyap Arvind |
Shares withheld for tax | 10,436 | $100.20 | $1.0M |
| 2026-09-15 | Choudary Kiran Kumar |
Conversion |
4,000 | — | — |
| 2026-09-15 | Choudary Kiran Kumar |
Open-market sale |
1,100 | $99.08 | $109.0K |
| 2026-09-15 | Choudary Kiran Kumar |
Open-market sale |
586 | $100.20 | $58.7K |
| 2026-09-15 | Choudary Kiran Kumar |
Open-market sale |
1,214 | $101.47 | $123.2K |
| 2026-09-15 | Choudary Kiran Kumar |
Open-market sale |
700 | $102.72 | $71.9K |
| 2026-09-15 | Choudary Kiran Kumar |
Shares withheld for tax |
13,995 | $100.20 | $1.4M |
| 2026-09-15 | Choudary Kiran Kumar |
Open-market sale |
400 | $103.48 | $41.4K |
| 2026-09-10 | Nithrakashyap Arvind |
Open-market sale |
2,321 | $91.67 | $212.8K |
| 2026-09-10 | Nithrakashyap Arvind |
Conversion |
12,820 | — | — |
| 2026-09-10 | Nithrakashyap Arvind |
Open-market sale |
369 | $87.55 | $32.3K |
| 2026-09-10 | Nithrakashyap Arvind |
Open-market sale |
611 | $89.12 | $54.5K |
| 2026-09-10 | Nithrakashyap Arvind |
Open-market sale |
4,844 | $89.73 | $434.7K |
| 2026-09-10 | Nithrakashyap Arvind |
Open-market sale |
4,675 | $90.88 | $424.9K |
| 2026-09-09 | Nithrakashyap Arvind |
Conversion |
12,820 | — | — |
| 2026-09-09 | Nithrakashyap Arvind |
Open-market sale |
3,243 | $89.33 | $289.7K |
| 2026-09-09 | Nithrakashyap Arvind |
Open-market sale |
5,297 | $90.41 | $478.9K |
| 2026-09-09 | Nithrakashyap Arvind |
Open-market sale |
3,237 | $91.16 | $295.1K |
| 2026-09-09 | Nithrakashyap Arvind |
Open-market sale |
1,013 | $92.08 | $93.3K |
| 2026-09-09 | Nithrakashyap Arvind |
Open-market sale |
30 | $92.87 | $2.8K |
| 2026-09-08 | Nithrakashyap Arvind |
Conversion |
12,820 | — | — |
| 2026-09-08 | Nithrakashyap Arvind |
Open-market sale |
7,836 | $91.47 | $716.8K |
| 2026-09-08 | Nithrakashyap Arvind |
Open-market sale |
2,217 | $91.95 | $203.9K |
| 2026-09-08 | Nithrakashyap Arvind |
Open-market sale |
2,767 | $90.43 | $250.2K |
| 2026-09-03 | Wassenaar Yvonne |
Open-market sale |
721 | $89.52 | $64.5K |
| 2026-09-03 | Wassenaar Yvonne |
Conversion |
513 | — | — |
| 2026-09-01 | Thompson John Wendell |
Open-market sale |
4,700 | $89.02 | $418.4K |
Well-known investors holding RBRK (13F)
| Investor | Quarter | Shares | Reported value | % of their 13F | Change vs prior quarter |
|---|---|---|---|---|---|
| AQR Capital Management (Cliff Asness) | 2026-06-30 | 9,947,988 | $780.1M | 0.27% | Added 349% |
| Two Sigma Investments | 2026-06-30 | 561,015 | $45.0M | 0.03% | Reduced 76% |
| Renaissance Technologies | 2026-06-30 | 509,189 | $40.9M | 0.06% | Added 35% |
| Citadel Advisors (Ken Griffin) | 2026-06-30 | 731,217 | $35.8M | — | Sold out |
| Baillie Gifford | 2026-06-30 | 388,021 | $31.2M | 0.03% | Added 135% |
| ARK Investment Management (Cathie Wood) | 2026-06-30 | 365,426 | $29.3M | 0.19% | Reduced 7% |
| Millennium Management (Israel Englander) | 2026-06-30 | 0 | $16.3M | 0.01% | New position |
| Millennium Management (Israel Englander) | 2026-06-30 | 131,091 | $10.5M | 0.01% | Reduced 67% |
| Gotham Asset Management (Joel Greenblatt) | 2026-06-30 | 107,773 | $8.7M | 0.02% | Added 95% |
| Oaktree Capital Management (Howard Marks) | 2026-06-30 | 0 | $4.6M | 0.09% | New position |
| Point72 Asset Management (Steve Cohen) | 2026-06-30 | 52,944 | $4.3M | 0.01% | Added 156% |
| D. E. Shaw & Co. | 2026-06-30 | 33,464 | $2.7M | 0.0% | Reduced 1% |
| Bridgewater Associates | 2026-06-30 | 35,725 | $1.7M | — | Sold out |
| Polen Capital Management | 2026-06-30 | 6,201 | $497.8K | 0.0% | New position |