Intercepts every enterprise internet session at a global network of data centers, scans it for threats, and sends it on — replacing the company's own firewall entirely.
At a glance
Depends onDownstream position: depends on 18 industries, supplies 5
ScaleMarket cap is above the global median
FinancialsAltman Z-Score: safe zone
Interpretations3 currently firing — 1 · 2
What this company is and how it runs — written from structure, not news.
Nature view
Zscaler sits in the middle of every internet session an enterprise employee makes — decrypting the traffic at one of its 150-plus edge data centers, scanning it for threats, and re-encrypting it before it reaches its destination, all in milliseconds. To use the platform, a company must remove its on-premises firewalls entirely, which means all identity checks, traffic policies, and data-loss rules get embedded inside Zscaler's infrastructure rather than the company's own network — so after a few months of custom configuration, leaving would mean rebuilding all of that from scratch on a new platform. Adding new edge locations to serve fresh geographies requires physical co-location deals, local internet peering agreements, and country-specific data certifications at each site, none of which can be rushed or replaced by simply buying more hardware, so a competitor cannot close the geographic gap just by spending money. The architecture's weak point is the mirror of its strength: if a country passes a data sovereignty law requiring traffic to stay within borders where Zscaler has no certified edge node, the entire inspection chain breaks there, because traffic that cannot legally reach a compliant node cannot be inspected at all.
How does this company make money?
Customers pay an annual subscription fee based on how many users they have and how much data flows through the Zero Trust Exchange. On top of the base license, customers can buy additional modules — data loss prevention, browser isolation, and digital experience monitoring — each sold as a separate add-on subscription.
What makes this company hard to replace?
Leaving requires rebuilding months of custom SAML configurations that connect the platform to the company's Active Directory and identity systems. Every application-specific traffic policy embedded in the customer's network would need to be reconstructed from scratch. FedRAMP and SOC 2 certifications that a replacement vendor does not yet hold would need to be obtained separately before a regulated customer could switch. API connections to existing tools like Splunk and ServiceNow would also need to be rebuilt on a new platform.
What limits this company?
The decryption, scanning, and re-encryption of every session must finish in milliseconds. If processing takes too long, live applications either break or get waved through without inspection — and since the old firewall has been removed, there is no backup. This means every edge data center must be fast enough to handle peak traffic without slipping, and adding new locations requires physical co-location negotiations, local internet exchange peering agreements, and jurisdiction-specific data handling certifications that must happen in sequence and cannot be rushed or automated.
What does this company depend on?
The platform cannot run without SSL/TLS certificate authorities, which grant the right to decrypt encrypted traffic. It relies on Microsoft Azure and AWS to host its edge data centers. Threat intelligence feeds from Proofpoint and CrowdStrike keep its scanning engines current. Internet exchange points provide the low-latency connections that make millisecond processing possible. For U.S. government customers specifically, FedRAMP authorization is required to operate at all.
Who depends on this company?
Enterprise IT departments are the most directly exposed — if the edge centers go down, remote workers lose internet access completely, since the old firewall no longer exists to fall back on. Microsoft 365 and Salesforce sessions stop working when traffic routing breaks. Financial services firms running trading applications see latency spikes during any slowdown in security processing. Healthcare systems depend on the platform to keep their data flows continuously compliant with HIPAA rules.
How does this company scale?
Once a security policy or threat signature is built, it copies instantly to all 150+ edge locations at no meaningful additional cost. But adding new locations — which is the only way to serve new geographies or reduce latency — requires physical co-location negotiations, local internet peering agreements, and jurisdiction-specific certifications at each site. That manual, place-by-place process stays the bottleneck no matter how large the platform grows.
What external forces can significantly affect this company?
GDPR and newer data sovereignty laws in various countries require traffic to stay within specific borders, which forces the platform to build locally certified edge infrastructure in each affected jurisdiction or lose the ability to serve customers there. Chinese internet restrictions and U.S. export controls on encryption technology limit where the platform can legally be deployed at all. On the upside, rapid growth in remote work is pushing more companies to replace traditional VPNs, expanding the market.
Where is this company structurally vulnerable?
If data sovereignty laws require a country's internet traffic to stay inside its borders, and the platform has no certified edge data center inside that country, the inspection chain snaps entirely — traffic that cannot legally travel to a certified node cannot be decrypted or scanned. Getting a new certified node approved takes time, and regulators can move faster than certifications can be obtained, leaving customers in those jurisdictions without a working service.
Price is read as structure — trend, levels, range, peak and volatility drawn on the chart. It does not predict where price goes next.
1 interpretation currently present — each is a set of fired observations whose alignment reads as one structural pattern. Click an observation to see the numbers behind it.
Two structural conditions align: (1) a multi-year price band exists where the stock has, on at least two separated occasions, stopped declining and bounced upward, and (2) current price is back inside or just above that zone after a meaningful drawdown from peak. The retest is a real one — the stock is not at a new all-time high being measured as a low.
Reads
An interpretation is present only while every observation it reads stays fired (score ≥ 70). It describes what the aligned readings show — never a verdict, never a prediction.
The reported statements, read against the company's own industry.
Financials view
Market Capitalization
24.25BUSD
vs all stocks (USD)
Updated Jul 19, 2026
Revenue (TTM)
3.17BUSD
vs all stocks (USD)
Updated Jul 19, 2026
Profit Margin
-2.44%
vs Software Infrastructure peers
Updated Jul 19, 2026
Beta
0.9580x
vs all stocks
Updated Jul 19, 2026
52-Week Change
-48.02%
vs all stocks
Updated Jul 19, 2026
Market Capitalization
24.25BUSD
vs all stocks (USD)
Updated Jul 19, 2026
Enterprise Value
22.58BUSD
vs all stocks (USD)
Updated Jul 19, 2026
Forward P/E
32.62x
vs Software Infrastructure peers
Updated Jul 19, 2026
Gross Margin
77.35%
vs Software Infrastructure peers
Updated Jul 19, 2026
Profit Margin
-2.44%
vs Software Infrastructure peers
Updated Jul 19, 2026
Operating Margin
-3.28%
vs Software Infrastructure peers
Updated Jul 19, 2026
Shares Outstanding
161.71MSharesUpdated Jul 19, 2026
Float Shares
105.12MSharesUpdated Jul 19, 2026
Shares Short
8.29MSharesUpdated Jul 19, 2026
Short Ratio
1.68days
vs all stocks
Updated Jul 19, 2026
Short % of Shares Outstanding
52-Week Low
114.63USDUpdated Jul 19, 2026
52-Week High
336.99USDUpdated Jul 19, 2026
52-Week Change
-48.02%
vs all stocks
Updated Jul 19, 2026
Beta
0.9580x
vs all stocks
Updated Jul 19, 2026
2 interpretations currently present — each is a set of fired observations whose alignment reads as one structural pattern. Click an observation to see the numbers behind it.
Three FCF-denominator ratios co-occur in their elevated ranges: FCF/total assets, FCF/total shareholders' equity, and industry-benchmarked FCF/OCF. The configuration describes free cash flow scaling against three different denominators at the latest annual snapshot.
Reads
Where is this company structurally exposed?
Ulcer Index Elevated, Drawdown From Peak Significant, 20-Week Volatility Elevated
Three price-behavior observations have aligned: the ulcer index (drawdown depth and duration composite) is elevated, current drawdown from peak is significant, and 20-week annualized volatility is in the upper portion of its mapped range.
Reads
An interpretation is present only while every observation it reads stays fired (score ≥ 70). It describes what the aligned readings show — never a verdict, never a prediction.
Shared structure with peers — never a ranking.
Relationships view
Structural observations derived from financial data, industry benchmarks, and supply chain position.
Structural Tensions
High gross margins eroded by operating costsNotable
Gross Margin: 0.77Profit Margin: -0.02
Financial Health
Altman Z-Score: safe zoneNotable
Altman Z-Score: 3.76
High earnings qualityNotable
Earnings Quality Score: 0.71
High structural barrier to entryNotable
Barrier to Entry: 0.67
Supply Chain
Downstream position: depends on 18 industries, supplies 5Notable
Outgoing: 5.00Incoming: 18.00
High connectivity hub: 23 industry connectionsNotable
Total Connections: 23.00
Scale
Market cap is above the global medianNotable
Market cap (USD): 24,246,726,178Global Median: 1,144,944,382.786