Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

EGAIN Corp EGAN US Equity

Information Technology · CIK 1066194 · FY ends Jun 30
$7.40
-0.08 (-1.07%)
USD · as of 2026-08-28 · marketstack

EGAIN Corp (Nasdaq: EGAN), an SEC filer in Services-Prepackaged Software, closed at $7.40, -1.1%, on 2026-08-28, with a market cap of $205M as of 2026-08-27, a trailing P/E of 6.6, a return on equity of 46.3%, a net margin of 36.5% and 3-year sales growth of -1.3%. Institutional ownership, earnings history and filed financials are on the tabs below.

EGAN · 10-K · period ended 2024-06-30

← all EGAN documents
filed 2024-09-12 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1600 of 2,005249k characters rendered

Table of Contents

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

WASHINGTON, D.C. 20549

FORM 10-K

(Mark One)

For the Fiscal Year Ended June 30, 2024

or

For the transition period from to

Commission File Number: 001-35314

eGain Corporation

(Exact name of registrant as specified in its charter)

1252 Borregas Avenue

Sunnyvale, California94089

(Address of principal executive offices, including zip code)

(408) 636-4500

(Registrant’s telephone number, including area code)

Securities registered pursuant to Section 12(b) of the Act:

Title of Each Class Trading Symbol Name of Each Exchange on Which Registered

Common Stock, par value $0.001 per share EGAN The Nasdaq Stock Market LLC

Securities registered pursuant to Section 12(g) of the Act: None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☐No☒

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days: Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☐ Accelerated filer ☐

Non-accelerated filer ☒ Smaller reporting company ☒

Emerging growth company ​ ☐ ​ ​ ​ ​

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in this filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act): Yes ☐ No ☒.

The aggregate market value of the voting and non-voting common equity held by non-affiliates (based on the closing price on Nasdaq) on December 31, 2023, was approximately $176.5 million.

There were 28,511,553 shares of the Registrant’s Common Stock, par value $0.001 per share, outstanding on September 9, 2024.

DOCUMENTS INCORPORATED BY REFERENCE

Items 10, 11, 12, 13 and 14 of Part III of this Annual Report on Form 10-K incorporate by reference information from the registrant’s proxy statement to be filed with the Securities and Exchange Commission in connection with the solicitation of proxies for the registrant’s 2024 Annual Meeting of Stockholders.

Table of Contents

EGAIN CORPORATION

TABLE OF CONTENTS

2024 FORM 10-K

​ ​ ​ ​ ​

ItemNo. Page

​ ​ ​ ​ ​

​ ​ Forward-Looking Statements ​ 3

​ ​ ​ ​ ​

​ ​ Summary Risk Factors ​ 4

​ ​ ​ ​ ​

PART I ​

​ ​ ​ ​ ​

1. Business 7

​ ​ ​ ​ ​

1A. Risk Factors 14

​ ​ ​ ​ ​

1B. Unresolved Staff Comments 31

​ ​ ​ ​ ​

1C. Cybersecurity 31

​ ​ ​ ​ ​

2. Properties 32

​ ​ ​ ​ ​

3. Legal Proceedings 32

​ ​ ​ ​ ​

4. Mine Safety Disclosures 33

​ ​ ​ ​ ​

PART II ​

​ ​ ​ ​ ​

​ ​ ​ ​ ​

​ ​ ​ ​ ​

​ ​ ​ ​ ​

7A. Quantitative and Qualitative Disclosures About Market Risk 50

​ ​ ​ ​ ​

8. Financial Statements and Supplementary Data 51

​ ​ ​ ​ ​

​ ​ ​ ​ ​

9A. Controls and Procedures 83

​ ​ ​ ​ ​

9B. Other Information 84

​ ​ ​ ​ ​

9C. Disclosure Regarding Foreign Jurisdictions That Prevent Inspections 84

​ ​ ​ ​ ​

PART III ​

​ ​ ​ ​ ​

10. Directors, Executive Officers and Corporate Governance 85

​ ​ ​ ​ ​

11. Executive Compensation 85

​ ​ ​ ​ ​

​ ​ ​ ​ ​

13. Certain Relationships and Related Transactions and Director Independence 85

​ ​ ​ ​ ​

14. Principal Accounting Fees and Services 86

​ ​ ​ ​ ​

PART IV ​

​ ​ ​ ​ ​

15. Exhibits and Financial Statement Schedules 87

​ ​ ​ ​ ​

​ ​ ​ ​ ​

Signatures 90

2

Table of Contents

Forward-Looking Statements

This report contains forward-looking statements that involve risks and uncertainties. These statements relate to future periods, future events or our future operating or financial plans or performance. Often, these statements include the words “believe,” “expect,” “target,” “anticipate,” “intend,” “plan,” “seek,” “estimate,” “potential,” or words of similar meaning, or future or conditional verbs such as “will,” “would,” “should,” “could,” “might,” or “may,” or the negative of these terms, and other similar expressions. These forward-looking statements include statements as to:

● expected benefits of our solutions to our clients and partners;

● our value proposition;

● our business plans, strategies, targets, and outlook;

● changes in technology, including AI technology and services;

● our expectations related to our product development plan;

● our beliefs regarding our prospects for our business;

● changes in demand for our solutions;

● our reliance on strategic and third party distribution partnerships;

● the effect of recent changes in U.S. tax legislation;

● the risks related to our international operations;

● the potential impact of foreign currency fluctuations and inflation; and

● the potential impact of health epidemics.

These forward-looking statements reflect our current views with respect to future events, are based on assumptions and are subject to risks and uncertainties. These risks and uncertainties could cause actual results to differ materially from those projected and include, but are not limited to:

3

Table of Contents

● our ability to improve our current solutions;

● our ability to execute our sales and marketing strategy;

● customer acceptance of our existing and future solutions;

● our ability to predict subscription renewals;

● the impact of new legislation or regulations on our business;

● our ability to compete;

● the success of our strategic and distribution partnerships;

● our ability to obtain capital when needed;

● our ability to manage future growth;

● our ability to retain key personnel and hire additional personnel;

● risks related to protection of our intellectual property;

● foreign currency fluctuations and inflation;

● the global economic environment;

● risks related to public health pandemics; and

● the risks set forth under “Risk Factors.”

Given these risks and uncertainties, you should not place undue reliance on these forward-looking statements. Except as required by federal securities laws, we undertake no obligation to update any forward-looking statements for any reason, even if new information becomes available or other events occur in the future.

All references to “eGain”, the “Company”, “our”, “we” or “us” mean eGain Corporation and its subsidiaries, except where it is clear from the context that such terms mean only eGain and exclude its subsidiaries.

eGain and eGain® are trademarks of eGain Corporation. We also refer to trademarks of other corporations and organizations in this report

Summary Risk Factors

Our business is subject to numerous risks and uncertainties that could affect our ability to successfully implement our business strategy and affect our financial results. You should carefully consider all of the information in this report and, in particular, the following principal risks and all of the other specific factors described in Item 1A. of this report, “Risk Factors,” before deciding whether to invest in our company.

● Our SaaS business model is subject to certain risks.

4

Table of Contents

5

Table of Contents

6

Table of Contents

PART I

ITEM 1. BUSINESS

Overview

eGain automates customer engagement with an AI knowledge hub SaaS solution. We sell to enterprises who want to better serve customers at scale by delivering trusted answers across self-service, contact centers, and field staff. True to our mantra of AX + BX + CX = DXTM, our AI knowledge hub orchestrates effortless Digital eXperience (DX) as it assists Agent eXperience (AX), empowers Business eXperience (BX) and assures Customer eXperience (CX). Many global brands use eGain to improve experience and reduce costs. We are headquartered in the Sunnyvale, California, United States. We also operate in the United Kingdom and India.

Industry Background

Introduction

According to Gartner Research, a majority of contact center agents are not satisfied with their desktop tools. Our assessment, based on more than two decades of serving clients is that good contact center agents ignore most information piled on their screens across multiple windows and tabs when they are interacting with customers. They focus on the customer conversation. Meanwhile, businesses expect agents to remember and refresh growing knowhow that is needed to answer customer questions across complex, expanding product portfolios and compliance-heavy processes, and then recall relevant knowhow contextually in the moment of truth – when the customer is on the line. In addition, this is expected of an entry-level workforce that is not well-paid, routinely replaced, and globally dispersed – mainly for cost reasons. This knowledge and guidance gap for agents in the flow of their work explains Gartner Research’s top technology recommendation for customer service and support leaders since 2022: invest in knowledge management tools.

AI Economy Demands Modern Knowledge Management

In a world selling commoditized, yet complex products to time-strapped customers, smart tools must automate the routine and augment the interesting across agent, business and customer support tasks. This need has been amplified by the disruption of traditional work models by COVID-19. Businesses realize that they need to invest in tools that can guide agents and customers with trusted answers, ensuring customer satisfaction and compliance. Recently we have seen the generative AI surprises pop up across businesses as businesses jumped into generative AI without solving the foundational knowledge needed to provide trusted input content to generative AI. Not surprisingly, businesses are quickly seeking modern knowledge management solutions.

AI Knowledge for Customer Engagement

To automate customer engagement, generative AI needs trusted content from a knowledge hub that ensures correct, compliant content is served with adequate controls. A knowledge hub can be built and maintained with much less time and cost using AI. It is a perfect technology intersection where AI needs knowledge and knowledge can be built easier with AI.

Contact Centers are a Brand Battleground

Contact centers offer significant opportunities to realize the transformation potential of generative AI. According to Forrester Research, there were 17 million contact center agents in 2023, with 71% of contact centers looking to hire more. Time-starved customers consuming complex products and grappling with extreme choices generate stubbornly high levels of customer contact. They need quick, correct, and assured help. The business impact of applying AI at scale on contact center operations can save the global economy hundreds of billions of dollars annually.

7

Table of Contents

Customer Engagement Automation is a Large, Growing Market

Businesses continue to invest in digital transformation, especially in customer engagement. To further reduce cost and improve experience, businesses want to harness AI knowledge to automate customer service via omnichannel, conversational interfaces. According to McKinsey, the aggregate cost of customer operations in the global economy is $1.5 trillion. They anticipate that businesses could reduce this cost by 35% using AI. Given these potential savings, the associated market opportunity for SaaS solutions is huge. According to a recent Gartner Research prediction, by 2025, 100% of all virtual customer assistant and virtual agent assistant projects that are not integrated with a modern knowledge management system will fail to meet their experience improvement and operational cost-reduction goals.

The eGain Approach and Benefits

What Customers Want

We believe customer service queries fall into three categories: informational, transactional, and situational. Any given customer contact can morph across these categories as the conversation develops. Tools must orchestrate customer contact with context —accounting for machine-human hand-offs (mixed-initiative interaction), channel switching, multimodal interaction, and conversational pause-and-resume. During these interactions, customers increasingly want trusted answers and guidance.

The eGain Solution is Comprehensive

eGain offers a comprehensive, unified solution organized into three hubs—eGain Knowledge HubTM, eGain Conversation HubTM, and eGain Analytics HubTM, to automate, augment and orchestrate digital-first customer engagement. We believe our feature-rich portfolio of applications empowers businesses to connect, solve, and optimize agent, business, and customer experience.

Solve with eGain Knowledge Hub

Our Knowledge Hub helps businesses to centralize knowledge, policies, procedures, situational expertise, and best-practices, while delivering guided, personalized, and trusted answers to customers, agents, and field staff. We believe our guided knowledge and virtual assistance applications ensure that all agents easily resolve customer queries, regardless of product or procedure.

Connect with eGain Conversation Hub

Our Conversation Hub offers comprehensive, scalable capabilities for digital-first, omnichannel interaction management within a modern, purpose-built desktop. Rich applications, powered by our Knowledge and AI capabilities (from our Knowledge Hub), proactively guide agents to efficiently interact with customers using chatbots, messaging applications, short message service (SMS), chat, email, social media, phone, video, fax, and letter.

Optimize with eGain Analytics Hub

Our Analytics Hub enables clients to measure, manage and optimize their omnichannel service operations and knowledge. In addition, embedded AI and Machine Learning (ML) helps clients generate product improvement and customer insights, while spotting opportunities to improve experience and automate processes.

Open, Secure APIs and Third-Party Connectors Deliver Quick Value

Our open, secure platform APIs enable clients and partners to extend and enhance our solutions and to integrate with enterprise assets to enable a single view of the customer. Pre-built integrations include connectors to Adobe, Apple Business Chat, Avaya, Amazon Connect, Cisco, Five9, Google Dialogflow, Genesys, Talkdesk, IBM Watson, Microsoft Dynamics, Microsoft SharePoint, Microsoft Teams, Salesforce, SAP, ServiceNow, and Zendesk. We offer a novel

8

Table of Contents

“Bring Your Own” composable architecture to plug external bots, messaging channels, and third-party agent desktops to compose differentiated customer experiences.

Compelling Benefits

Our solution delivers quick value, easy innovation, and big business impact. Specifically, we help businesses:

o Ensure compliance with regulations, policies, procedures, and best practices.

Competitive Strengths

Composable Platform with Rich APIs, Events, and UX Widgets

The eGain solution is a comprehensive omnichannel solution for the customer engagement market, with AI and knowledge applications at its core. We unlock the full power of our cloud platform with extensive APIs on a composable architecture, served via a developer portal to enable knowledge everywhere to power omnichannel customer and employee experiences.

Enterprise-Grade, Secure Cloud Service with Differentiated Offerings

Our cloud offering is secure, scalable, and offers unique capabilities. With respect to security and certification, we offer SOC2, PCI, HIPAA, FedRAMP, and GDPR certification. We are also approved as a supplier on Crown Commercial Service’s (CCS) G-Cloud Framework in the UK market. The Internal Revenue Service uses our solutions served from the eGain Cloud.

Transformative Value at Scale Across Diversified Customer Base

Our solution delivers transformative value at scale. We believe that our understanding of the customer need and our ability to fulfill it with enterprise-grade capability is unmatched. Our clients range from over a hundred thousand users at a healthcare client using our solution on a 24x7 basis to a Property and Casualty (P&C) insurer with fifteen thousand contact center advisors and thirty-thousand field agents.

Market-leading Innovation with a Risk-free Trial Model

To de-risk customer decisions, we offer a unique Innovation in 30 DaysTM program—a 30-day guided production pilot in the eGain Cloud – at no cost and with no strings attached. Businesses can experience our product with their data, content, and process in a production setting.

Direct Go-to-market Strategy, Complemented by a Growing Partner Ecosystem

We take our solutions to market through a direct sales model, primarily in North America and Western Europe. We complement direct sales with resell partnerships. We also partner with System Integrators and boutique consultants.

Customers

We mostly sell to large enterprises, which we define as businesses with over a billion dollars in annual revenue or government organizations. Over 82% of our annual recurring cloud revenue for the fiscal year ended June 30, 2024 (which we refer to as fiscal year 2024) came from such large enterprises.

For fiscal year 2024, North America (NA) and combined Europe, Middle East, and Africa (EMEA) revenue accounted for 78% and 22% of total revenue.

9

Table of Contents

One of our largest customers, who is also our partner, accounted for 18% of total revenue in fiscal year 2024.

Competition

We compete with application software providers, including LivePerson, Inc., NICE, Ltd., and Verint Systems Inc. In addition, we occasionally compete with some of our platform partners where some of our product capabilities overlap, including Five9, Genesys, Microsoft, Salesforce, and ServiceNow.

Our target market is highly competitive and some of our competitors may have longer operating histories, greater economies of scale, greater financial resources, greater engineering and technical resources, greater sales and marketing resources, stronger strategic partnerships and distribution channels, larger user bases, products and services with different functions, and feature sets and greater brand recognition than we have. We believe the principal competitive factors in our market include the following:

o proven track record of customer success;

o speed and ease of implementation;

o quick value realization;

o rich product functionality;

o strong analyst ratings;

o strong customer references;

o financial stability and viability of the vendor;

o strong product adoption;

o ease of use and rates of user adoption;

o ease of integration with existing applications;

o quality of customer support;

o vendor reputation and brand awareness.

Growth Strategy

We are investing in multiple programs to accelerate growth.

Advance Product and Platform Leadership

Innovation is in our DNA. We are investing actively in experimenting with, enhancing, and applying AI technologies to accelerate and automate tasks in the knowledge management and customer engagement lifecycle. In addition, we are expanding our platform connectivity to CRM, CCaaS, UCaaS, and CMS platforms with enhanced APIs and connectors.

Invest in Direct Sales and Marketing

We design and execute scalable and personalized marketing programs to boost brand awareness, based on client success, product leadership and no-risk trial offers. To complement our marketing investment, we have built and trained a field sales team to maintain high-touch presence in target accounts.

10

Table of Contents

Develop New Partner Relationships

We are developing new partnerships with complementary platform providers (with large customer bases) to enhance their proposition with our Knowledge-powered customer engagement capabilities. At the same time, we are investing in delivery partnerships to scale our delivery capabilities.

Land and Expand in the Enterprise

With the sustained progress we have made in customer success, we see a replicable pattern emerging: land enterprise logos with a small footprint in one business unit, demonstrate business value, and then expand in the enterprise. We believe we are increasing the value of investment in eGain for our clients by deeply integrating our capabilities via our enhanced APIs with enterprise assets like enterprise collaboration platforms, CRM systems, transaction and billing, and content sources.

Selectively Pursue Acquisitions

From time to time, we pursue inorganic strategies to strengthen our product portfolio. As opportunities arise, we look for strategic acquisitions we believe will deliver compelling value faster than organic options.

Sales and Marketing

Sales Strategy

Our sales strategy is to pursue targeted accounts, mostly B2C (Business-to-Consumer) enterprises and consumer-centric government agencies, through a combination of our direct sales force and partners. These enterprises typically have thousands of customer service agents in their contact centers. Our direct sales force is organized into teams that include field sales representatives and sales consultants. Our direct sales force is complemented by lead generation representatives and sales development representatives. We also complement our direct effort with sales alliances.

Marketing and Partner Strategy

Our marketing strategy is to build our brand around the following pillars: thought leadership, product leadership, and customer advocacy. We have a long track record of thought leadership in this market. Our popular “Knowledge Management for Dummies” publication, for example, enjoys thousands of digital downloads and physical distribution in our target community. Recently, we published a revised edition of this pioneering work with generative AI updates, including relevant AI-powered product info, customer case studies, and best-practices.

Our partners help extend the breadth and depth of our product offerings, drive market awareness, and augment our professional service capabilities. We believe these relationships are important to delivering successful integrated products and services to our customers. Our partner portal, eGain EconetTM, provides comprehensive sales support and services information for partners.

Subscription Services

Our subscription services provide customers with access to our software on a cloud-based platform that we manage and offer on a subscription basis. These subscription services allow our customers to easily consume our product innovation without dealing with infrastructure, installation and ongoing administration. We generally offer these services through a 36-month contract, with pricing based on the number of agents or self-service sessions.

Professional Services

Our worldwide professional services organization provides consulting, implementation, training, and managed services to deliver business value, drive customer success and build customer loyalty.

11

Table of Contents

Customer Support

We offer 24/7 customer support via online and phone channels worldwide under support agreements. Our customer support centers are in the United States, the United Kingdom, and India.

Research and Development

The market for our products changes rapidly and is characterized by evolving industry standards, swift changes in customer requirements, and frequent product introductions.

We continuously analyze market and customer requirements and evaluate external technology that we believe will enhance our competitiveness, increase our lifetime customer value, and expand our target market. Our product roadmap effectively combines build, partner, and buy options.

Intellectual Property

We regard our intellectual property as critical to our success. We rely on intellectual property and other laws, in addition to confidentiality procedures and licensing arrangements, to protect the proprietary aspects of our technology and business.

As of June 30, 2024, we had 17 issued patents in the United States. Our issued U.S. patents expire at various times between 2028 and 2040.

We continually assess the strength of our intellectual property protection for those aspects of our technology that we believe constitute innovations providing significant competitive advantages. Future applications may or may not receive the issuance of valid patents or registered trademarks.

We routinely require our employees, customers, and potential business partners to enter into confidentiality and nondisclosure agreements before we disclose any sensitive aspects of our products, technology, or business plans. In addition, we require employees to agree to surrender to us any proprietary information, inventions or other intellectual property they generate or come to possess while employed by us. Despite our efforts to protect our proprietary rights through confidentiality and license agreements, unauthorized parties may attempt to copy or otherwise obtain and use our products or technology. These precautions may not prevent misappropriation or infringement of our intellectual property. In addition, some of our license agreements with certain customers and partners require us to place the source code for our products into escrow. These agreements typically provide that some party will have a limited, non-exclusive right to access and use this code as authorized by the license agreement if there is a bankruptcy proceeding instituted by or against us, or if we materially breach a contractual commitment to provide support and maintenance to the party.

Human Capital

Our key human capital management objectives are to attract, retain and develop the highest quality talent. To support these objectives, our human resources programs are designed to develop talent to prepare them for critical roles and leadership positions for the future; reward and support employees through competitive pay and benefits; enhance our culture through

12

Table of Contents

efforts aimed at making the workplace more engaging and inclusive; acquire talent and facilitate internal talent mobility to create a high-performing and diverse workforce. As of June 30, 2024, we had 544 employees, including 539 full-time employees, of which 195 were in product development, 229 in services and support, 64 in sales and marketing, and 56 in finance and administration.

None of our employees are covered by collective bargaining agreements. While we believe our relations with our employees are good, our future performance depends largely upon the continued service of our key technical, sales and marketing, and senior management personnel, none of whom are bound by employment agreements requiring service for a defined period of time.

Available Information

We were incorporated in Delaware in September 1997, and our website is located at www.egain.com. We make available free of charge on our website our annual reports on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K and amendments to those reports, as soon as reasonably practicable after we electronically file or furnish such materials to the Securities and Exchange Commission. Our website and the information contained therein or connected thereto are not intended to be incorporated into this Annual Report on Form 10-K.

Information About Our Executive Officers

The following table sets forth information regarding eGain’s executive officers as of September 12, 2024:

​ ​ ​ ​ ​

Name Age Position

Ashutosh Roy 58 Chief Executive Officer and Chairman

Eric N. Smit 62 Chief Financial Officer

Promod Narang 66 Chief Technology Officer

AshutoshRoyco-foundedeGain andhas served asChiefExecutive Officerand a Director of eGain sinceSeptember1997andasPresidentsinceOctober1,2003.FromMay1995through April1997,Mr.RoyservedasChairman of WhoWhere?Inc., an Internet-servicescompany co-founded byMr.Roy. FromJune1994to April1995, Mr.Roy worked atParsecTechnologies, a call centercompany basedin New Delhi,India, which he co-founded.FromAugust1988to August1992,Mr.Royworkedas asoftware engineeratDigital EquipmentCorporation, a major company in the computer industry at the time.Mr.Royholds a B.S.in ComputerSciencefromtheIndian Institute ofTechnology, NewDelhi, a Master’s degreeinComputerSciencefromJohnsHopkinsUniversityand a M.B.A. fromStanford University.

Eric N. Smit has served as Chief Financial Officer since August 2002. Prior to that, Mr. Smit served in a variety of roles at eGain, including Vice President, Operations from April 2001 to July 2002, Vice President, Finance and Administration from June 1999 to April 2001, and Director of Finance from June 1998 to June 1999. From December 1996 to May 1998, Mr. Smit served as Director of Finance for WhoWhere? Inc., an Internet services company. From April 1993 to November 1996, Mr. Smit served as Vice President of Operations and Chief Financial Officer of Velocity Incorporated, a software game developer and publishing company. Mr. Smit holds a Bachelor of Commerce in Accounting from Rhodes University, South Africa.

Promod Narang has served as Chief Technology Officer since November 2022. Mr. Narang joined eGain in October 1998 and served as Director of Engineering and from March 2000 to October 2022, he served as Senior Vice President of Products and Engineering prior to assuming his current position. Prior to joining eGain, Mr. Narang served as President of VMpro, a system software consulting company, from September 1987 to October 1998. Mr. Narang holds a Bachelor of Science in Computer Science from Wayne State University.

13

Table of Contents

ITEM 1A.RISK FACTORS

The risks and uncertainties described below are not the only ones facing us. Other events that we do not currently anticipate or that we currently deem immaterial also may affect our results of operations, cash flows and financial condition.

Risks Related to Our Business and Strategy

Our business is influenced by a range of factors that are beyond our control and that we have no comparative advantage in forecasting.

Factors influencing our business include:

● general economic and business conditions;

● currency exchange rate fluctuations;

● the overall demand for enterprise software and services;

● customer acceptance of cloud-based solutions;

● general political developments.

The global economic climate continues to influence our business. This includes items such as a general tightening in the credit markets, lower levels of liquidity, increases in the rates of default and bankruptcy, and extreme volatility in credit, equity and fixed income markets. These macroeconomic developments negatively affected, and could continue to negatively affect, our business, operating results or financial condition which, in turn, could adversely affect our stock price. A general weakening of, and related declining corporate confidence in, the global economy or the curtailment in government or corporate spending could cause current or potential customers to reduce their technology budgets or be unable to fund software or services purchases, which could cause customers to delay, decrease or cancel purchases of our products and services or cause customers to not pay us or to delay paying us for previously purchased products and services.

Our revenue and operating results have fluctuated in the past and are likely to fluctuate in the future, and because we recognize revenue from subscriptions over a period of time, downturns in revenue may not be immediately reflected in our operating results.

Because we recognize revenue when we have satisfied performance obligations to customers in connection with our sales contracts, most of our revenue each quarter results from recognition of deferred revenue related to agreements entered into during previous quarters. Consequently, declines in new or renewed subscription agreements and maintenance agreements that occur in one quarter will largely be felt in future quarters, both because we may be unable to generate sufficient new revenue to offset the decline and because we may be unable to adjust our operating costs and capital expenditures to align with the changes in revenue. In addition, our subscription model makes it more difficult for us to increase our revenue rapidly in any period, because revenue from new customers must be recognized over the applicable subscription term. It is difficult to forecast the expediency of the transition of our license customers to our cloud delivery model. Accordingly, we believe that period-to-period comparisons of our results of operations should not be relied upon as definitive indicators of future performance.

Other factors that may cause our revenue and operating results to fluctuate include:

● timing of customer budget cycles;

● reduced renewals;

14

Table of Contents

Any of these developments may adversely affect our revenue, operating results and financial condition. Furthermore, we maintain a provision for credit losses resulting from the inability of our customers to make required payments. In such cases, we may be required to defer revenue recognition on sales to affected customers. In the future, we may have to record additional reserves or write-offs, or defer revenue on sales transactions, which could negatively impact our financial results.

Our SaaS business model is subject to certain risks.

Our business is highly dependent on our ability to continue to expand our SaaS business and cloud operations, including keeping pace with the market transition to SaaS solutions. If customers choose not to renew, or reduce, their subscriptions, our operating results and financial results will suffer.

The deferral or loss of one or more significant orders can also materially adversely affect our operating results, especially in a given quarter. As with other software-focused companies, a large amount of our quarterly business tends to come in the last few weeks, or even the last few days, of each quarter. This trend complicates the process of accurately predicting revenue and other operating results, particularly on a quarterly basis. In addition, our business is subject to seasonal factors that may also cause our results to fluctuate from quarter to quarter.

If we are unable to properly manage our SaaS transition, our business may suffer.

We cannot accurately predict subscription renewal rates and the impact these rates may have on our future revenue and operating results.

We allow our customers to elect not to renew their subscriptions for our service after the expiration of their initial subscription period, which is typically 12 to 36 months, and some customers have elected not to renew. In addition, our customers may choose to renew for fewer subscriptions (in quantity or products) or renew for shorter contract lengths. We cannot accurately predict renewal rates given our varied customer base of enterprise and small and medium size business customers and the number of multiyear subscription contracts. Our renewal rates may decline or fluctuate as a result of a number of factors, including customer dissatisfaction with our service, decreases in customers’ spending levels, decreases in the number of users at our customers, pricing changes and general economic conditions. If our customers do not renew their subscriptions for our service or reduce the number of paying subscriptions at the time of renewal, our revenue will decline, and our business will suffer.

Our future success also depends in part on our ability to sell additional features and services, more subscriptions or enhanced editions of our service to our current customers. This may also require increasingly sophisticated and costly sales efforts that are targeted at senior management. Similarly, the rate at which our customers purchase new or enhanced services depends on a number of factors, including general economic conditions and our customers’ reactions to price

15

Table of Contents

changes related to these additional features and services. If our efforts to upsell to our customers are not successful and negative reaction occurs, our business may suffer.

Our lengthy sales cycles and the difficulty in predicting timing of sales or delays may impair our operating results.

The long sales cycle for our products may cause license and subscription revenue and operating results to vary significantly from period to period. The sales cycle for our products can be six months or more and varies substantially from customer to customer. Because we sell complex and deeply integrated solutions, it can take many months of customer education to secure sales. Since our potential customers may evaluate our products before, if ever, executing definitive agreements, we may incur substantial expenses and spend significant management and legal effort in connection with a potential customer.

Our multi-product offering and the increasingly complex needs of our customers contribute to a longer and unpredictable sales cycle. Consequently, we often face difficulty predicting the quarter in which expected sales will actually occur. This contributes to the uncertainty and fluctuations in our future operating results. In particular, the corporate decision-making and approval process of our customers and potential customers has become more complicated. This has caused our average sales cycle to further increase and, in some cases, has prevented the closure of sales that we believed were likely to close.

Because we depend on a relatively small number of customers for a substantial portion of our revenue, the loss of any of these customers or our failure to attract new significant customers could adversely impact our revenue and harm our business.

We have in the past and expect in the future to derive a substantial portion of our revenue from sales to a relatively small number of customers. The composition of these customers has varied in the past, and we expect that it will continue to vary over time. The loss of any significant customer or a decline in business with any significant customer would materially and adversely affect our financial condition and results of operations.

The market for customer engagement software, including generative AI product offerings, is competitive, and our business will be adversely affected if we are unable to successfully compete.

The market for customer engagement software is intensely competitive. Other than product innovation and existing customer relationships, there are no substantial barriers to entry in this market, and established or new entities may enter this market in the future. While software internally developed by enterprises represents indirect competition, we also compete directly with packaged application software vendors, including Genesys Telecommunications Laboratories, Inc., LivePerson, Inc., NICE Ltd., and Verint Systems Inc. In addition, we face actual or potential competition from larger software companies such as Microsoft Corporation, Oracle Corporation, salesforce.com, Inc., ServiceNow, Inc., and similar companies that may attempt to sell customer engagement software to their installed base.

We believe that competition will continue to be fierce as current competitors increase the sophistication of their offerings and as new participants enter the market. Many of our current and potential competitors have longer operating histories, larger customer bases, broader brand recognition, and significantly greater financial, marketing and other resources. With more established and better-financed competitors, these companies may be able to undertake more extensive marketing campaigns, adopt more aggressive pricing policies, and make more attractive offers to businesses to induce them to use their products or services. If we are unable to compete successfully, our business will be adversely affected.

We are also investing in AI across the entire company and infusing generative AI capabilities into our product and service offerings. We expect AI technology and services to be a highly competitive and rapidly evolving market. We will bear significant development and operational costs to build and support the generative AI capabilities, products, and services necessary to meet the needs of our customers. To compete effectively, we must also be responsive to technological change, potential regulatory developments, and public scrutiny. Such competitive pressure may cause decreased sales volumes, price reductions, and/or increased operating costs, such as for research and development, marketing, and sales activities. This may lead to lower revenue, gross margins, and operating income. In addition, customers are currently assessing their AI utilization strategy, so it is difficult to estimate with any reasonable degree of precision the impact of generative AI product offerings on our future revenue or expected demand for our products.

16

Table of Contents

If we fail to expand and improve our sales performance and marketing activities, or retain our sales and marketing personnel, we may be unable to grow our business, which could negatively impact our operating results and financial condition.

Expansion and growth of our business is dependent on our ability to expand our sales force and on the ability of our sales force to increase sales. If we are not able to effectively develop and maintain awareness of our products in a cost-effective manner, we may not achieve widespread acceptance of our existing and future products. This may result in a failure to expand and attract new customers and enhance relationships with existing customers. This may impede our efforts to improve operations in our other areas and may result in declines in the market price of our common stock.

Due to the complexity of our customer engagement hub platform and related products and services, we must utilize highly trained sales personnel to educate prospective customers regarding the use and benefits of our products and services as well as provide effective customer support. If we have turnover in our sales and marketing teams, we may not be able to successfully compete with our competitors, and our results of operations and financial condition may be harmed.

Our failure to maintain, develop, or expand strategic and third-party distribution channels would impede our revenue growth.

Our success and future growth depend in part upon the skills, experience, performance and continued service of our distribution partners, including software and hardware vendors and resellers. Our distribution partners engage with us in a number of ways, including assisting us to identify prospective customers, distributing our products and services in geographies where we do not have a physical presence and distributing our products and services where they are considered complementary to other products of the partner or third-party products distributed by the partner. We believe that our future success depends in part upon our ability to develop, maintain and expand strategic, long-term and profitable partnerships and reseller relationships. If we are unable to do so for any reason, including as a result of any change in the leadership of our distribution partners, or if any existing or future distribution partners fail to successfully market, resell, implement or support our products for their customers, or if distribution partners represent multiple providers and devote greater resources to market, resell, implement and support competing products and services, our future revenue growth could be impeded.

We sometimes rely on distribution partners to recommend our products to their customers. We likewise depend on broad market acceptance by these distribution partners of our product and service offerings. Our agreements generally do not prohibit competitive offerings and our distribution partners may develop market or recommend software applications that compete with our products. To the extent we devote resources to these relationships and the partnerships do not proceed as anticipated or provide revenue or other results as anticipated, our business may be harmed. Once partnerships are forged, there can be no guarantee that such relationships will be renewed in the future or available on acceptable terms. If we lose strategic third-party relationships, fail to renew or develop new relationships, or fail to fully exploit revenue opportunities within such relationships, our results of operations and future growth may suffer.

Difficulties and delays in customers implementing our products could harm our revenue and margins.

We generally recognize revenue upon the transfer of control of promised services to our customers in the amount that is commensurate with the consideration that we expect to receive in exchange for those services. If an arrangement requires significant customization or implementation services from us, recognition of the associated subscription and service revenue could be delayed. The timing of the commencement and completion of these services is subject to factors that may be beyond our control, as this process may require access to the customer’s facilities and coordination with the customer’s personnel after delivery of the software obligations. In addition, customers could cancel or delay product implementations. Implementation typically involves working with sophisticated software, computing, and communications systems. If we experience difficulties with implementation or do not meet project milestones in a timely manner, we could be obligated to devote more customer support, engineering, and other resources to a particular project. Some customers may also require us to develop customized features or capabilities. If new or existing customers cancel or have difficulty deploying our products or require significant amounts of our professional services, support, or customized features, revenue recognition could be cancelled or further delayed and our costs could increase, causing increased variability in our operating results.

17

Table of Contents

Implementation services may be performed by our own staff, by a third-party partner or by a combination of the two. Our strategy is to work with partners to increase the breadth of capability and depth of capacity for delivery of these services to our customers, and we expect the number of our partner-led implementations to continue to increase over time. If a customer is not satisfied with the quality of work performed by us or a partner or with the type of professional services or functionality delivered, even if we are not contractually responsible for the partner services, then we could incur additional costs to address the situation, the profitability of that work might be impaired and the customer’s dissatisfaction with our or our partner’s services could damage our ability to expand the scope of functionality subscribed to by that customer. In addition, negative publicity related to our customer relationships, regardless of its accuracy, may further damage our business by affecting our ability to compete for new business with current and prospective customers.

We conduct a significant portion of our business and operations outside of the United States, which exposes us to additional risks that may not exist in the United States. These risks in turn could cause our operating results and financial condition to suffer.

We derived 22% of our revenue from EMEA sales during the fiscal years ended June 30, 2024 and 2023. In addition to those discussed elsewhere in this section, our EMEA sales operations are subject to a number of specific risks, such as:

● foreign currency fluctuations and imposition of exchange controls;

● difficulty and costs in staffing and managing our international operations;

● difficulties in collecting accounts receivable and longer collection periods;

● health or similar issues, such as a pandemic or epidemic;

● various trade restrictions and tax consequences;

● reduced intellectual property protections in some countries.

Any of the above risks could adversely affect our international operations, reduce our revenue from customers outside of the United States or increase our operating costs, each of which could adversely affect our business, results of operations, financial condition, and growth prospects.

As of June 30, 2024, approximately 45% of our workforce was employed in India. Of our employees in India, 46% are allocated to research and development. Although the movement of certain operations internationally was principally motivated by cost cutting, the continued management of these remote operations requires significant management attention and financial resources that could adversely affect our operating performance. In addition, with the significant increase in the numbers of foreign businesses that have established operations in India, the competition to attract and retain employees there has increased significantly. As a result of the increased competition for skilled workers, we experienced increased compensation costs and expect these costs to increase in the future. Our reliance on our workforce in India makes us particularly susceptible to disruptions in the business environment in that region. In particular, sophisticated telecommunications links, high-speed data communications with other eGain offices and customers, and overall consistency and stability of our business infrastructure are vital to our day-to-day operations, and any impairment of such infrastructure will cause our financial condition and results to suffer. In addition, the maintenance of stable political relations between the United States, the European Union (EU), and India are also of great importance to our operations.

Any of these risks could have a significant impact on our product development, customer support, or professional services. To the extent the benefit of maintaining these operations abroad does not exceed the expense of establishing and maintaining such activities, our operating results and financial condition will suffer.

18

Table of Contents

Unplanned system interruptions, delays in service or inability to increase capacity, including internationally, at our third-party data center facilities could impair the use or functionality of our cloud operations and harm our business.

Our customers have in the past experienced some interruptions with our cloud operations. We believe that these interruptions will continue to occur from time to time. These interruptions could be due to hardware and operating system failures. As a result, our business will suffer if we experience frequent or long system interruptions that result in the unavailability or reduced performance of our hosted operations or reduce our ability to provide remote management services. We expect to experience occasional temporary capacity constraints due to sharply increased traffic or other Internet-wide disruptions, which may cause unanticipated system disruptions, slower response times, impaired quality, and degradation in levels of customer service. If this were to continue to happen, our business and reputation could be seriously harmed.

Our success largely depends on the efficient and uninterrupted operation of our computer and communications hardware and network systems. We currently serve our customers from third-party data center facilities operated by third parties in the United States and other international locations. Any damage to, or failure of, our systems generally could interrupt service or impair the use or functionality of our cloud operations. In addition, as we continue to increase the number of customers and users on our cloud operations, we will need to increase the capacity of our data center infrastructure. If we do not increase our capacity in a timely manner, customers could experienceinterruptions or delays in access to our cloud operations.Customer data that we store in third party data centers may also be vulnerable to damage or interruption from floods, fires, earthquake, power loss, telecommunications failures and similar events. Any damage to, or failure of, our systems, or those of our third-party data centers, could result in impairment of, or interruptions in, our service. Impairment or interruptions in our service may reduce our revenue, cause us to issue credits, pay penalties, or cause customers to terminate their subscriptions and adversely affect our renewal rate and our ability to attract new customers. Our business will also be harmed if our customers and potential customers believe our cloud operations are unreliable.

We maintain a business continuity plan for our customers in the event of an outage. We maintain other co-locations for the purpose of disaster recovery as well as maintaining backups of our customer’s information. We provide premium disaster recovery and standard disaster recovery to our customers. If a customer opts not to pay for premium disaster recovery, we will only assure that their data is available within 72 hours. This delay could cause severe disruptions to our customers’ customers and may result in customer termination of our solutions. Our premium disaster recovery service provides for an alternative data center and a return to operations within one business day.

We have entered into support obligations with our customers that require minimum performance standards, including standards regarding the response time of our support services. If we fail to meet these standards, our customers could terminate their relationships with us, and we could be subject to contractual refunds, and exposure to claims for losses by, customers.

Software errors could be costly and time-consuming for us to correct, and could harm our reputation and impair our ability to sell our solutions.

Our solutions are based on complex software that may contain errors, or “bugs,” that could be costly to correct, harm our reputation, and impair our ability to sell our solutions to new customers. Moreover, customers relying on our solutions may be more sensitive to such errors and potential security vulnerabilities and business interruptions for these applications. If we incur substantial costs to correct any errors of this nature, our operating margins could be adversely affected. Because our customers depend on our solutions for critical business functions, any service interruptions could result in lost or delayed market acceptance and lost sales, higher service-level credits and warranty costs, diversion of development resources, and product liability suits.

The terms we agree to in our Service Level Agreements or other contracts may result in increased costs or liabilities, which would in turn affect our results of operations.

Our Service Level Agreements provide for service credits for system unavailability, and in some cases, indemnities for loss, damage, or costs resulting from use of our system. If we were required to provide any of these in a material way, our results of operations would suffer.

19

Table of Contents

If we are unable to increase the profitability of subscription revenue, if we experience significant customer attrition, or if we are required to delay recognition of revenue, our operating results could be adversely affected.

We have invested, and expect to continue to invest, substantial resources to expand, market, implement, and refine our cloud offerings. If we are unable to increase the volume of our subscription business, we may not be able to achieve sustained profitability.

Factors that could harm our ability to improve our gross margins, which may affect our operating profitability, include:

We depend on broad market acceptance of our applications and of our business model. If our expectations regarding the market for our applications are not met, our business could be seriously harmed.

We depend on the widespread acceptance and use of our applications as an effective solution for businesses seeking to manage high volumes of customer interactions across multiple channels, including Web, phone, email, print and in-person. While we believe the potential to be very large, we cannot accurately estimate the size or growth rate of the potential market for such product and service offerings generally, and we do not know whether our products and services in particular will achieve broad market acceptance. The market for customer engagement software is rapidly evolving, and concerns over the security and reliability of online transactions, the privacy of users and quality of service or other issues may inhibit the growth of the Internet and commercial online services. If the market for our applications fails to grow or grows more slowly than we currently anticipate, our business will be seriously harmed.

Furthermore, our business model is premised on business assumptions that are still evolving. Our business model assumes that both customers and companies will increasingly elect to communicate through multiple channels, as well as demand integration of the online channels into the traditional telephone-based call center. If any of these assumptions is incorrect or if customers and companies do not adopt digital technology in a timely manner, our business will be seriously harmed and our stock price will decline.

We may be unable to respond to the rapid technological change and changing customer preferences in the online sales, marketing, customer service, and/or online consumer services industries and this may cause our business to suffer.

If we are unable, for technological, legal, financial or other reasons, to adapt in a timely manner to changing market conditions in the online sales, marketing, customer service and/or e-commerce industry or our customers’ or Internet users’ requirements or preferences, our business, results of operations and financial condition would be materially and adversely affected. Business on the Internet is characterized by rapid technological change. In addition, the market for online sales, marketing, customer service and expert advice solutions is relatively new. Changes in customer and Internet user requirements and preferences, frequent new product and service introductions embodying new technologies and the emergence of new industry standards and practices such as but not limited to security standards could render our services and our proprietary technology and systems obsolete. The rapid evolution of these products and services will require that

20

Table of Contents

we continually improve the performance, features and reliability of our services. Our success will depend, in part, on our ability to:

● enhance the features and performance of our services;

● develop and offer new services that are valuable to companies; and

If any of our new services, including upgrades to our current services, do not meet our customers’ expectations, our business may be harmed. Updating our technology may require significant additional capital expenditures and could materially and adversely affect our business, results of operations, and financial condition.

If new services require us to grow rapidly, this could place a significant strain on our managerial, operational, technical, and financial resources. In order to manage our growth, we could be required to implement new or upgraded operating and financial systems, procedures and controls. Our failure to expand our operations in an efficient manner could cause our expenses to grow, our revenue to decline or grow more slowly than expected and could otherwise have a material adverse effect on our business, results of operations and financial condition.

We employ third-party technologies for use in or with our platform and the inability to license such technologies on commercially reasonable terms or the inability to maintain these licenses or errors in the software we license could result in increased costs, or reduced service levels, which could adversely affect our business.

Our platform incorporates certain third-party software obtained under licenses from other companies, and we use third-party software development tools as we continue to develop and enhance our platform. We anticipate that we will continue to rely on such third-party software in the future. Although we believe that there are commercially reasonable alternatives to the third-party software we currently license, this may not always be the case, or it may be difficult or costly to replace such software. In addition, integration of the software used in our platform with new third-party software may require significant work and require substantial investment of our time and resources. Also, to the extent that our platform depends upon the successful operation of third-party software in conjunction with our software, any undetected errors or defects in this third-party software could prevent the deployment or impair the functionality of our platform, delay new feature introductions, result in a failure of our functionality, and injure our reputation. Our use of additional or alternative third-party software would require us to enter into license agreements with third parties. To the extent we need to license third-party technologies, we may be unable to do so on commercially reasonable terms or at all.

Third-party licenses may expose us to increased risks, including risks associated with the integration of new technology, the diversion of resources from the development of our own proprietary technology, and our inability to generate revenue from new technology sufficient to offset associated acquisition and maintenance costs. In the event that we are not able to maintain our licenses to third-party software, or cannot obtain licenses to new software as needed, or in the event third-party software used in conjunction with our platform contains errors or defects, our business, operating results, and financial condition may be adversely affected.

Our offshore product development, support and professional services may prove difficult to manage or may not allow us to realize our cost reduction goals, produce effective new solutions and provide professional services to drive growth.

We use offshore resources to perform new product and services development and provide support and professional consulting efforts, which requires detailed technical and logistical coordination. We must ensure that our international resources and personnel are aware of and understand development specifications and customer support, as well as implementation and configuration requirements and that they can meet applicable timelines. If we are unable to maintain acceptable standards of quality in support, product development and professional services, our attempts to reduce costs and drive growth through new products and margin improvements in technical support and professional services may be negatively impacted, which would adversely affect our results of operations. Outsourcing services to offshore providers may expose us to misappropriation of our intellectual property or that of our customers, or make it more difficult to defend intellectual property rights in our technology.

21

Table of Contents

If we are unable to hire and retain key personnel, our business and results of operations would be negatively affected.

Our success will depend in large part on the skills, experience and performance of our senior management, engineering, sales, marketing and other key personnel. The loss of the services of any of our senior management or other key personnel, including our Chief Executive Officer and co-founder, Ashutosh Roy, could harm our business. Additionally, in the technology industry, there is substantial and continuous competition for highly skilled business, product development, technical and other personnel. We may also experience increased compensation costs that are not offset by either improved productivity or higher sales. Our failure to recruit new personnel and to retain and motivate existing personnel could have significant negative effects on us, including impairing our ability to expand our business, and our results of operations could suffer.

We may not be able to realize the benefits of offering the limited, free “Innovation in 30 days” version of our service.

We offer a limited version of our subscription service to customers or potential customers free of charge (known as “Innovation in 30 days”) in order to promote usage, brand and product awareness, and adoption, and we invest time and resources for such initial engagements without compensation from the customers. Some customers never enter into a definitive contract for our paid subscription service despite the time and effort we may have expended on such initiatives. To the extent that these customers do not become paying customers, we will not realize the intended benefits of this marketing effort, and our ability to grow our business and revenue may be harmed.

We may not be able to raise additional capital on acceptable terms, if at all, or without dilution to our stockholders which could limit our ability to grow our business and expand our operations.

Our working capital requirements in the foreseeable future are subject to numerous risks and will depend on a variety of factors. We may seek additional funding to finance our operations or should we make acquisitions. We may also need to secure additional financing due to unforeseen or unanticipated market conditions. We may try to raise additional funds through public or private financings, strategic relationships, or other arrangements. Such financing may be difficult to obtain on terms acceptable to us, if at all. If we raise additional funds through the issuance of equity or convertible securities, then the issuance could result in substantial dilution to existing stockholders. If we raise additional funds through the issuance of debt securities or preferred stock, these new securities would have rights, preferences, and privileges senior to those of the holders of our common stock. In addition, the terms of these securities could impose restrictions on our operations. If we are not able to raise additional funds on terms acceptable to us, if and when needed, our ability to fund our operations, take advantage of opportunities, and develop or expand our business could be significantly limited.

Our provision may be insufficient to cover accounts receivable we are unable to collect.

We assume a certain level of credit risk with our customers in order to do business. Conditions affecting any of our customers could cause them to become unable or unwilling to pay us in a timely manner, or at all, for products or services we have already provided them. In the past, we have experienced collection delays from certain customers, and we cannot predict whether we will continue to experience similar or more severe delays in the future. Although we have established provision to cover losses due to delays or inability to pay, there can be no assurance that such reserves will be sufficient to cover our losses. If losses due to delays or inability to pay are greater than our reserves, it could harm our business, operating results and financial condition.

22

Table of Contents

If we acquire companies or technologies, we may not realize the expected business benefits, the acquisitions could prove difficult to integrate, disrupt our business and adversely affect our operations.

As part of our business strategy, we periodically make investments in, or acquisitions of, complementary businesses, joint ventures, services and technologies and intellectual property rights, and we expect that we will continue to make such investments and acquisitions in the future. Acquisitions and investments involve numerous risks, including:

● diversion of financial and managerial resources from existing operations;

● potential loss of key employees;

● potential unknown liabilities associated with the acquired businesses;

● delays in customer purchases due to uncertainty related to any acquisition;

● challenges caused by distance, language and cultural differences;

● the tax effects of any such acquisitions.

We may be subject to legal liability and/or negative publicity for the services provided to consumers through our technology platforms.

Our technology platforms enable representatives of our customers as well as individual service providers to communicate with consumers and other persons seeking information or advice on the Internet. The law relating to the liability of online platform providers such as us for the activities of users of their online platforms is often challenged in the U.S. and internationally. We may be unable to prevent users of our technology platforms from providing negligent, unlawful or inappropriate advice, information or content through our technology platforms, or from behaving in an unlawful manner, and we may be subject to allegations of civil or criminal liability for negligent, fraudulent, unlawful or inappropriate activities carried out by users of our technology platforms.

Claims could be made against online services companies under both U.S. and foreign law such as fraud, defamation, libel, invasion of privacy, negligence, copyright or trademark infringement, or other theories based on the nature and content of the materials disseminated by users of our technology platforms. In addition, domestic and foreign legislation has been proposed that could prohibit or impose liability for the transmission over the Internet of certain types of information. Our

23

Table of Contents

defense of any of these actions could be costly and involve significant time and attention of our management and other resources.

The Digital Millennium Copyright Act (DMCA) is intended, among other things, to reduce the liability of online service providers for listing or linking to third-party web properties that include materials that infringe copyrights or rights of others. Additionally, portions of the Communications Decency Act (CDA) are intended to provide statutory protections to online service providers who distribute third party content. A safe harbor for copyright infringement is also available under the DMCA to certain online service providers that provide specific services, if the providers take certain affirmative steps as set forth in the DMCA. Certain questions regarding the safe harbor under the DMCA and the CDA have yet to be litigated, and we cannot guarantee that we will meet the safe harbor requirements of the DMCA or of the CDA. If we are not covered by a safe harbor, for any reason, we could be exposed to claims, which could be costly and time-consuming to defend.

If our cybersecurity systems or the systems of our vendors, partners and suppliers are breached and unauthorized access is obtained to a customer’s data or our data or IT systems, our service may be perceived as not being secure, customers may curtail or stop using our service and we may incur significant legal and financial exposure and liabilities.

Security incidents have become more prevalent across industries and the methods and techniques used by threat actors continue to evolve at a rapid pace. These cyberattacks may occur on our systems and we may be unable to identify current attacks, anticipate these attacks or implement adequate security measures. Our service involves the storage and transmission of customers’ proprietary information, and security incidents could expose us to a risk of loss of this information, loss of access, litigation and possible liability. The techniques used to effect unauthorized penetration of computer systems are constantly evolving and have been increasing in sophistication. While we have security measures in place that are designed to protect customer information and prevent data loss and other security breaches, these security measures may be breached as a result of third-party action, including intentional misconduct by computer hackers (which may involve nation states and individuals sponsored by them), employee error, malfeasance or otherwise and result in someone obtaining unauthorized access to our customers’ data or our data, including our intellectual property and other confidential business information, or our IT systems. Additionally, third parties may attempt to fraudulently induce employees or customers into disclosing sensitive information such as user names, passwords or other information in order to gain access to our customers’ data or our data or IT systems.

Employees or contractors have introduced vulnerabilities in, and enabled the exploitation of, our IT environments in the past and may do so in the future. These cybersecurity attacks threaten to misappropriate our proprietary information, cause interruptions of our IT services and commit fraud. Because the techniques used to obtain unauthorized access, or to sabotage systems, change frequently and generally are not recognized until launched against a target, we may be unable to anticipate these techniques or to implement adequate preventative measures. Further, if unauthorized access or sabotage remains undetected for an extended period of time, the effects of such breach could be exacerbated. In addition, our ability to defend against and mitigate cyberattacks depends in part on prioritization decisions that we and third parties upon whom we rely make to address vulnerabilities and security defects. While we endeavor to address all identified vulnerabilities in our products, we must make determinations as to how we prioritize developing and deploying the respective fixes, and we may be unable to do so prior to an attack.

In addition, our customers may authorize third party access to their customer data located in our cloud environment. Because we do not control the transmissions between customer authorized third parties, or the processing of such data by customer authorized third parties, we cannot ensure the integrity or security of such transmissions or processing.

Cybersecurity attacks could require significant expenditures of our capital and diversion of our resources.If these attacks are successful, they could result in the theft of proprietary, personally identifiable, confidential and sensitive information of ours, our employees, our customers and our business partners, and could materially disrupt business for us, our customers and our business partners. A successful cybersecurity attack involving our data center, network or software products could also negatively impact the market perception of the effectiveness of our products or lead to contractual disputes, litigation or government regulatory action against us, any of which could materially adversely affect our business, reputation and resulting operations.

24

Table of Contents

We may also experience disruptions, outages, and other performance problems on our systems due to service attacks, unauthorized access, or other security-related incidents. For example, third parties may conduct attacks designed to temporarily deny customers access to our services. Any successful denial of service attack could result in a loss of customer confidence in the security of our platform and damage to our brand.

Our platform involves the storage and transmission of our customers’ information, which may including their business and financial data. As a result, unauthorized access to customer data or security breaches could result in the loss, or unauthorized dissemination, of such data, which could seriously harm our or our customers’ businesses and reputations. Any of these security incidents could negatively affect our ability to attract new customers, cause existing customers to elect to not renew their subscriptions, result in reputational damage or subject us to third-party lawsuits, regulatory fines, or other action or liability, which could adversely affect our operating results. Any insurance coverage we may have related to security and privacy damages may not be adequate for liabilities actually incurred and we cannot be certain that insurance will continue to be available to us on economically reasonable terms, or at all. These risks are likely to increase as we continue to grow the scale and functionality of our platform and process, store, and transmit increasingly large amounts of our customers’ information and data, which may include proprietary or confidential data or personal or identifying information.

Changes in the European regulatory environment regarding privacy and data protection regulations, such as the GDPR, could expose us to risks of noncompliance and costs associated with compliance.

We have in the past relied on adherence to the U.S. Department of Commerce’s Safe Harbor Privacy Principles, the U.S.- EU and U.S.-SwissSafe Harbor Frameworks, and their successors, the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks, as agreed to and set forth by the U.S. Department of Commerce, and the EU and Switzerland, which established a means for legitimating the transfer of personally identifiable information (PII) by U.S. companies doing business in Europe from the European Economic Area (EEA) and Switzerland to the U.S. However, as a result of the October 6, 2015 EU Court of Justice (ECJ), opinion in Case C-362/14 (Schrems v. Data Protection Commissioner) regarding the adequacy of the U.S.-EU Safe Harbor Framework, and the July 16, 2020 ECJ judgment in Case C-311/18 (Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems) regarding the adequacy of the Privacy Shield Framework, both frameworks are no longer deemed to constitute a valid method of compliance with restrictions set forth in European law regarding the transfer of data outside of the EEA. The EJC also noted that standard contractual clauses (approved by the European Commission as an adequate personal data transfer mechanism) may not necessarily be relied upon in all circumstances. In addition to other mechanisms, in limited circumstances we may rely on Privacy Shield certifications of third parties (for example, vendors and partners). The European Commission and the United Kingdom’s Information Commissioner’s Office have published new standard contractual clauses that are required to be implemented. Following issuance of a U.S. Executive Order, a new framework, the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”) was created as a successor to the Privacy Shield. Following an adequacy decision issued by the European Commission on July 10, 2023, the DPF, along with a UK extension to the EU-U.S. DPF that allows the transfer of personal data from the UK to the U.S. (the “UK DPF Extension”), is available for companies as a lawful transfer mechanism for personal data transfers to the U.S. from the EEA and UK. The Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) also has been established, but has not yet been granted an adequacy decision by the Swiss Federal Data Protection and Information Commissioner. We have self-certified to the EU-U.S. DPF, the UK DPF Extension, and the Swiss-U.S. DPF. The EU-U.S. DPF already has been the subject of legal challenge, however, and more generally, these frameworks may be subject to legal challenges from privacy advocacy groups or others. Additionally, the European Commission's adequacy decision regarding the DPF provides that the DPF will be subject to future reviews and may be subject to suspension, amendment, repeal, or limitations in scope by the European Commission. These developments regarding cross-border data transfers have created uncertainty and increased the risk around our international operations and may require us to review and amend the legal mechanisms by which we make or receive personal data transfers to the U.S. and other jurisdictions. We may, among other things, be required to implement additional contractual and technical safeguards for any personal data transferred out of the EEA, Switzerland, the United Kingdom or other regions which may increase compliance costs, lead to increased regulatory scrutiny or liability, may require additional contractual negotiations, and may adversely impact our business, financial condition and operating results.

We may also experience hesitancy, reluctance, or refusal by European or multi-national customers to continue to use our services due to the potential risk exposure to such customers as a result of the international legal developments. We and our customers are at risk of enforcement actions taken by an EU or UK data protection authority until such point in time

25

Table of Contents

that we ensure that all data transfers to us from the EEA and UK are legitimized. We may find it necessary to establish systems to maintain EU/UK-origin data in the EEA or UK, which may involve substantial expense and distraction from other aspects of our business.

We publicly post our privacy policies and practices concerning our processing, use and disclosure of PII. Our publication of our privacy policy and other public statements that provide promises and assurances about privacy and security can subject us to potential governmental action if they are found to be deceptive or misrepresentative of our practices. Further, the costs of compliance with, and other burdens imposed by, such laws, regulations and policies that are applicable to us may limit the use and adoption of our products and solutions and could have a material adverse impact on our results of operations.

Privacy concerns and laws, evolving regulation of cloud computing and other domestic or foreign regulations may limit the use and adoption of our solutions and adversely affect our business.

Further to the above, regulation related to the provision of services on the Internet is increasing, as federal, state and foreign governments continue to adopt new laws and regulations addressing data privacy and the collection, processing, storage and use of personal information. Further, laws are increasingly aimed at the use of personal information for marketing purposes, such as the EU’s e-Privacy Directive (which is set to be replaced by a new EU e-Privacy Regulation which will have a “direct effect” in each EU Member State), and the country-specific regulations that implement that directive. These and other requirements could reduce demand for our solutions or restrict our ability to store and process data or, in some cases, impact our ability to offer our services and solutions in certain locations. Although we have implemented contracts, diligence programs, policies and procedures designed to address compliance with applicable laws and regulations, there can be no assurance that our employees, contractors, partners, suppliers, data providers or agents will not violate such laws and regulations or our contracts, policies and procedures. Additionally, public perception and standards related to the privacy of personal information can shift rapidly, in ways that may affect our reputation or influence regulators to enact regulations and laws that may limit our ability to provide certain products and services. For example, numerous jurisdictions, including the EU, are considering laws and regulations that would impose additional data privacy and other compliance requirements on the use of AI and could require us to adjust or limit our product offerings in such jurisdictions.

In the U.S., California enacted the California Consumer Privacy Act (CCPA) on June 28, 2018, which went into effect on January 1, 2020. The CCPA gives California residents expanded rights to access and delete their personal information, opt out of certain personal information sharing and receive detailed information about how their personal information is used. The CCPA provides for civil penalties for violations, as well as a private right of action for data breaches that is expected to increase data breach litigation. On November 3, 2020, California passed the California Privacy Rights Act (CPRA), which became effective on January 1, 2023 and amends and expands the CCPA, including the introduction of sensitive personal information as a new regulated dataset in California that is subject to new disclosure and purpose limitation requirements. Additionally, by July 2024, additional states had enacted numerous comprehensive state data privacy laws, requiring businesses to evaluate each law individually for specific compliance requirements and consumer rights, including the following:

● The Utah Consumer Privacy Act became effective on December 31, 2023;

● Montana's Consumer Data Privacy Act will come into effect on October 1, 2024;

● New Jersey’s Privacy Act will come into effect on January 15, 2025;

● Tennessee’s Information Protection Act will come into effect on July 1, 2025;

● Minnesota’s Consumer Privacy Act will come into effect on July 31, 2025;

26

Table of Contents

Furthermore, New York enacted the Stop Hacks and Improve Electronic Data Security Act (SHIELD Act), which became effective March 2020 and requires companies with data relating to New Yorkers to adopt comprehensive cybersecurity programs. Aspects of the CCPA, CPRA and other states’ privacy laws remain unclear and we may be required to modify our practices further in an effort to comply with them. These statutes may increase our compliance costs and potential liability.

Furthermore, on August 11, 2023, India’s Digital Personal Data Protection Bill (DPDP) received presidential assent after passing both houses of India’s legislature but there has been no official slated implementation date. DPDP applies to personal data processed within India and personal data outside the territory of India if such processing is in connection with any activity related to offering of goods or services to data subjects.We will continue to monitor developments related to new privacy laws which will require us to incur additional costs and expenses in an effort to monitor and comply with such laws.

In addition to government activity, privacy advocacy and other industry groups have established or may establish new self-regulatory standards that may place additional burdens on us. Our customers expect us to meet voluntary certification or other standards established by third parties, such as TRUSTe. If we are unable to maintain these certifications or meet these standards, it could adversely affect our ability to provide our solutions to certain customers and could harm our business.

The costs of compliance with and other burdens imposed by laws, regulations and standards may limit the use and adoption of our service and reduce overall demand for it, or lead to significant fines, penalties or liabilities for any noncompliance.

Furthermore, concerns regarding data privacy may cause our customers’ customers to resist providing the data necessary to allow our customers to use our service effectively. Even the perception that the privacy of personal information is not satisfactorily protected or does not meet regulatory requirements could inhibit sales of our products or services, and could limit adoption of our subscription solution. Moreover, as our customers face increased scrutiny for data privacy breaches, they may elect to transfer the risk to us through contractual provisions which may subject us to increasing levels of contractual liability for data privacy breaches.

Issues in the development and use of AI may result in reputational or competitive harm or liability.

We are integrating AI into several of our offerings, developed either by us or in collaboration with our strategic partner, OpenAI. We anticipate significant growth in this area. However, like many innovations, AI comes with risks and challenges that could impact its adoption and our business. Potential issues include flawed algorithms or training methods, inadequate or biased datasets, and harmful or illegal content generated by AI systems. Poor AI development or deployment practices could lead to incidents that hinder AI acceptance, cause harm, or result in our products not functioning as intended. Human oversight may be necessary for certain outputs. These challenges, along with other issues related to innovative technologies, could expose us to competitive harm, regulatory actions, legal liabilities (including under new AI regulations in the EU), and reputational damage. Some AI applications raise ethical concerns or have broad societal impacts. If our AI solutions lead to unintended consequences, misuse, or controversy due to their effects on human rights, privacy, employment, or other social, economic, or political issues, we may face reputational harm, negatively affecting our business and financial performance.

Anti-corruption, anti-bribery, and similar laws, and failure to comply with these laws, could subject us to criminal penalties or significant fines and harm our business and reputation.

We are subject to anti-corruption and anti-bribery and similar laws, such as the U.S. Foreign Corrupt Practices Act of 1977, as amended, the U.S. domestic bribery statute contained in 18 U.S.C. § 201, the U.S. Travel Act, the USA PATRIOT Act, the UK Bribery Act 2010, and other anti-corruption, anti-bribery, and anti-money laundering laws in countries in which we conduct activities. Anti-corruption and anti-bribery laws have been enforced aggressively in recent years and are interpreted broadly and prohibit companies and their employees and agents from promising, authorizing, making or offering improper payments, or other benefits to government officials and others in the private sector. As we increase our international sales and business, our risks under these laws may increase. Noncompliance with these laws could subject us to investigations, sanctions, settlements, prosecution, other enforcement actions, disgorgement of profits, significant fines,

27

Table of Contents

damages, other civil and criminal penalties or injunctions, adverse media coverage, and other consequences. Any investigations, actions, or sanctions could harm our business, operating results, and financial condition.

Industry-specific regulation is evolving and unfavorable industry-specific laws, regulations or interpretive positions could limit our ability to provide services and harm our business.

Our customers and potential customers conduct business in a variety of industries, including financial services, the public sector, healthcare and telecommunications. Regulators in certain industries have adopted and may in the future adopt regulations or interpretive positions regarding the use of cloud computing and other outsourced services. The costs of compliance with, and other burdens imposed by, industry-specific laws, regulations and interpretive positions may limit customers’ use and adoption of our services and reduce overall demand for our services. For example, some financial services regulators have imposed guidelines for use of cloud computing services that mandate specific controls or require financial services enterprises to obtain regulatory approval prior to outsourcing certain functions. If we are unable to comply with these guidelines or controls, or if our customers are unable to obtain regulatory approval to use our service where required, our business may be harmed. In addition, an inability to satisfy the standards of certain voluntary third-party certification bodies that our customers may expect, such as an attestation of compliance with the PCI Data Security Standards, may have an adverse impact on our business. If we are unable to achieve or maintain these industry-specific certifications or other requirements or standards relevant to our customers, it could adversely affect our ability to provide our services to certain customers and harm our business.

In some cases, industry-specific laws, regulations or interpretive positions may also apply directly to us as a service provider. Any failure or perceived failure by us to comply with such requirements could have an adverse impact on our business.

We face risks related to pandemic and public health emergencies which could have a material adverse effect on our business, financial condition and results of operations.

Pandemics, such as the COVID-19 pandemic, and other public health emergencies, and preventative measures taken to contain or mitigate such crises have caused, and may in the future cause, business slowdown or shutdown in affected areas and significant disruption in the financial markets, both globally and in the United States. These events have led to and could again lead to adverse impacts to our business, results of operations, financial conditions, and cash flows. We cannot predict whether, and to what degree, our sales, operations and financial results could in the future be affected by the pandemic and preventative measures.

We cannot reasonably predict the ultimate impact of any pandemic or public health emergency, including the extent of any adverse impact on our business, results of operations and financial condition, which will depend on, among other things, the duration and spread of the pandemic or public health emergency, the impact of governmental regulations that

28

Table of Contents

have been, and may continue to be, imposed in response, the effectiveness of actions taken to contain or mitigate the outbreak, the availability, safety and efficacy of vaccines, including against emerging variants of the infectious disease, and global economic conditions. Additionally, disruptions have in the past made it more challenging to compare our performance, including our revenue growth and overall profitability, across quarters and fiscal years, and could have this effect in the future. To the extent a pandemic or public health emergency adversely affects our business, results of operations, financial conditions, and cash flows, it may also heighten many of the other risks described in this “Risk Factors” section.

Changes to current accounting policies could have a significant effect on our reported financial results or the way in which we conduct our business.

Generally accepted accounting principles and the related accounting pronouncements, implementation guidelines and interpretations for some of our significant accounting policies are highly complex and require subjective judgments and assumptions. Some of our more significant accounting policies that could be affected by changes in the accounting rules and the related implementation guidelines and interpretations include:

● recognition of revenue;

● contingencies and litigation; and

● accounting for income taxes.

Changes in these or other rules, or scrutiny of our current accounting practices, or a determination that our judgments or assumptions in the application of these accounting principles were incorrect, could have a significant adverse effect on our reported operating results or the way in which we conduct our business.

Risks Related to Intellectual Property

We have been and may in the future be sued by third parties for various claims including alleged infringement of proprietary rights that can be time-consuming, incur substantial costs, and divert the attention of management, which could adversely affect our operations and cash flow.

We are involved in various legal matters arising from the normal course of business activities. These may include claims, suits, and other proceedings involving alleged infringement of third-party patents and other intellectual property rights, and commercial, labor and employment, and other matters.

The software and Internet industries are characterized by the existence of a large number of patents, trademarks and copyrights and by frequent litigation based on allegations of infringement or other violations of intellectual property rights. We have received and may receive in the future communications from third parties claiming that we or our customers have infringed the intellectual property rights of others. In addition, we have been, and may in the future be, sued by third parties for alleged infringement of their claimed proprietary rights. Our technologies and those of our customers may be subject to injunction if they are found to infringe the rights of a third party or we may be required to pay damages, or both. Many of our agreements require us to indemnify our customers for third-party intellectual property infringement claims, which would increase the cost to us of an adverse ruling on such a claim.

The outcome of any litigation, regardless of its merits, is inherently uncertain. Any claims and lawsuits, and the disposition of such claims and lawsuits, could be time-consuming and expensive to resolve, divert management attention from executing our business plan, lead to attempts on the part of other parties to pursue similar claims and, in the case of intellectual property claims, require us to change our technology, change our business practices or pay monetary damages, or enter into short- or long-term royalty or licensing agreements.

Any adverse determination related to intellectual property claims or other litigation could prevent us from offering our service to customers, could be material to our financial condition or cash flows, or both, or could otherwise adversely affect our operating results. In addition, depending on the nature and timing of any such dispute, a resolution of a legal matter could materially affect our future results of operation or cash flows or both.

29

Table of Contents

We rely on trademark, copyright, trade secret laws, contractual restrictions and patent rights to protect our intellectual property and proprietary rights and, if these rights are impaired, then our ability to generate revenue will be harmed.

If we fail to protect our intellectual property rights adequately, our competitors might gain access to our technology, and our business might be harmed. In addition, defending our intellectual property rights might entail significant expense. Any of our trademarks or other intellectual property rights may be challenged by others or invalidated through administrative process or litigation. While we have some U.S. patents and pending U.S. patent applications, we may be unable to obtain patent protection for the technology covered in our patent applications. In addition, our existing patents and any patents issued in the future may not provide us with competitive advantages, or may be successfully challenged by third parties. Furthermore, legal standards relating to the validity, enforceability and scope of protection of intellectual property rights are uncertain. Effective patent, trademark, copyright and trade secret protection may not be available to us in every country in which our service is available. The laws of some foreign countries may not be as protective of intellectual property rights as those in the U.S., and mechanisms for enforcement of intellectual property rights may be inadequate. Accordingly, despite our efforts, we may be unable to prevent third parties from infringing upon or misappropriating our intellectual property.

We might be required to spend significant resources to monitor and protect our intellectual property rights. We may initiate claims or litigation against third parties for infringement of our proprietary rights or to establish the validity of our proprietary rights. Any litigation, whether or not it is resolved in our favor, could result in significant expense to us and divert the efforts of our technical and management personnel.

Our failure or inability to develop non-infringing technology or license proprietary rights on a timely basis would harm our business.

We may be subject to legal proceedings and claims from time to time in the ordinary course of our business, including claims of alleged infringement of the patents and other intellectual property rights of third parties. Our products may infringe on issued patents that may relate to our products because patent applications in the United States are not publicly disclosed until the patent is issued, and hence applications may have been filed which relate to our software products. Intellectual property litigation is expensive, time consuming, and could divert management’s attention away from running our business. Litigation could also require us to develop non-infringing technology or enter into royalty or license agreements. These royalty or license agreements, if required, may not be available on acceptable terms, if at all, in the event of a successful claim of infringement.

General Risk Factors

Our stock price has demonstrated volatility and continued market conditions may cause declines or fluctuations.

The price at which our common stock trades has been and will likely continue to be highly volatile and show wide fluctuations due to factors such as the following:

● concerns related to liquidity of our stock;

● conditions and trends in the Internet and other technology industries; and

● general market and economic conditions.

Furthermore, the stock market has experienced significant price and volume fluctuations that have affected the market prices for the common stock of technology companies, regardless of the specific operating performance of the affected company. These broad market fluctuations may cause the market price of our common stock to decline.

30

Table of Contents

Our insiders who are significant stockholders have the ability to exercise significant control over matters requiring stockholder approval, including the election of our board of directors, and may have interests that conflict with those of other stockholders.

Our directors and executive officers, together with their affiliates and members of their immediate families, beneficially owned, in the aggregate, approximately 34% of our outstanding capital stock as of June 30, 2024, of which our Chief Executive Officer, Ashutosh Roy, beneficially owned approximately 30% as of such date. As a result of these concentrated holdings, Mr. Roy individually or together with this group has the ability to exercise significant control over most matters requiring our stockholders’ approval, including the election and removal of directors and the approval of significant corporate transactions, such as a merger or sale of our company or its assets.

ITEM 1B. UNRESOLVED STAFF COMMENTS

None.

ITEM 1C. CYBERSECURITY

RISK MANAGEMENT AND STRATEGY

Protecting our business information, intellectual property, customer and employee data, and technology systems is crucial for our business continuity, regulatory compliance, and stakeholder trust. We have implemented enterprise cybersecurity risk mitigation and governance processes, detailed in our Information Security Protection Program (“Security Plan”). Our strategy is guided by the Security Plan’s principles, which involve monitoring threats and vulnerabilities, assessing and monitoring related controls, and supporting the Chief Information Security Officer (CISO). Our cybersecurity policies, standards, processes, and practices are integrated into our overall risk management system to enhance our ability to protect our operations and information. This includes annual cybersecurity reporting to the board of directors by senior leadership.

We engage third-party providers to conduct evaluations of our security controls, through penetration testing, independent audits or consulting on best practices. These evaluations include testing both the design and operational effectiveness of our security controls.

Our Security Plan

Our Security Plan, developed in collaboration with third-party consultants, aligns with the National Institute of Standards and Technology (NIST) and ISO27001. This program encompasses security and privacy, risk-based controls, and integrates lessons learned from past cybersecurity incidents. Under the Security Plan, cyber risks, including threats and incidents, are continuously assessed, treated, and monitored. We incorporate insights from incident response and risk mitigation into our cyber risk management strategy to enhance overall cybersecurity. The Security Plan is led by specific management positions selected for their expertise, as detailed below.

Following best practices in cyber risk management, we have worked with recognized third-party experts to align the foundational processes, metrics, monitoring, and reporting of the Security Plan with common frameworks such as NIST.

Third-Party Cyber Risk Management

Our Third Party Cyber Risk Management Plan ensures that due diligence is carried out on third parties prior to and during engagement. Prior to engagement, third parties are assessed using a questionnaire that covers all areas of security including cyber risk and external documentation is requested such as SOC2 T2, penetration testing, and ISO27001 certification and scope. We include security and privacy clauses within our third party contracts where applicable, whichcover the implementation of security controls and self reporting. During engagement, third parties are regularly reviewed, at least annually, to ensure that cyber risks are evaluated and assessed on a continual basis.

Cyber Incident Response Plan

Our Incident Response Plan outlines the processes for detecting, identifying, prioritizing, and analyzing information security events. Depending on the incident’s scope, business impact, and potential material risk, our CISO, legal counsel,

31

Table of Contents

and business stakeholders are engaged. This cross-functional team assesses the appropriate response and mitigation pathway. Once security events are identified through our enterprise detection and monitoring ecosystem, the Incident Response Plan establishes a prioritization and decision workflow to determine the scope, business impact, and potential material risk, implemented in collaboration with the CISO, legal counsel, and business stakeholders.

Additionally, we have implemented an information security training program for employees, which includes security awareness training on cybersecurity risks, simulated phishing emails, and regular communication about cybersecurity risks.

While we occasionally experience cybersecurity threats and incidents, we are not aware of any material risks from these threats, including from past incidents, that have materially affected or are likely to materially affect our business strategy, financial condition, results of operations, or cash flows. However, there is no assurance that future cybersecurity threats will not have a material impact. For more information on our cybersecurity-related risks, please see “Item 1A. Risk Factors.”

GOVERNANCE

Protecting our customers’ data is a top priority for our board of directors and management team. Our risk management team, integrated into our CIS function, is led by our CISO. This team brings together extensive experience in information security, governance, and compliance, covering areas such as engineering, architecture, cybersecurity, and privacy. They are responsible for defining the program, overseeing cybersecurity governance, and gathering insights to assess, identify, and manage cybersecurity threats, their severity, and mitigations.

Our CISO, who reports to the Chief Financial Officer, leads the company’s technology and digital capabilities, including the overall cybersecurity strategy. Our CISO has over 25 years experience working in the commercial sector within the IT and security environments, across a variety of business verticals. Prior to this was in the Armed Forces working in an IT, telecommunications and security capacity. A member of (ISC)2 and CISSP certified, the CISO understands the security and protection requirements needed for areas such as data protection, PCI/DSS, HIPAA, FedRAMP.

The Audit Committee of our board of directors is charged with oversight of data privacy and cybersecurity risks. Our CISO provide annual updates on cybersecurity risks and related mitigating actions to the Audit Committee, meet with the full board of directors at least annually and inform the Audit Committee immediately if a cybersecurity incident is deemed material. They report to the Audit Committee and the board of directors on compliance and regulatory issues, provide updates concerning continuously-evolving threats and mitigating actions, and present a NIST Cybersecurity Framework Scorecard. Additionally, the CISO discusses and presents strategies to address technological changes, such as AI. In overseeing cybersecurity risks, the Audit Committee focuses on aggregated, thematic issues with a risk-based approach. Oversight of cybersecurity risk incorporates strategy metrics, third-party assessments, and internal audit and controls. Outside counsel advises the board of directors on best practices for cybersecurity oversight by the board of directors, and the evolution of that oversight over time. Management also reports on strategic key risk indicators, ongoing initiatives, and significant incidents and their effect.

ITEM 2. PROPERTIES

We lease all facilities used in our business as of June 30, 2024. Our corporate headquarters is located in Sunnyvale, California, and we also have corporate offices in Newbury, England, and Pune, India. We believe that our offices are adequate to meet our current and near future operating needs.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2024-06-30, filed 2024-09-12 · accession 0001558370-24-012767

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 18 headings are on that chain and 1 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.