SentinelOne Q2FY27 Results: Revenue up 21% to $292 million

scanx
Reviewed by
Ashish TScanX News Team
Key Highlights
  • SentinelOne reported Q2FY27 revenue of $292 million, up 21% YoY, exceeding the top end of guidance
  • Record Q2 net new ARR of $56 million grew 4% YoY; total ARR rose 22% to approximately $1.22 billion
  • RPO surged 45% to a record $1.7 billion, driven by larger upmarket lands and longer contract durations
  • Adjusted operating margin reached a record 10%, expanding 820 bps YoY; EPS of $0.08 doubled YoY
  • Full-year FY27 revenue guidance raised to $1.202 billion to $1.207 billion; operating income outlook raised to $124 million to $128 million
powered bylight_fuzz_icon
50947611

*this image is generated using AI for illustrative purposes only.

SentinelOne Inc reported Q2FY27 revenue of $292 million, up 21% year-over-year, exceeding the top end of its guidance range, while delivering a record operating margin of 10% and its fifth consecutive quarter of positive net new ARR growth.

The quarter also saw record second-quarter net new ARR of $56 million, growing 4% year-over-year, driven by strong new logo acquisition and broader platform adoption. International markets represented 39% of total revenue. Total ARR grew 22%, and ARR per customer reached a new company record, led by momentum at the top end of the market. For customers spending $100,000 or more, the dollar-based net retention rate expanded sequentially for the third consecutive quarter.

Key Financial Metrics

The following table summarises SentinelOne's Q2FY27 performance against guided and prior-year figures:

Metric Value Change
Revenue $292 million +21% YoY
Total ARR ~$1.22 billion +22% YoY
Net new ARR (Q2) $56 million +4% YoY
Remaining performance obligations (RPO) $1.7 billion +45% YoY
Adjusted operating margin 10% Record; +820 bps YoY
Earnings per share $0.08 Doubled YoY
Cash, equivalents and investments $813 million No debt
Trailing twelve-month free cash flow margin 6% +~400 bps YoY
Sales and marketing as % of revenue 34% -900+ bps YoY

RPO growth accelerated to 45% in Q2, reaching a record $1.7 billion, driven by larger upmarket lands and increased contract duration. Management noted that seven- and eight-figure customer wins are becoming consistent.

Operational Momentum

Strategic wins in the quarter included a complete rip-and-replace of a primary competitor at a leading aerospace and defense enterprise, consolidating Endpoint, Data, Cloud, and AI security onto the Singularity platform. A major government agency standardised on Singularity EDR following a rigorous evaluation, and Bell Canada selected Prompt Security to secure one of Canada's most critical networks. A major American tech giant expanded its SentinelOne deployment, choosing Singularity Cloud over a close competitor, while a leading global financial institution standardised on the Singularity platform following a competitive evaluation.

Within a year of its launch, SentinelOne Flex exceeded 10% of total arrangements, with strong traction among both new and existing customers and a growing pipeline of Flex opportunities.

What the Numbers Show

Growth in AI-native security platforms is accelerating faster than the broader business. ARR from AI security offerings — Prompt Security and Purple AI — tripled year-over-year in Q2, outpacing the overall 21% revenue growth rate. Data solutions marked their fifth consecutive quarter of ARR growth acceleration, and Cloud security marked its third consecutive quarter of ARR growth acceleration. This divergence signals a mix shift toward specialised AI governance and data tools. IDC independently validated a 338% three-year ROI for Purple AI customers, a 331% three-year ROI for SentinelOne's AI SIEM, and a 301% three-year ROI for Singularity Endpoint.

CFO Sonalee Parekh noted that the 22% net new ARR growth in the first half exceeded internal targets, and that net retention among the $100,000-plus customer cohort has now expanded for several consecutive quarters, which she characterised as a confirmed trend rather than a one-quarter uptick.

Guidance

Building on Q2 momentum, management raised both revenue and operating income outlooks for full-year FY27.

Period Metric Guidance
Full-year FY27 Revenue $1.202 billion to $1.207 billion
Full-year FY27 Revenue growth (midpoint) ~20% YoY
Full-year FY27 Operating income $124 million to $128 million
Full-year FY27 Operating margin (midpoint) ~10%
Full-year FY27 Earnings per share $0.30 to $0.32
Full-year FY27 Non-GAAP tax rate ~17%
Full-year FY27 Weighted average diluted share count ~361 million
Q3FY27 Revenue $309 million to $311 million
Q3FY27 Revenue growth (midpoint) ~20% YoY
Q3FY27 Operating income $38 million to $40 million
Q3FY27 Operating margin (midpoint) ~13%
Q3FY27 Earnings per share $0.08 to $0.09
Q3FY27 Weighted average diluted share count ~370 million

Market Context

CEO Tomer Weingarten highlighted sovereign deployment capability as a structural differentiator, noting that SentinelOne is the only modern security platform deployable across cloud, on-premises, and air-gapped environments. An aerospace and defense giant selected SentinelOne as the sole provider to pass every requirement in an air-gapped, highly restricted proof of concept. The company also expanded its AWS collaboration around unified AI governance, integrating AI security capabilities directly with Amazon Bedrock Agent Core. LevelBlue, described as the world's largest managed security provider, was named a Premier remediation partner for Wayfinder Frontier AI Services during the quarter.

Disclaimer: This article is AI-generated using data from ViewTrade. ScanX is not liable for any inaccuracies.

How might the rapid adoption of SentinelOne Flex influence the company's long-term revenue predictability and customer churn rates compared to traditional licensing models?

Given the tripling ARR in AI security offerings, what specific competitive threats from incumbent SIEM or cloud-native security providers could emerge as the AI governance market matures?

Will SentinelOne's focus on air-gapped and sovereign deployments create a sustainable moat in the defense and government sectors, or will specialized niche competitors erode this advantage?

like16
dislike

SentinelOne expands Wayfinder AI services with OpenAI Daybreak models

scanx
Reviewed by
Ritika DScanX News Team
Key Highlights
  • SentinelOne expands Wayfinder Frontier AI Services with OpenAI Daybreak models via Daybreak Defense Network
  • Integration starts with GPT-5.6-Cyber to proactively identify and remediate exploitable enterprise threats
  • New capabilities include AI-powered code risk analysis and compromise assessment features
  • Services pair frontier AI models with offensive and defensive security experts for prioritized remediation
powered bylight_fuzz_icon
50015500

*this image is generated using AI for illustrative purposes only.

SentinelOne (NYSE: S) announced an expanded set of offerings for its Wayfinder Frontier AI Services, powered by OpenAI Daybreak models through the Daybreak Defense Network.

The update introduces GPT-5.6-Cyber, a model selected for its performance in reverse engineering military-grade malware like fast16, according to internal benchmarks by SentinelLABS.

New Capabilities

The expanded services focus on two primary areas: AI-powered code risk analysis and AI-enabled compromise assessment. These features aim to prioritize remediation by identifying which exposures attackers can actually reach.

Code Risk Analysis

This capability scans customer repositories for OWASP-class flaws, code implants, exposed secrets, and supply-chain risks. When malicious samples are detected, AI-assisted workflows support disassembly and deobfuscation, fusing static and sandbox evidence.

Key outputs include:

  • Indicators of compromise (IOCs)
  • MITRE ATT&CK mapping
  • Recommended detections for the fleet

All verdicts are validated by SentinelOne’s offensive-security analysts before delivery.

Compromise Assessment

This feature evaluates telemetry against detection rules to surface posture gaps, such as risky use of VPNs, proxies, or remote-management tools. It replaces manual review with AI-driven triage.

When triage surfaces suspected malicious samples, the system performs behavioral analysis to confirm scope and impact. Customers receive findings packages ranked by real-world exploitability, validated by defensive security analysts.

Strategic Context

Steve Stone, Chief Customer Officer at SentinelOne, stated that attackers are increasingly using AI to exploit weaknesses with greater speed and scale. The integration aims to close this gap by providing customers with prioritized maps and remediation guidance rather than long backlogs.

Frontier AI models have made headlines for their ability to surface novel threats that traditional signatures or scanners may miss. This new reality is already changing how security teams approach exposure and patch management. But bigger lists are rarely helpful in identifying which risks are materially exploitable in a customer’s environment. What’s critical is knowing which exposures an attacker can actually reach, and closing them fast. Wayfinder Frontier AI Services are built precisely for that job, pairing frontier AI models with SentinelOne's elite offensive and defensive security experts so customers get a prioritized map and remediation guidance vs. a longer backlog.

Wayfinder Frontier AI Services is generally available. The new capabilities featuring OpenAI Daybreak models are currently in private preview, with broader availability planned.

What the Numbers Show

The source data highlights a strategic shift toward specialized model deployment rather than general-purpose AI application. By explicitly benchmarking GPT-5.6-Cyber against specific threats like fast16 malware, SentinelOne is validating model efficacy through concrete security outcomes (reverse engineering success) rather than generic performance metrics. This suggests a dependency on high-fidelity threat intelligence to justify the integration of frontier models into operational workflows.

Disclaimer: This article is AI-generated using data from ViewTrade. ScanX is not liable for any inaccuracies.

How might the integration of OpenAI Daybreak models impact SentinelOne's pricing structure and customer adoption rates compared to its existing AI offerings?

What are the potential cybersecurity risks associated with sending sensitive code repositories and telemetry data to third-party frontier AI models for analysis?

How will competitors in the endpoint detection and response (EDR) market respond to SentinelOne's move toward specialized, military-grade malware reverse engineering capabilities?

like18
dislike

More News on SentinelOne Inc