fsly-20251231
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
WASHINGTON, D.C. 20549
____________________________
FORM 10-K
____________________________
☒ ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934
For the fiscal year ended December 31, 2025
or
☐ TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934
Commission File Number: 001-38897
____________________________
FASTLY, INC.
(Exact name of registrant as specified in its charter)
____________________________
475 Brannan Street, Suite 300
San Francisco, CA94107
(Address of principal executive offices) (Zip code)
(844) 432-7859
(Registrant's telephone number, including area code)
Not Applicable
(Former name, former address, or former fiscal year, if changed since last report)
____________________________
Securities registered pursuant to Section 12(b) of the Act:
Title of each class Trading Symbol(s) Name of each exchange on which registered
Class A Common Stock, $0.00002 par value FSLY The Nasdaq Stock Market LLC
Securities registered pursuant to Section 12(g) of the Act: None
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or 15(d) of the Act. Yes ☐ No ☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of "large accelerated filer," "accelerated filer," "smaller reporting company," and "emerging growth company" in Rule 12b-2 of the Exchange Act.
Large accelerated filer ☒ Accelerated filer ☐
Non-accelerated filer ☐ Smaller reporting company ☐
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
1
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to § 240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒
The aggregate market value of the voting and non-voting common equity held by non-affiliates of the registrant, based on the closing price of $7.06 for a share of the Registrant’s Class A Common Stock ("common stock") on June 30, 2025 (the last business day of the registrant's most recently completed second quarter), as reported by the New York Stock Exchange on such date, was approximately $1.0 billion.
As of February 13, 2026, 151.8 million shares of the registrant's common stock were outstanding.
Portions of the registrant’s Definitive Proxy Statement relating to the 2026 Annual Meeting of Stockholders are incorporated by reference into Part III of this Annual Report on Form 10-K where indicated. Such Definitive Proxy Statement will be filed with the Securities and Exchange Commission within 120 days after the end of the registrant’s fiscal year ended December 31, 2025.
2
TABLE OF CONTENTS
Page
Part I
Item 1. Business 7
Item 1A. Risk Factors 25
Item 1B. Unresolved Staff Comments 66
Item 1C. Cybersecurity 66
Item 2. Properties 67
Item 3. Legal Proceedings 67
Item 4. Mine Safety Disclosures 68
Part II
Item 6. Reserved 71
Item 7A. Quantitative and Qualitative Disclosures about Market Risk 88
Item 8. Financial Statements and Supplementary Data 89
Item 9A. Controls and Procedures 131
Item 9B. Other Information 133
Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 133
Part III
Item 10. Directors, Executive Officers, and Corporate Governance 134
Item 11. Executive Compensation 134
Item 14. Principal Accountant Fees and Services 134
Part IV
Item 15. Exhibits, Financial Statement Schedules 135
3
SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS
This Annual Report on Form 10-K contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, (the “Securities Act”), and Section 21E of the Securities Exchange Act of 1934, as amended, (the “Exchange Act”), about us and our industry that involve substantial risks and uncertainties. All statements other than statements of historical facts contained in this Annual Report on Form 10-K, including statements regarding our future results of operations and financial condition, business strategy, and plans and objectives of management for future operations, are forward-looking statements. In some cases, forward-looking statements may be identified by words such as “anticipate,” “believe,” “continue,” “could,” "design,” “estimate,“ “expect,” "intend,” “may,” “plan,” “potentially,” “predict,” “project,” "should,” “will,” "would,” “target,“ or the negative of these terms or other similar expressions.
Forward-looking statements are based on our management’s beliefs and assumptions and on information currently available. These forward-looking statements are subject to a number of known and unknown risks, uncertainties and assumptions, including risks described in the section titled “Risk Factors” and elsewhere in this Annual Report on Form 10-K, regarding, amongst other things:
•defects, interruptions, outages, delays in performance, or similar problems with our platform;
•our ability to attract new enterprise customers and to have existing enterprise customers continue and increase their use of our platform;
•the potential loss or significant reduction in usage by one or more of our major customers;
•component delays, shortages, and price increases;
•our history of operating losses;
•the potential that security measures, or those of third parties upon which we rely, are compromised, or the security, confidentiality, integrity, or availability of our information technology, software, services, networks, communications, or data is compromised, limited or fails;
•our ability to efficiently develop and sell new products and respond effectively to rapidly changing technology, evolving industry standards, changing regulations, and changing customer needs, requirements, or preferences;
•our ability to forecast our revenue accurately and manage our expenditures;
•our ability to effectively develop and expand our marketing and sales capabilities;
•our ability to compete effectively with existing competitors and new market entrants;
•our ability to maintain and enhance our brand;
•our ability to comply with evolving laws, regulations, industry standards, and other obligations;
•our ability to identify and integrate acquisitions, strategic investments, partnerships, or alliances;
•our ability to attract and retain qualified employees and key personnel;
•our reliance on the performance of highly skilled personnel, including our senior management and other key employees, and the loss or transition of one or more of such personnel, or of a significant number of our team members;
•our involvement in class-action lawsuits and other litigation matters;
•our estimates or judgments relating to our critical accounting estimates may prove to be incorrect or impaired;
•our ability to maintain effective internal control over financial reporting; and
4
•stock price volatility, and the potential decline in the value of our common stock.
We caution you that the foregoing list may not contain all of the forward-looking statements made in this Annual Report on Form 10-K.
Other sections of this Annual Report on Form 10-K may include additional factors that could harm our business and financial performance. Moreover, we operate in a very competitive and rapidly changing environment. New risk factors emerge from time to time, and it is not possible for our management to predict all risk factors nor can we assess the impact of all factors on our business or the extent to which any factor, or combination of factors, may cause actual results to differ from those contained in, or implied by, any forward-looking statements.
You should not rely upon forward-looking statements as predictions of future events. We cannot assure you that the events and circumstances reflected in the forward-looking statements will be achieved or occur. Although we believe that the expectations reflected in the forward-looking statements are reasonable, we cannot guarantee future results, levels of activity, performance or achievements. Except as required by law, we undertake no obligation to update publicly any forward-looking statements for any reason after the date of this Annual Report on Form 10-K or to conform these statements to actual results or to changes in our expectations. You should read this Annual Report on Form 10-K and the documents that we reference in this Annual Report on Form 10-K and have filed as exhibits to this Annual Report on Form 10-K with the understanding that our actual future results, levels of activity, performance, and achievements may be materially different from what we expect. We qualify all of our forward-looking statements by these cautionary statements.
In addition, statements that “we believe” and similar statements reflect our beliefs and opinions on the relevant subject. These statements are based upon information available to us as of the filing date of this Annual Report on Form 10-K, and while we believe such information forms a reasonable basis for such statements, such information may be limited or incomplete, and our statements should not be read to indicate that we have conducted an exhaustive inquiry into, or review of, all potentially available relevant information. These statements are inherently uncertain and investors are cautioned not to unduly rely upon these statements.
Investors and others should note that we may announce material business and financial information to our investors using our investor relations website (www.fastly.com/investors), our filings with the Securities and Exchange Commission, our corporate X (formerly known as Twitter) account (@Fastly), our blog (www.fastly.com/blog), our corporate LinkedIn account (www.linkedin.com/company/fastly), webcasts, press releases, and conference calls. We use these mediums, including our website, to communicate with investors and the general public about us, our products, and other issues. It is possible that the information that we make available on these mediums may be deemed to be material information. We therefore encourage investors and others interested in us to review the information that we make available through these channels. However, some information we disclose (whether in this report or other mediums) is informed by third-party frameworks and the expectations of various stakeholders and, therefore, is not necessarily material for purposes of our securities filings, even if we use words such as “material” or “materiality.” Particularly in the environmental, social, and governance matters context, information often uses definitions of materiality that differ from (and are more expansive than) the definition under U.S. federal securities laws.
RISK FACTOR SUMMARY
Our business is subject to significant risks and uncertainties that make an investment in us speculative and risky. Below we summarize what we believe are the principal risk factors, but these risks are not the only ones we face, and you should carefully review and consider the full discussion of our risk factors in the section titled “Risk Factors”, together with the other information in this Annual Report on Form 10-K. If any of the following risks actually occur (or if any of those listed elsewhere in this Annual Report on Form 10-K occurs), our business, reputation, financial condition, results of operations, revenue, and future prospects could be seriously harmed. Additional risks and uncertainties that we are unaware of, or that we currently believe are not material, may also become important factors that adversely affect our business.
•If our platform fails to perform properly due to defects, interruptions, outages, delays in performance, or similar problems, and if we fail to develop enhancements to resolve any defect, interruption, delay, or other problems, we could lose customers, become subject to service performance or warranty claims or incur significant costs.
5
•If we are unable to attract new customers, in particular, enterprise customers, and to have existing enterprise customers continue and increase their use of our platform, our business will likely be harmed.
•We receive a substantial portion of our revenues from a limited number of customers within a limited number of industries, and the loss of, or a significant reduction in usage by, one or more of our major customers would result in lower revenues and could harm our business.
•Component delays, shortages, or price increases could interrupt our ability to complete the construction of our servers or POPs and to meet the usage needs of our customers. Our operating results could be materially harmed if we are unable to adequately manage our infrastructure needs.
•Our history of operating losses makes it difficult to evaluate our current business and prospects and may increase the risks associated with your investment.
•If our IT Systems or data, or those of third parties upon which we rely, are compromised now, or in the future, or the security, confidentiality, integrity, or availability of our information technology, software, services, networks, communications or data is compromised, limited or fails, our business could experience materially adverse consequences, including but not limited to regulatory investigations or actions, litigation, fines and penalties, disruptions of our business operations, loss of revenue or profits, loss of customers or sales, reputational harm, and other adverse consequences.
•If we fail to efficiently develop and sell new products and respond effectively to rapidly changing technology, evolving industry standards, changing regulations, and changing customer needs, requirements, or preferences, our products may become less competitive.
•If we fail to forecast our revenue accurately, or if we fail to manage our expenditures, our operating results could be adversely affected.
•Failure to effectively develop and expand our marketing and sales capabilities could harm our ability to increase our customer base and achieve broader market acceptance of our platform.
•The markets in which we participate are competitive, and if we do not compete effectively, our business will be harmed.
•If we fail to maintain and enhance our brand, our ability to expand our customer base will be impaired and our business, results of operations and financial condition may suffer.
•We are subject, or may become subject, to stringent and evolving U.S. and foreign laws, governmental regulations and rules, contractual obligations, industry standards, policies and other obligations related to privacy, infrastructure, artificial intelligence, and data security.
•Acquisitions, strategic investments, partnerships, or alliances could be difficult to identify and integrate, divert the attention of management, disrupt our business, and dilute stockholder value.
•The failure to attract and retain qualified personnel could prevent us from executing our business strategy.
•We rely on the performance of highly skilled personnel, including our senior management and other key employees, and the loss or transition of one or more of such personnel, or of a significant number of our team members, could harm our business.
6
•We are, and may in the future be, involved in class-action lawsuits and other litigation matters that are expensive and time-consuming. If resolved adversely, lawsuits and other litigation matters could seriously harm our business.
•If our estimates or judgments relating to our critical accounting estimates prove to be incorrect, our results of operations could be adversely affected.
•If we are unable to maintain effective internal control over financial reporting in the future, investors may lose confidence in the accuracy and completeness of our financial reports, and the market price of our common stock may be seriously harmed.
•Our stock price is volatile, and the value of our common stock may decline.
PART I
Item 1. Business
Overview
Organizations around the world are more dependent on the quality of digital experiences they provide than ever before. As the internet approaches an inflection point where automated, artificial intelligence (“AI”)-driven traffic increases demands on infrastructure, Fastly is the essential platform to deliver resilient, highly performant, always-on software and services at global scale.
The edge cloud is a category of Infrastructure as a Service (“IaaS”) that enables software engineers to build, secure, and deliver digital experiences at the edge of the Internet. Our platform represents the convergence of the Content Delivery Network (“CDN”) with functionality that has traditionally been delivered by hardware-centric appliances such as Application Delivery Controllers (“ADC”), Web Application Firewalls (“WAF”), API Management, Bot Detection, Distributed Denial of Service (“DDoS”), Web Application and API Protection (“WAAP”), and infrastructure protection.
Processing at the edge is an ideal way to handle highly dynamic and time-sensitive data, especially when performance matters. Organizations of all sizes, including Fortune 500 companies that run 24/7 operations, leverage our edge cloud platform for a diverse range of critical functions that benefit from processing at the edge, including enhancing user experience, scaling agentic AI workloads, and powering core commerce capabilities to drive conversion and customer success. The edge cloud complements data center, central cloud, and hybrid solutions, and is critical for responsive, safe, and secure AI-centric experiences.
Fastly focuses holistically on the edge cloud from developer creation to end-user experience, with our global footprint and integrated security core to our platform. Our platform is poised to capitalize on the rise of agentic AI, where autonomous agent consumption is driving the bulk of internet traffic. Fastly is uniquely positioned – and has laid the groundwork – to lead the intelligence fabric that helps enterprises adapt to this shift. We are capturing this opportunity by supporting edge workloads and AI traffic management, allowing organizations to optimize AI-driven services alongside human interactions. We play a unique role in helping enterprises optimize and accelerate interactions with authorized AI agents and blocking abuse, powering their differentiation and AI-fueled innovation.
Organizations must keep up with a complex and ever-evolving landscape. We’ve built a powerful unified edge platform designed from the ground up to be programmable and support agile software development, and we continuously drive innovation to meet the ever changing needs of our customers. We believe that our platform gives our customers a significant competitive advantage – whether they were born into the AI-centric digital age or are just embarking on their transformation journey.
7
Products & Services
Fastly Platform
Fastly’s platform has evolved over the years to meet changing technology demands and the needs of a growing customer base. Built on the core principles of performance, resilience, and programmability, it was originally designed to accelerate applications and services at global scale. Over time, the platform expanded to also encompass edge computing, cloud-native architectures, unified application security, and emerging AI workloads.
Today, Fastly’s platform is designed to address the requirements of the always-on digital economy by providing essential infrastructure and application solutions for customers across a broad range of industries. We serve organizations across ecommerce, streaming media, gaming, digital publishing, and high tech to financial services and more. Our platform supports diverse use cases, from edge distribution and delivery, to cloud-native applications, serverless development, web application and API protection, and edge computing.
A Modern Platform
We have taken advantage of modern network design to build a platform optimized for performance, resilience and scale. Our platform is built to accelerate a wide range of content, including dynamic content, allowing customers to deliver faster, more personalized web and mobile experiences. It is also designed to scale rapidly and intelligently, while being resilient, to reliably support peak traffic events like live streaming events, flash sales, and major gaming releases.
Cloud-Native
As cloud-native solutions have become more mainstream for building and running applications, we are also well suited to support these environments. We offer an API-driven, developer-friendly platform that integrates smoothly with modern stacks, continuous integration/continuous deployment pipelines and cloud infrastructures. Our platform acts as an intelligent edge layer in front of customers’ single or multi-cloud environments. By accelerating, protecting, and optimizing API traffic, intelligently routing requests, and reducing load on origin servers, we improve application performance, security, and reliability. These benefits extend beyond enhancing centralized cloud applications to also supporting larger deployments in virtual private clouds and globally distributed, edge-native applications.
Edge Computing
As application architectures have evolved, with latency-sensitive functionality moving closer to end users, we have expanded our platform to support programmable edge computing. Built on WebAssembly (“WASM”) to support microsecond code execution times, our compute environment enables customers to run layers of intelligent logic, including AI, in front of their applications and services, all while maintaining performance. This allows customers to optimize their workflows for higher conversion rates, increased revenue generation, and faster developer innovation. With built-in isolation technology, the platform is also secure by design, enabling customers to run business-critical workloads while minimizing the potential for vulnerabilities or unauthorized access. Some common edge compute use cases include fast, scalable personalization; security and authentication enforcement; and on-the-fly image or video optimization. Being part of core application workflows, these compute use cases can drive even deeper usage of Fastly’s platform.
Unified Application Security
In response to growing customer demand for consolidated application security, we offer a suite of security solutions to minimize the impact of attacks on and abuse against applications, APIs, and software services. By design, our powerful platform is ideally suited to adapt to and sustain resilience against massive traffic swells, whether network-layer DDoS attacks or global-scale real-time media events. Our AI-driven Adaptive Threat Engine enables real-time detection and mitigation of evolving attacks through traffic pattern analysis across our network, which we also apply to our customers’ individual services through our DDoS Protection product. We layer software products on top of our resilient platform, empowering customers with tailorable protection that lets them block, deceive, redirect, and otherwise manage attack, abuse, and other unwanted traffic. Our integrated web application firewall and bot management capabilities leverage our platform’s evidence-based, context-aware detection capabilities so customers can proactively address unwanted activity. Our platform provides real-time visibility into security events, attack traffic, and rule performance, enabling faster identification and remediation of potential risks to minimize the business impact of security incidents. Our built-in deception and mitigation techniques allow customers to detect and block attack attempts while obfuscating successful defense from attackers, slowing down attackers’ ability to evolve their operations.
8
AI-Ready
As AI becomes an essential part of modern applications, we are pursuing a dual opportunity: enabling AI workloads for our customers and leveraging AI to enhance our platform’s usability and capabilities. Our platform offers semantic caching and edge data stores to speed up AI workloads, while support for real-time messaging and pre-processing of visual data for AI models reduces latency and improves efficiency for AI applications. Fastly’s platform also includes capabilities for managing agentic AI and AI bot traffic, and controlling services through natural language interfaces.
Platform Differentiators
The evolution of Fastly’s platform is powered by a set of core differentiators. These differentiators have allowed us to rapidly adapt to changing market needs.
Robust architecture: Our network is comprised of robust, high-density POPs (points of presence) designed to minimize footprint and colocation costs while delivering content closer to end users. Strategically located near major cloud providers and peered with Internet exchanges worldwide, our POPs are designed to achieve optimal performance with fewer nodes than traditional architectures.
Software-controlled:We built a smarter network using fast switches and server-layer routing intelligence, allowing us to deliver real-time responses by optimally routing customer traffic. Our network also supports origin health checks for CDN and Compute services, which are designed to monitor and direct traffic away from unhealthy backends to maintain service reliability.
Resilient by design: Our network is designed to withstand common performance degradation and connectivity issues with internet transit providers. Fast Path Failover provides automatic detection and rerouting of underperforming edge connections at the transport layer. Precision Path monitors origin connections and reroutes traffic in real time to the best available path. Autopilot, our automated egress traffic engineering solution, allows us to reliably manage high-traffic events without manual intervention. When it comes to protecting against DDoS attacks, our Adaptive Threat Engine is designed to enhance platform resilience by automatically detecting and mitigating attacks in real time, using advanced behavior modeling and traffic analysis to stop threats even when attackers rotate IPs.
Fully programmable: We have built a fully programmable platform that gives customers comprehensive control over how their content is cached and how it responds to end-user requests. Using our flexible APIs, customers can make configuration changes themselves, rather than relying on professional services. This results in faster end-user experiences and cost savings for our customers, while unlocking developer innovation.
Granular visibility: Customers need continuous insight into the status of their apps and services. Across our product lines, we provide real-time logging, rich metrics, alerts and dashboards enabling faster, data-driven decision making. Software engineers can monitor performance, detect anomalies, and troubleshoot issues faster using these tools, maximizing availability and performance for their apps and services. Fastly’s granular visibility enables customers to iterate quickly on new releases, bringing innovations to market faster so they can stay ahead of competitors.
DevOps-friendly: We make it easy for customers to integrate Fastly into their DevOps workflows through rich APIs and support for platforms like Terraform, Amazon S3, and Google Cloud Storage. Combined with our configurability and visibility, these integrations enable developers to include Fastly in their continuous integration and deployment processes, accelerating and optimizing software and feature releases to enable their business goals.
Powerful Compute environment: Our platform provides a serverless compute environment that enables developers to run business-critical workloads at the edge with high performance, resilience, and minimal maintenance. Using WASM, code compiles to native machine code and executes in secure, isolated sandboxes across all our edge service delivery points. Our compute environment enables enterprises to deliver low-latency, reliable, and secure workloads and applications that serve business-critical use cases spanning new revenue opportunities, differentiation, and AI innovation.
9
Network Services
Fastly is an extension of our customers’ infrastructure. Our Network Services are designed to speed up and optimize the delivery of web and application traffic while ensuring developers and engineers do not lose visibility or control. Whether customers are looking to deliver engaging web and streaming experiences to their users, move apps to the cloud, or scale their DevOps practices, our Network Services provide the speed, security, and flexibility customers need.
Content Delivery Network
•Dynamic Site Acceleration. Speeds up requests and responses between cache nodes in our Points of Presence (“POPs”) and customers’ origin servers to serve their dynamic web and mobile content faster.
•Origin Shield. Allows us to designate a specific POP to serve as a shield for a customer’s origin servers. When web content is refreshed and multiple end users request the new content simultaneously, a deluge of requests can hit a customer’s origin server. This can result in poor web or application performance. With Origin Shield, we collapse all these content requests into a single request and hold it in queue at the Origin Shield POP. That allows us to retrieve the new content from the customer’s origin server only once, and then serve it to all end users who requested it. This approach reduces costs for our customers, while improving performance for their end users.
•Instant Purge. Allows customers to clear the cached copy of their content globally in milliseconds, not seconds. We allow customers to send a command to our platform that invalidates an old version of their content throughout our global edge infrastructure. This causes a new version of content to be retrieved from the application server the next time it is requested. This feature enables our customers to serve highly dynamic content at the edge faster, facilitating delightful application experiences. Rapidly changing content like shopping cart items, flight search results, sports scores, or current weather conditions in any given location can all be served faster from the network edge.
•Surrogate Keys. Allows customers to fine-tune purging by tagging related objects across their site with a key name and description, then purging by that key. Customers can purge their entire site of a given object or set of objects all at once, without impacting performance. For example, customers could purge any images and content related to discontinued sale items, discounted products, or outdated news across their site all at once.
•Programmatic Control. Provides direct programmatic control of edge delivery services to our customers, allowing them to precisely control what content is cached, for how long and when it should be refreshed. Combined with comprehensive APIs, this allows our customers to build, test and deploy custom logic, using their own development, test and deployment environment, for even the most complex digital experiences.
•Content Compression. Compresses content with technologies like Gzip and Brotli, providing direct performance improvements and a more responsive web experience for end users.
•Reliability Features. Support the availability of customer content with features including origin health checks, a ‘grace mode’ feature that will continue serving content even when customer origin(s) fail, Multipath TCP, and real time error dashboards and API feeds that are backed by a 100% uptime Service Level Agreement (“SLA”).
•Fanout. Enables customers to push data in real time to many users, such as synchronous communication of messages in a chatroom, server updates to Internet of Things (“IoT”) devices and other types of data between devices. Real-time messaging is used in a wide range of data streaming applications, including IoT, live commenting, end-user notifications, chat and more.
•Domainr. Provides customers with a real-time and programmatic means for checking domain availability. A programmatic solution for verifying trust for domains is especially useful for platform customers. Using Domainr's APIs, customers can embed these functions directly into their workflows.
10
•Modern Protocols and Performance. Helps our customers, and the Internet in general, receive the best possible performance regardless of user device, connectivity or location though supporting the development of next generation web technologies and protocols such as HTTP/3, QUIC, client hints and HTTP prioritization.
•Staging Environment. Allows customers to test changes to their CDN or Compute service configurations in a staging environment before deploying them to the production network. This helps identify and resolve potential issues earlier in the development process. Staging features are automatically enabled for use in the Fastly API, command line interface, and via Terraform.
Video / Streaming
•Live Streaming. Delivers millions of concurrent high-quality live streams. It can deliver online content using major HTTP streaming formats while providing real-time feedback to optimize viewer experiences. In addition, we partner with multiple video platform vendors to improve the flexibility and scale of live-streaming workflows and reduce the total cost of ownership for customers.
•Video on Demand. Reduces the load on origin servers and accelerates time-to-first-frame by caching and rapidly delivering Video on Demand content. Our on-the-fly-packaging feature optimizes streaming media on demand and facilitates immediate playback, thus enhancing viewer experiences across regions, devices, and platforms.
•Media Shield. Large streaming customers typically use multiple CDNs for media delivery for redundancy and protection. Our Media Shield product supports these efforts and can reduce the total cost of ownership while also regaining lost visibility and improving performance. By collapsing multiple origin requests for identical content across several CDNs, content can be streamed faster, more efficiently, and with a significantly smaller infrastructure burden.
•Cache Reservation. Allows large streaming customers to reserve cache space at Fastly’s edge for high traffic events. By prioritizing a customer’s content cache storage, Cache Reservation allows that content to stay in cache for longer, minimizing content eviction in multi-tenant environments. It also helps reduce cloud egress costs by optimizing origin offload from any CDN, including Fastly.
•Live Event Monitoring. With real-time monitoring, streaming delivery, request collapsing, capacity planning, and flexible deployment, Fastly Live Event Monitoring gives customers insights into their live streaming performance and the ability to troubleshoot immediately, all while reducing costs.
Object Storage
•Object Storage. Fastly Object Storage is an Amazon S3-compatible large object storage solution that works seamlessly with both our CDN and Compute services. Customers can store large file sizes, improving latency, increasing cache hit ratios, and reducing egress charges. Objects stored in Object Storage are accessible via an S3-compatible interface. Our on-demand migration feature enables customers to only migrate their required working set of data, reducing egress charges from their source provider.
Load Balancing
•Load Balancer. Manages HTTP/HTTPS requests to a customer’s origin using granular content-aware routing decisions. We allow customers to manage traffic across multiple IaaS providers, data centers, and hybrid clouds. We also provide improved performance and cost savings over ADCs, especially during a spike or surge in traffic.
Image Optimization
•Image Optimizer. We offer a real-time image manipulation and delivery service and store transformations at the edge. When an image is requested, we resize it, adjust quality, crop/trim, change orientations, convert
11
formats, and more, all on demand. Transforming images at the edge eliminates latency and reduces traffic to origin servers, allowing customers to save on infrastructure and egress costs.
Origin Connect
•Origin Connect. Ideal for companies moving more than one gigabyte of data per second, such as media, video, and streaming companies, Origin Connect provides a direct private network connection between an organization’s origin server and an Origin Shield POP. This is an effective way to lower transit costs, reduce engineering complexity, and improve reliability for high-volume streaming content.
Security
Customers across multiple industries rely on Fastly to help rapidly secure their business-critical websites, apps, and APIs. Our modern approach to application security provides the accuracy, flexibility, and ease-of-use that our customers value and expect. Fastly provides a suite of security solutions focused on protecting websites, apps, and APIs from unwanted activity, including DDoS attacks, application layer attacks, and abusive behavior from automated software such as AI crawlers. This solution suite is designed to be real-time, scalable, and customizable, offering customers the ability to tailor and adapt their security to their unique and evolving business needs.
Next-Gen WAF. Our next-generation Web Application Firewall protects applications from malicious attacks that seek to compromise apps and APIs. Our context-aware solution requires no tuning, reducing our customers’ time to deploy software changes, and is more accurate than the traditional rule or signature-based approaches. Our WAF can be installed in any infrastructure: cloud, virtual private cloud, container, on-premise data center or hybrid environments or at the edge. Key features include:
•Bot Management. Bad bots can perform content scraping, tie up system resources, perform account brute forcing and other harmful actions. Our solution (available as part of our Next-Gen WAF) monitors web application and API traffic for automated bot activity, allowing customers to automatically block malicious bot-generated web requests, while providing access for wanted or verified bots. Additional advanced bot management features are available in our separate Bot Management product, described below.
•API Protection. Attackers often target sensitive APIs with malicious activity like attempting to validate stolen credit cards, perform ecommerce gift card fraud or obtain patient healthcare records. We help customers stop API abuse by enabling them to monitor for unexpected values and parameters submitted to API endpoints, and block unauthorized requests.
•Account Takeover Protection. Account takeover occurs when attackers use authentication credentials to take over legitimate user accounts. Attackers test stolen credentials in an automated manner called “credential stuffing.” Our Account Takeover Protection empowers customers to automatically block and alert on credential stuffing attacks.
•Deception. Our advanced deception feature blocks malicious login attempts while also misleading attackers with fake “invalid username/password” responses. Attackers are left frustrated, thinking their credentials are bad and retrying them without realizing they have been detected. This feature is currently available for our Next-Gen WAF, and our goal is to embed deception into both new and existing security products to create end-to-end attacker tracing across customer’s production environments.
•Advanced Rate Limiting. Advanced Rate Limiting enables customers to stop malicious and anomalous high volume web requests and reduce resource consumption while allowing legitimate traffic through to application and API endpoints—doing so means companies can provide a superior customer experience that scales to meet increasing demand.
Bot Management. Fastly Bot Management is an add-on service that provides customers with visibility into bot traffic, allowing them to differentiate between good and bad bots. They can then enforce rulesets and policies in the Fastly Next-Gen WAF control panel. Key features include AI Bot Management for controlling AI bot access, advanced client-side detection of sophisticated automated attacks, and support for dynamic challenges with Private Access Tokens (“PATs”), which allows for verification of legitimate users without relying on CAPTCHAs. Rather than
12
blocking all bots, our approach supports customers’ business goals by giving them granular control to block malicious bots while allowing legitimate automated traffic, such as search engine crawlers or monitoring tools, to access their services.
API Security. Fastly has a set of capabilities designed to help customers better protect their APIs. API Discovery automatically and continuously finds, collects and organizes customer API traffic across their Fastly services into one manageable interface. API Inventory allows customers to save and customize an accurate, detailed, and continuously-updated API inventory from the latest traffic surfaced in API Discovery. Being able to review and set aside APIs that are behaving as expected allows customers to more easily identify APIs which need security attention.
Client-Side Protection. Fastly Client-Side Protection helps our customers meet PCI-DSS compliance requirements. It provides real-time monitoring and protection against unauthorized modifications to client-side scripts and response headers, helping businesses secure sensitive customer data and maintain compliance.
Fastly DDoS Protection. Fastly’s DDoS Protection provides enhanced application-layer defense against DDoS attacks without requiring any upfront tuning. When unexpected volumetric events occur, our proprietary Adaptive Threat Engine leverages advanced, automated pattern analysis—including machine-learning–style behavior modeling—to determine legitimacy. If an attack is detected, it analyzes a comprehensive set of traffic characteristics to identify the attacker and quickly mitigate their attacks, even if IPs are rotated. Fastly DDoS Protection also features a zero-attack-fee billing model, ensuring customers are never charged for attack traffic.
TLS Encryption
•Transport Layer Security (“TLS”).As part of our standard product, our platform terminates HTTPS connections at our network edge, offloading encrypted traffic from our customers’ web servers for better performance. Predefined roles allow customers to more precisely manage TLS access without having to grant unnecessarily broad permissions. We also provide a number of different certificate procurement and hosting options.
•Platform TLS. Our Platform TLS offering is designed to allow customers with multiple web properties to manage TLS certificates at scale, while enabling a fast, secure experience for their end users. It supports delivery and management of hundreds of thousands of certificates, supported by our worldwide TLS termination and acceleration solution.
•Certainly. Certainly is our own publicly-trusted TLS Certification Authority. Fastly customers can use a certificate issued by Certainly to secure any website or API endpoint served by our CDN.
Privacy. Fastly offers several privacy enablement capabilities. Our OHTTP Relay solution provides fast, reliable separation and isolation of end user data, while passing along non-identifying requests to the business server. Fastly’s OHTTP Relay is designed to enhance online privacy for users of several of the largest internet vendors. Fastly has worked with others to develop and standardize the technology behind PATs. As an alternative to CAPTCHAs, PATs provide better user privacy by helping ensure there is no leakage of non-essential data.
Compliance. Our caching and delivery services are designed and measured against key audit and regulatory standards to help customers manage their compliance, including the Health Insurance Portability and Accountability Act (“HIPAA”), the European Union's General Data Protection Regulation (“EU GDPR”), the United Kingdom’s GDPR (“U.K. GDPR”), and industry standards like the PCI Data Security Standard and SSAE-18. Fastly is also certified to the ISO/IEC 27001:2022 standard for its Information Security Management System, and our Next-Gen WAF is FIPS 140-3 compliant for organizations that process sensitive government information or operate in regulated sectors.
Compute
Fastly Compute enables developers to build edge-native applications, APIs, authentication layers, and mission-critical edge functions on our programmable edge platform. These workloads run without requiring developers to manage the underlying infrastructure. Like all our offerings, Compute is built to be secure, performant and scalable.
13
Compute supports a multitude of use cases, including:
•Enhancing Search Engine Optimization ranking by managing redirects and content rewrites at the edge to improve site performance and gain real-time visibility;
•Building high-volume data pipelines for telemetry, user monitoring, IoT sensor arrays, and more;
•Lowering infrastructure costs while delivering faster personalized experiences by handling user authentication and token management for application APIs at the edge; and
•Enabling low latency ad personalization by allowing our customers to serve ads quickly from the edge based on user data.
Key features of Compute include:
•Serverless execution environment. Compute offers a fast, secure serverless code execution engine. It allows customers to deploy code across Fastly’s global edge cloud platform, and execute the code close to the user for low latency. Compute also leverages the power of Fastly’s global platform via a set of powerful developer APIs for fine grained programmatic control (e.g. Cache API’s).
•Language support.Compute works with any WASM-supported languages, including JavaScript, C++, Rust, Go, and a growing list of additional languages. Customers also have the ability to create their own language Software Development Kits. Support for languages that developers already know and want to code in is key for adoption and we will continue to add more over time.
•Storage and Data. Compute has a number of features that makes it easier and faster to access data at the edge instead of having to go back to the central cloud. This helps developers innovate faster and unlocks more latency-sensitive use cases at the edge.
◦Key Value (“KV”) Store. KV Store offers global, durable storage for compute functions at the edge. With fast reads and writes from both the edge or via API, customers can store, control, or cache their data to reduce origin dependency and unlock new use cases.
◦Config Store. Developers want to iterate fast when developing applications. Config Store supports this by allowing them to store multiple common code configurations at the edge, which they can then deploy instantly, instead of having to push new code for every single configuration change.
◦Secret Store. Secret Store is a secure and performant storage system for Compute customers' most sensitive data like API keys, passwords, certificates, and other credentials. It leverages the Hashicorp vault to centrally store, access, and manage secrets across Fastly's cloud infrastructure.
◦Object Storage. Fastly Object Storage is an Amazon S3-compatible large object storage solution that works seamlessly with Fastly’s Compute and CDN services.
•Developer Experience. Our products are designed to empower developers, from their first interaction with Fastly to serving billions of requests daily. Our award-winning Developer Experience team guides developers with training materials, events and tooling aimed at building a deeper understanding of our products. We maintain code samples, published to Fastly’s Developer Hub, and build testing tools like Fastly Fiddle, in order to accelerate customer testing and adoption. Many customers integrate our products directly into their DevOps tools and internal developer platforms. Beyond traditional debugging, we also facilitate advanced diagnostics on our platform through rapid global deploy times, live logs and additional observability tools.
•Fast Forward and Open Source Ecosystem. Our Fast Forward program is designed to empower and support developers, open source projects, and nonprofits that share our vision of an internet that is free, open, and safe for all. Any eligible open source project or nonprofit can apply to receive free Fastly products, including our CDN, security, compute, and observability products. From empowering millions of developers with open source tools, to providing consumers with accessible information, education, and relief services, Fast Forward members leverage Fastly to deliver impact at global scale.
14
◦Language ecosystems. Rust Foundation, Python Software Foundation, Ruby Central, Perl (MetaCPAN), OpenJS Foundation.
◦Open Source governance organizations. Linux Foundation, Apache Foundation, Drupal Association.
◦Open Source projects. Linux kernel, cURL project, Kubernetes, OpenStreetMap.
◦Nonprofit organizations. Khan Academy, Scratch, Watchduty, ArXiv, EFF, Kiva, MercyCorps, Reporters sans Frontières.
Observability
For customers, the ability to continuously monitor the status of their websites, products, and services is essential. Across all our Network Services, Compute and Security product lines, we provide customers with real-time insights for better decision making. Software engineers can quickly identify potential issues, investigate anomalies, improve performance, and uptime and iterate faster on new releases.
•Real-time Logging. To help tune the performance of Fastly services, we support real-time log streaming of customer data that passes through Fastly. We support a number of protocols that allow our customers to stream logs to a variety of locations, including third-party services, for storage and analysis.
•Logging Insights. Fastly Logging Insights is a professional services package that provides actionable intelligence that can be used to diagnose and troubleshoot issues for optimal performance and user experience. Our expert consultants implement a guided customization of preconfigured dashboards tailored to a customer’s specific goals.
•Regional Log Aggregation. Beta release that allows customers to control where their Fastly log data is processed and delivered, helping support stringent data residency requirements while also enhancing log data security. We currently support log processing within the EU and the US.
•Metrics. We offer customers a variety of ways to report on the performance and activity of their services. Our metrics, APIs and dashboards provide real-time, per-second visibility and historical reporting.
•Edge Observer. Provides per-second visibility and historical reporting on the performance and activity of multiple Fastly services in a single pane of glass. Metrics and logs along with every part of the request path are available for consumption in real-time without adding latency.
•Alerts. Provides in-platform alerts for Fastly services, origins, domains, and compute apps. Alerts are driven by real-time metrics and are fully customizable. They can be shared through Slack, email, or integrations with existing escalation workflow tools, for faster detection and response times.
•Sustainability dashboard. Offers self-service access, an API, and downloadable data to track electricity consumption and electricity-related greenhouse gas emissions resulting from customer usage of the Fastly platform, based on our published carbon calculation methodology.
We also offer a number of add-on Observability services which support our Network Services and Compute product lines:
•Log Explorer & Insights. This feature allows customers to store, inspect and monitor their log data directly on our platform, eliminating the need for third-party tools to view and analyze logs. Using the Insights dashboard, customers get a variety of views of their logging data so they can visualize and identify trends. Log Explorer facilitates troubleshooting by allowing customers to view, filter, and analyze logs using the Fastly control panel and API.
•Origin Inspector. Customers can simplify their data pipeline and easily monitor every origin response, byte, status code, and more without needing a third party data collector. They can report on egress data within the
15
Fastly web interface with interactive dashboards. Customers can also verify the success of their Fastly services, especially with shielding or multi-CDN environments.
•Domain Inspector. Customers can easily monitor traffic for a single fully qualified domain name or multiple domains within a Fastly service. They can account for every domain request, byte, and status code or quickly determine edge or origin issues with our combined edge and aggregated origin metrics, all without needing to send log data to a third-party data collector.
The following add-on Observability tools are designed to support our Compute product line, empowering developers to monitor and program in real-time:
•Log Tailing. We give customers visibility into log messages from their applications so they can quickly identify bugs, all within their terminal of choice with Fastly Command Line Interface. This helps avoid difficult third-party log management and debugging challenges.
•Tracing. For customers building apps with Compute, we tag individual end-user requests with unique identifiers and maintain request tracing parameters by tracking when users enter and exit our serverless platform. This feature allows developers to more easily track the performance of application functions post-deployment.
AI Capabilities
AI is becoming an increasingly important part of modern application development. We have extended our powerful, programmable platform to include new products and feature enhancements that help customers accelerate, protect, and optimize their AI-driven workloads.
AI Bot Management. Fastly AI Bot Management is a feature within our Bot Management offering. It provides visibility and control over automated traffic by using behavioral analysis and threat intelligence to identify and classify AI bots. Customers can gain insight into how AI bots access and scrape their content, enabling them to evaluate whether this activity aligns with their business goals—such as generative engine optimization—or constitutes unauthorized use. They can then take targeted actions, including blocking, rate-limiting, or allowing this AI bot traffic. AI Bot Management is also integrated with Tollbit and other monetization vendors, to monetize AI bot scraping of customer content. The Tollbit integration allows customers to redirect AI bots to a paywall for token verification. AI bots with valid tokens are granted access to content, while AI bots without valid tokens are required to pay for access.
Edge Data Storage. Fastly Key-Value Store and Object Storage are edge data storage solutions which can help optimize AI workloads. Key-Value Store supports semantic caching of large language model (“LLM”) responses, allowing applications to instantly serve relevant results while reducing calls to expensive, high-latency model APIs. Object Storage supports AI workloads by providing a cost-effective way to store and serve large datasets for LLM training, enabling organizations to scale AI model training while reducing storage costs.
Fanout. Fastly Fanout simplifies the delivery of real-time workloads by managing complex, persistent client-server communications at the edge. It supports a broad range of use cases by enabling AI agents to autonomously connect fragmented steps into automated workflows. Its flexible architecture provides a framework for enabling pub/sub, IoT and other real-time communication options for agentic handoffs.
Image Optimizer. FastlyImage Optimizer integrates into AI workflows as an intelligent preprocessing layer that refines images before they are processed by AI models. Using our smart crop feature, it preserves and optimizes the most relevant regions of an image, reducing unnecessary data sent into the AI pipeline. This helps improve model performance, lower compute and egress costs, and reduce workload latency.
Fastly also provides AI solutions designed to simplify the management of our services.
Model Content Protocol (“MCP”) Server. Fastly MCP Server is an open-source tool that enables AI assistants—including Claude, Claude Code, Gemini, OpenAI, Cursor, and others—to interact with and manage Fastly services using natural language. Customers can perform tasks like purging caches, viewing traffic patterns, or updating configurations, through simple conversational commands. MCP Server also streamlines security workflows, making it
16
easier to automate and manage CDN services, Compute applications, and security settings. Beyond basic operations, it supports advanced advisory interactions, such as analyzing service configurations, suggesting optimizations, or reviewing WAF rules.
AI Assistant. FastlyAI Assistant is an in-console AI helper released in beta that provides users with contextual, real-time answers about Fastly’s products and services. By surfacing relevant information with citation links directly within the control panel, AI Assistant improves the user experience and helps customers explore and configure Fastly more efficiently. This helps to simplify onboarding and configuration for both new and existing users.
Services
Professional Services. Fastly offers the following professional services:
•Network Services. Distributed systems can be complex, but regardless of a customer’s skill level, Fastly technical experts are available to guide and optimize the customer's cloud strategy. We offer various levels of engagements, from a light helping hand, to acting as an extension of developer teams, with global support and flexible professional services hours.
•Response Security. This service offers rapid, expert intervention when customers need it the most. With an industry-leading SLA, our Customer Security Operations Center (CSOC) helps mitigate application and API attacks 24/7/365, to minimize impact and facilitate quick recovery.
•Managed Security Professional. This service offers proactive protection for customers' most critical apps and APIs. It includes expert 24/7/365 monitoring and mitigation from Fastly’s CSOC across all Fastly security products, quarterly reporting, and an industry-leading SLA.
•Managed Security Enterprise. This service offers comprehensive, white-glove defense for customers’ applications and APIs. It includes expert 24/7/365 proactive monitoring and mitigation by Fastly’s CSOC across all Fastly security products, multiple industry-leading SLAs, proactive threat hunting, monthly reporting, and strategic analysis.
Managed CDN.Fastly’s Managed CDN provides maximum control and flexibility. We deploy our edge cloud network on dedicated POPs within a customer’s private network at locations of their choosing. Our service can be used exclusively, or as part of a hybrid, multi-CDN strategy.
Support Plans. Fastly offers three levels of support plans and available technical support add-ons with dedicated technical specialists and account managers that provide extended security expertise.
•Standard. The Standard support plan gives every Fastly customer immediate access to our Community Forum and extensive documentation. Customer support is available via email during business hours.
•Gold. The Gold support plan offers enhanced product support, priority routing for support cases, and expedited 24/7 incident response times.
•Enterprise. Enterprise level support equips customers with 24/7 online support for incidents and general inquiries, 15-minute escalation response times, phone support, access to a private Slack channel, and a team of technical experts to help optimize a customer’s Fastly service, including compliance support.
Our Growth Strategy
Our growth strategy focuses on making our edge cloud platform accessible to a broader base of customers through enhancing our product experience, investments in technology and infrastructure, attracting new business, growing partnerships, and vertical expansion. Key elements of our growth strategy include the following:
•Product strategy. Built upon a strategy of durable innovation, our programmable edge cloud platform creates a consistent and predictable pipeline of innovation. We plan to expand existing product lines like Network Services and Security, and expect to further incubate newer products for future growth.
17
With the goal of making it easier for customers to do business with us, we continue to build out a single, unified platform where they can access and manage all their Fastly services in one place. Our security products - DDoS Protection, Next-Gen WAF, Bot Management, Client-side Protection, and API Security - are available on one platform, and easily accessible through the Fastly Control Panel. We have also taken steps to further simplify customer onboarding and service usage, through easy access to self-training information from within the Fastly app, and more code samples and support.
•Expansion into additional vertical markets. Our platform offers a broad range of capabilities. Our differentiated high performance and low-latency delivery network and edge compute platform, as well as enhanced security capabilities, allows us to serve the needs of our existing customers and continue to add customers from a diverse set of industries.
•Expand existing customer relationships. Over time, our customers have expanded their use of our platform. In more technically savvy organizations, software engineering leaders have championed our solution, paving the way for us to engage with business decision makers. For more traditional organizations, we are often brought in to initially help facilitate a move to the cloud and from there we extend our product to support many other use cases. We plan to continually increase wallet-share over time for existing customers as we build out new products and features, and as customers continue to fully recognize the value of our platform.
•Grow our technical partner ecosystem. We operate between and complement the “big 3” origin cloud platforms, Amazon Web Services (“AWS”), Microsoft (Azure), and Google Cloud Platform, and a growing community of companies that provide big data, AI, and security solutions. In this sense, we act as the unifying layer for a growing number of cloud services. As customers consume more cloud and software as a service (“SaaS”) offerings, we can create additional value and grow with these partners.
•Attract new customers. With new product innovations, additional vertical focus areas, growing partners, and an optimized go-to-market engine, we plan to attract new business and continue to grow. In addition, we can help new customers accelerate, protect, and optimize their AI-driven workloads, AI-generated software, and traditional applications that increasingly experience agentic interactions.
•International expansion. As our customer base grows, we plan to scale our network to bring edge computing closer to where our customers are. We believe significant opportunities exist for international growth.
Partner Ecosystem
Partners are one of the ways Fastly creates new value for customers, reaches new markets, and builds things we couldn’t do alone. Our strategy is to create economic, reputational, and technical value with our partners and to be the engine that powers their revenue and growth. To achieve this, we partner with a number of global channel partners who offer our performant and secure solutions on top of their own value-added services. We work with top cloud service providers to combine our complementary products and services and to offer streamlined procurement through cloud marketplaces. We also partner with a number of third-party technical partners to extend our capabilities across new markets and use-cases. Ultimately, partners help our customers by:
•Providing a complete suite of value-added services and solutions
•Offering flexible and efficient engagement and purchasing models
•Acting as a single point of contact; and
•Extending geographic coverage and support.
Channel Partners. Fastly’s partners take full advantage of our powerful, open, and programmable edge cloud platform to build and deliver high-margin services and value-added offerings for end customers. Our partner program operates like a flywheel to innovate, market, sell, and deliver solutions jointly with our partners. The three primary channel partner types we work with are:
•Referral partners: Recommend Fastly products to their customers for a commission and include partners like agencies and consultants.
18
•Reseller partners: Act as a reseller to offer additional value on top of Fastly’s products and services and include partners like value-added resellers, system integrators, and more.
•MSP and MSSP partners: Managed Service Providers (MSP) and Managed Security Service Providers (MSSP) can earn technical certifications to provide certified implementation services and/or embed Fastly technology to enhance their SaaS or Platform as a Service offerings.
Partners work with Fastly’s sales and presales teams to scale sales cycle support. This helps expand our worldwide network of partners dedicated to protecting and delivering customers’ content. We have expanded the reach and breadth of these partners to include cross-selling delivery and security products. We have made significant investments in this area by adding additional channel sales and marketing resources, technical training and enablement, partner discounts, and an elevated partner program to offer partners even more benefits.
Cloud Partners. We integrate with major cloud providers to enhance their services and create solutions that are powerful, scalable, and secure. We have exclusive Private Network Interconnects (PNIs) and peering arrangements with key cloud providers such as Google Cloud Platform, AWS, and others to eliminate or minimize egress fees, enhance security, and improve overall performance. We are also available for purchase on the Google Cloud Marketplace and AWS Marketplace which can help eliminate the need for customers to have separate billing arrangements and makes Fastly services eligible for Google Cloud and AWS committed spends. We have strong go-to-market relationships with our cloud partners which allow us to access the benefits of their partner programs like joint business planning, co-selling, account support, added marketing funding, and more.
Integration Partners.We integrate with a number of third-party partners who offer complementary technology across a number of strategic use-cases and industries. These partners help expand our reach into new markets by offering customers a solution that seamlessly integrates with their existing technology stack making our technology even stickier. Here are some examples:
•Security: Our Next-Gen WAF integrates seamlessly with a broad ecosystem of third-party tools, enabling customers to streamline workflows, strengthen DevOps processes, enhance security visibility, and improve operational efficiencies. Our Next-Gen WAF supports Kubernetes and service mesh and API gateway technologies such as Envoy, Istio, and Ambassador to accommodate modern microservices architectures. It is also compatible with major cloud and platform providers, including Amazon Web Services, Microsoft Azure, Heroku, and VMware Tanzu.
The Fastly Next-Gen WAF is also integrated with A10 Networks ADC appliances enabling optional application security controls for their customers. This partnership expands our reach to new customer segments, including organizations that primarily operate in private data centers, maintain a smaller public cloud footprint, or are located in different geographic regions where Fastly has had more limited historical penetration.
•Logging & Analytics: Our real-time logging feature integrates with more than 20 logging endpoint partners to allow customers to customize and visualize their edge data for better monitoring of performance and security anomalies. Examples include DataDog, Looker (Google Cloud), SumoLogic, Logentries, Google Cloud Platform (GCP), Microsoft (Azure Blob Storage), and more.
•Compute: We work with a growing ecosystem of partners who are tapping into our powerful Compute serverless technology to extend their solutions across a variety of different use-cases.
•Media & Entertainment: We have partnerships across a number of technology providers in the media and entertainment industry to enhance our edge platform’s performance features, modern security offerings, and real-time metrics.
Competition
Our platform spans several markets from cloud computing and cloud security to CDNs. We segment the competitive landscape into six key categories:
19
•Legacy CDN platform solutions like Akamai;
•Application and API security vendors like Akamai, Cloudflare, F5, and Thales (Imperva);
•Point CDN players like Bunny CDN, CDNetworks, CDN77, and Qwilt;
•CDN providers that also offer serverless edge compute functionality like Akamai and Cloudflare;
•Public cloud providers that have added CDN and WAF capabilities like Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft (Azure); and
•Traditional on-premise, data center appliance vendors for load balancing, WAF, and/or DDoS like F5, Thales (Imperva), and Radware.
The principal competitive factors in our market include:
•platform functionality, scalability, performance, ease of use, ease of integration and programmability, reliability, security availability, and cost effectiveness;
•global network coverage and availability;
•ability to support modern application development processes and utilize new and proprietary technologies to offer services and features previously not available in the marketplace;
•ability to identify new markets, applications, and technologies;
•ability to attract and retain customers;
•brand, reputation, and trustworthiness;
•credibility with developers;
•quality of customer support;
•ability to recruit software engineers and sales and marketing personnel;
•ability to develop and protect intellectual property; and
•ability to identify opportunities for acquisitions and strategic relationships and successfully execute on them.
We believe we generally compete favorably with our competitors on the basis of these factors. Our edge cloud platform integrates many of the point products offered by our competitors which is a key differentiator. However, many of our competitors have substantially greater financial and technical resources in addition to larger sales and marketing budgets, broader market distribution, and more mature intellectual property portfolios.
20
Our Culture and Human Capital Resources
Our Values
Technology has the potential to make a radically positive impact on the world, and we aspire to improve human lives through our work. We were founded on strong ethical principles, and have intentionally grown values-first, scaling our workforce, services, customer portfolio, and investment partners purposefully. Our values guide our hiring practices as well as the ethics we are committed to upholding as we scale. We believe that as a result of our values, we have been able to identify, attract, engage and retain great people. We want to serve the very best of the Internet. We choose to work with customers that we believe have integrity, are trustworthy, and do not promote violence or hate. Our eight core values define who we are and how we choose to grow, hire, train, work, communicate, make decisions, support each other, and serve our customers.
Our Hiring Strategy
At Fastly, our ability to innovate and compete in the edge compute, delivery, security, and observability markets is directly tied to our ability to attract and retain specialized technical talent. We view our workforce as a strategic extension of our platform architecture: distributed, resilient, and high-performing.
Cultivating Technical Excellence and Belonging We are committed to building a workforce comprised of highly qualified individuals who reflect our core values. Our engineering recruitment focuses on attracting world-class experts in the foundational technologies of the internet, including Rust, WASM, and high-scale network security to foster our edge computing innovation.
Strategic Talent Pipelines and Development To maintain a competitive edge and a service-oriented culture, we leverage non-traditional talent pipelines. A key component of our strategy is our internal mobility program, which identifies high-potential talent from various backgrounds and technical training programs for our support organizations. These individuals often transition into broader roles across the company, infusing our product and engineering teams with a deep, customer-centric mindset and practical operational experience.
Total Rewards and Retention To attract and retain our highly qualified employees and executive team, we offer a competitive compensation program designed to align employee interests with long-term company success. This program includes a combination of competitive base salaries, performance-based incentives, comprehensive benefits, and a robust equity compensation component intended to motivate and reward long-term commitment and innovation.
21
We are building a global workforce and an inclusive culture that empowers and supports our employees and customers, regardless of background. We onboard all new employees with training programs on our values, our business, and important policies, including our Safe, Welcoming, and Productive Work Environment Policy. Annually thereafter we provide employees with code of conduct and security awareness training, a learning reimbursement program and performance evaluations. Our employee engagement efforts currently include company-wide newsletters and all-hands meetings, through which we aim to keep our employees well-informed and increase transparency. Our Employee Resource Groups are open to all employees and focus on making Fastly a better place where all employees are included, valued and engaged. We also use employee engagement surveys to collect employee feedback and assess the effectiveness of our culture, our strategy, and various health and well-being programs.
Employees
As of December 31, 2025, we had a total of 1,140 employees worldwide and 258 employees located outside of the United States; 47% of our employees resided within 50 miles of a Fastly office and 53% of our employees worldwide were considered remote, which means they resided more than 50 miles from a Fastly office or in locations where we do not have a Fastly office. We will continue to search for the best possible talent for every role and cultivate best-in-class in-office and remote employee experiences.
Our Organization
Sales & Marketing
Sales and marketing work closely to attract new customers and expand the adoption of our platform to help customers drive business outcomes.
We are building a go-to-market engine that scales, becomes increasingly more efficient, and is nimble enough to continue to grow our business in four dimensions:
•Customer logo acquisition
•Expansion into additional vertical markets and within existing customers
•Partner ecosystem leverage
•International expansion
Fastly’s marketing efforts have a significant impact on new logo acquisition, demand generation, and brand awareness. We are focused on optimizing the return on our marketing investment to drive demand across our portfolio and regions.
Our sales and marketing organizations collaborate to cultivate customer relationships with developers and business leaders at enterprises and technology-savvy organizations to drive revenue growth. We have geographically-based sales teams that continue to enhance our value-based selling methodology. Our land and expand sales strategy for enterprise customers has successfully demonstrated our platform’s capabilities, and our customer support enables broad adoption of our technology within an organization.
Customer Support
We have designed our products and platform to be self-service and require minimal customer support. Customers are automatically covered by our Standard support plan as soon as they sign up with us. They can file a ticket with the support team, and access documentation including online FAQs, API references, and configuration guidelines. Our support approach is unique and built with developers in mind. Our first-line support employee typically has an engineering background and is highly technical.
We also provide several options for premier, hands-on support from a team of highly-technical senior support engineers and technical account managers. They act as a single point of contact for our support, product, and engineering teams. Our support model is global, with 24/7 coverage and support offices located in North America, EMEA, and APAC.
22
Research & Development
Our research and development team members are responsible for the design, development, and reliability of all aspects of our edge cloud platform. Continuous improvement and innovation are core to our DNA, and these efforts are baked directly into our service life cycle. Scale, performance, security, and reliability are core functional requirements of everything we build into our platform to serve our customers.
Our philosophy of customer empowerment guides our research processes. Our product managers regularly engage with customers and developers, DevOps and site reliability engineering communities, as well as our internal stakeholders and subject matter experts, in order to understand customer needs. Our engineering team includes experts with deep experience who intimately understand customers’ technical challenges and build solutions that deliver outcomes our customers value the most.
Throughout the strategic design and build phases of our product life cycle, our development organization works closely with our product, infrastructure, operations, and compliance teams to design, develop, test, and launch any given solution. We strive for a balance of rapid iteration without compromise on the core functional requirements that our customers expect: scale, performance, security, and reliability.
As of December 31, 2025, we had 415 employees in our research and development group. Our research and development expenses were $162.7 million for the year ended December 31, 2025.
Infrastructure
Our infrastructure team is responsible for the design, deployment, and maintenance of the servers and network hardware that form the foundation of our mission critical edge cloud environment. We invest in research into global Internet geography to identify optimal colocation site selection, network partner identification, and network-to-network interconnection opportunities. These activities allow us to connect in close proximity to core Internet backbones and Internet service providers, thereby enhancing network performance. We carefully evaluate and test hardware from leading server, network, and component manufacturers to assess their compliance with our workload performance, system efficiency, and mean time-to-repair standards. In our process, we evaluate commodity server and network platforms to avoid vendor lock-in, while optimizing the mix of components in an effort to improve efficiency and optimize our capital expenditures. We intend to grow the number of data center colocation sites as traffic on our network grows and as demand for new markets justify investment.
Trust
Our security, compliance and data governance teams, as well as other departments across the company, continually iterate on our trust programs to better meet growing customer needs, updated regulatory requirements, and the evolving security threat landscape. To help validate the controls that safeguard our platform and the data moving through it, we have expanded our portfolio of security and compliance-related assessments and certifications over time.
Intellectual Property
We rely on a combination of patent, copyright, trademark, and trade secret laws in the United States and other jurisdictions, as well as license agreements and other contractual protections, to protect our proprietary technology. We also rely on a number of registered and unregistered trademarks to protect our brand.
As of December 31, 2025, in the United States, we had 112 issued or allowed patents, which expire between August 2033 and March 2043, 5 patent applications pending for examination. As of such date, we also had 22 issued patents and one patent application published or pending for examination in foreign jurisdictions, all of which are related to U.S. patents and patent applications. In addition, as of December 31, 2025, we had 18 registered trademarks and no pending trademarks in the United States. As of such date, we also had 35 registered trademarks in foreign jurisdictions.
In addition, we seek to protect our intellectual property rights by requiring our employees and independent contractors involved in development of intellectual property on our behalf to enter into agreements acknowledging that all works or other intellectual property generated or conceived by them on our behalf are our property, and assigning to us any rights, including intellectual property rights, that they may claim or otherwise have in those works or property, to the extent allowable under applicable law.
23
Despite our efforts to protect our technology and proprietary rights through intellectual property rights, licenses, and other contractual protections, unauthorized parties may still copy or otherwise obtain and use our software and other technology. In addition, we intend to continue to expand our international operations, and effective intellectual property, copyright, trademark, and trade secret protection may be unavailable or limited in foreign countries. Any significant impairment of our intellectual property rights could harm our business or our ability to compete. Further, companies in the communications and technology industries own large numbers of patents, copyrights, and trademarks and frequently threaten litigation, or file suit based on allegations of infringement or other violations of intellectual property rights. We are currently subject to, and expect to face in the future, allegations that we have infringed the intellectual property rights of third parties. From time to time, we also receive demands for indemnification from our customers under the terms of our contracts with them for infringement of a third-party’s intellectual property rights.
Legal Proceedings
From time to time, we have been and will continue to be subject to legal proceedings and claims, including proceedings and claims relating to employment, intellectual property, and commercial disputes. We are not presently a party to any legal proceedings that, if determined adversely to us, would individually or taken together have a material effect on our business, results of operations, financial condition, or cash flows. We have received, and may in the future continue to receive, claims from third parties asserting, among other things, infringement of their intellectual property rights. Future litigation may be necessary to defend ourselves, our partners, and our customers by determining the scope, enforceability, and validity of third-party proprietary rights, or to establish our proprietary rights. The results of any current or future litigation cannot be predicted with certainty, and regardless of the outcome, litigation can have an adverse impact on us because of defense and settlement costs, diversion of management resources, and other factors.
Please refer to Note 9—Commitments and Contingencies for discussion around our legal proceedings.
Regulatory
We are subject to a number of U.S. federal and state and foreign laws and regulations that involve matters central to our business. These laws and regulations may involve privacy and data security, intellectual property, competition, consumer protection, critical infrastructure or other subjects. Many of the laws and regulations to which we are subject are still evolving and being tested in courts and could be interpreted in ways that could harm our business. In addition, the application and interpretation of these laws and regulations often are uncertain, particularly in the new and rapidly evolving industry in which we operate. Because global laws and regulations have continued to develop and evolve rapidly, it is possible that we may not be, or may not have been, compliant with each such applicable law or regulation. For a description of the risks we face related to regulatory matters, refer to “Item 1A.—Risk Factors” in this Annual Report on Form 10-K.
Corporate Information
We were initially incorporated under the laws of the State of Delaware in March 2011 under the name SkyCache, Inc. We changed our name to Fastly, Inc. in May 2012. Our principal executive offices are located at 475 Brannan Street, Suite 300, San Francisco, California 94107. Our telephone number is 1-844-432-7859. Our website address is www.fastly.com. The information contained on, or that can be accessed through, our website does not constitute part of this Annual Report on Form 10-K.
We file annual reports on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K, and amendments to reports filed or furnished pursuant to Sections 13(a), 14 and 15(d) of the Exchange Act. The SEC maintains a website at https://www.sec.gov that contains reports, and other information regarding us and other companies that file materials with the SEC electronically. Copies of our reports on Forms 10-K, Forms 10-Q, and Forms 8-K, may be obtained, free of charge, electronically through our investor relations website at www.fastly.com/investors as soon as reasonably practicable after we file such material with, or furnish such material to, the SEC.
24
Item 1A. Risk Factors
Investing in our common stock involves a high degree of risk. Investors should carefully consider the risks and uncertainties described below, together with all of the other information contained in this Annual Report on Form 10-K, including the section titled “Management’s Discussion and Analysis of Financial Condition and Results of Operations” and our consolidated financial statements and related notes, before deciding to invest in our common stock. Unless otherwise indicated, references to our business being harmed in these risk factors will include harm to our business, reputation, customer growth, results of operations, financial condition, or prospects. Any of these events could cause the trading price of our common stock to decline, which would cause our stockholders to lose all or part of their investment. Our business, results of operations, financial condition, or prospects could also be harmed by risks and uncertainties not currently known to us or that we currently do not believe are material.
Risks Related to Our Business, Industry and Technology
If our platform fails to perform properly due to defects, interruptions, outages, delays in performance, or similar problems, and if we fail to develop enhancements to resolve any defect, interruption, delay, or other problems, we could lose customers, become subject to service performance or warranty claims, or incur significant costs.
Our operations are dependent upon our ability to prevent system interruption. The applications underlying our edge cloud computing platform are inherently complex and may contain material defects or errors, which may cause disruptions in availability or other performance problems. We have from time to time found defects and errors in our platform and may discover additional defects or errors in the future that could result in data unavailability, unauthorized access to, loss, corruption, or other harm to our customers’ data. These defects or errors could also be found in third-party applications or open source software on which we rely. We may not be able to detect and correct defects or errors before implementing our products. Consequently, we or our customers may discover defects or errors after our products have been deployed.
We currently serve our customers from our POPs located around the world. Our customers need to be able to access our platform at any time, without interruption or degradation of performance. However, we have not developed redundancies for all aspects of our platform. We depend, in part, on our third-party facility providers’ ability to protect these facilities against damage or interruption from natural disasters, extreme weather events, power or telecommunications failures, criminal acts, armed conflict, public health issues, such as a pandemic or epidemic, and similar events. In some cases, third-party cloud providers run their own platforms that we access, and we are, therefore, vulnerable to their service interruptions. In the event that there are any defects or errors in software, failures of hardware, damages to a facility, or misconfigurations of any of our services, we may have to divert resources away from other planned work, could experience lengthy interruptions in our platform, and also incur delays and additional expenses in arranging new facilities and services. Our customers may choose to divert their traffic away from our platform as a result of interruptions or delays. Business continuity arrangements, including the existence of redundant data centers that are designed to become active during certain lapses of service, may not function as intended, and any disruptions to our service could harm our business.
We design our system infrastructure and procure and own or lease the computer hardware used for our platform. Design and mechanical errors, spikes in usage volume, and failure to follow system protocols and procedures could cause our systems to fail, resulting in interruptions on our platform. Moreover, we have experienced and may in the future experience system failures or interruptions in our platform as a result of human error. These outages have resulted and may in the future result in service level agreement claims. Any interruptions or delays in our platform, whether caused by our products or our data centers, third-party error, our own error, natural disasters (such as drought, flooding, wildfires, and storms), or security breaches, whether accidental or willful, could harm our relationships with customers, reduce customers’ usage of our platform, cause our revenue to decrease and our expenses to increase, and divert resources away from product development. Climate change and other environmental or social pressures are expected to increase the frequency and severity of certain events, as well as contribute to chronic changes (such as changes in meteorological and hydrological patterns) that may also result in similar or additional risks. Also, in the event of damage or interruption, our insurance policies may not adequately compensate us for any losses that we may incur. These factors in turn could further reduce our revenue, subject us to liability and cause us to issue service credits or cause customers to fail to renew their customer contracts, any of which could harm our business.
The occurrence of any defects, errors, disruptions in service, failures involving redundant data centers, or other performance problems, interruptions, or delays with our platform, whether in connection with the day-to-day operations or otherwise, could result in:
25
•loss of customers;
•reduced customer usage of our platforms;
•lost or delayed market acceptance and sales of our products, or the failure to launch products or features on anticipated timelines;
•delays in payment to us by our customers;
•injury to our reputation and brand;
•governmental inquiry or oversight;
•legal claims, including warranty and service level agreement claims, against us; or
•diversion of our resources, including through increased service and warranty expenses or financial concessions, and increased insurance costs.
The costs incurred in correcting any material defects, errors, or other performance problems in our platform may be substantial and could harm our business.
If we are unable to attract new customers, in particular, enterprise customers, and to have existing enterprise customers continue and increase their use of our platform, our business will likely be harmed.
To grow our business, we must continue to attract new customers, in particular, enterprise customers, and generate revenue from those new customers. To do so, we must successfully convince potential customers of the benefits and the value of our platform. This may require significant and costly sales efforts that are targeted at larger enterprises and senior management of these potential customers. Sales to enterprise customers may involve longer sales cycles as a result of customers requiring considerable time to evaluate our platform, requiring participation in a competitive purchasing process, having more formal processes for approval of purchases, and more complex requirements. These factors significantly impact our ability to add new customers and increase the time, resources, and sophistication required to do so. In addition, numerous other factors, some of which are out of our control, may now or in the future impact our ability to acquire new customers, including potential customers’ commitments to other providers, real or perceived costs of switching to our platform, our failure to expand, retain, and motivate our sales and marketing personnel, our failure to develop or expand relationships with potential customers and channel partners, failure by us to help our customers to successfully deploy our platform, negative media or industry or financial analyst commentary regarding us or our solutions, litigation, and deteriorating general economic conditions. If we fail to attract new customers, particularly enterprise customers, as a result of these and other factors our business will likely be harmed.
In addition, our ability to grow and generate incremental revenue depends on our ability to maintain and grow our relationships with our existing enterprise customers so that they continue and increase their usage of our platform. If these customers do not maintain and increase their usage of our platform, our revenue may decline and our results of operations will likely be harmed.
For some of our products, we charge our customers based on their usage of our platform. Most of our customers, including some of our largest enterprise customers, do not have long-term contractual financial commitments to us. Some of our customers, who generally do not include our enterprise customers, enter into “click-through” agreements with us via our self-service model, and agree to a minimum monthly fee by signing up online with a credit card, and can easily terminate their subscriptions, or switch to a less expensive plan, at will with little advance notice. In addition, most of our current customer contracts are only one year in duration and these customers may not use our platform in a subsequent year. In order for us to maintain or improve our results of operations, it is important that our customers, in particular, our enterprise customers, use our platform in excess of their commitment levels, if any, and continue to use our platform on the same or more favorable terms. Our ability to retain our largest customers and expand their usage could be impaired for a variety of reasons, including customer budget constraints, customer satisfaction, changes in our customers’ underlying businesses, changes in the type and size of our customers, pricing changes, competitive conditions (including customers building their own CDNs), the acquisition of our customers by other companies, governmental actions, or the possibility thereof, and general economic conditions. Because many of our largest customers’ minimum usage commitments for our platform are relatively low compared to their expected
26
usage, it can be easy for certain customers to quickly reallocate usage or switch from our platform to an alternative platform altogether. In addition, certain customers may reduce or cease their use of our products at any time without penalty or termination charges, even after they have expanded usage in prior periods.
We base our decisions about expense levels and investments on estimates of our future revenue and anticipated rate of growth. Many of our expenses are fixed cost in nature for some minimum amount of time, such as colocation and bandwidth, so if we do experience slower usage growth on our platform it may not be possible to reduce costs in a timely manner or without the payment of fees to exit certain obligations early. If any of these events were to occur, our business may be harmed.
In addition, many of our customers have negotiated and may continue to negotiate lower rates in exchange for an agreement to renew, expand their usage in the future, or adopt new products. As a result, in certain cases, even though customers have not reduced their usage of our platform, the revenue we derive from that usage has decreased. If our platform usage or revenue fall significantly below the expectations of the public market, securities analysts, or investors, our business would be harmed, which could cause our stock price to decline.
Our future success also depends in part on our ability to expand our existing customer relationships, in particular, with enterprise customers, by increasing their usage of our platform, selling them additional products and upgrading their existing products. The rate at which our customers increase their usage of our platform and purchase products from us depends on a number of factors, including our ability to grow our platform and maintain the security and availability of it, develop and deliver new features and products, maintain customer satisfaction, general economic conditions and pricing and services offered by our competitors. If our efforts to increase usage of our platform by, or sell new and additional products to, our enterprise customers are not successful, our business would be harmed. In addition, even if our largest customers increase their usage of our platform, we cannot guarantee that they will maintain those usage levels for any meaningful period of time. In addition, because many of our products endeavor to deliver increased efficiency and functionality, the successful sale of a new or additional product to an existing customer could result in a reduction of the customer’s overall usage of our platform.
We receive a substantial portion of our revenues from a limited number of customers within a limited number of industries, and the loss of, or a significant reduction in usage by, one or more of our major customers would result in lower revenues and could harm our business.
Our future success depends on establishing and maintaining successful relationships with a diverse set of customers. We currently receive a substantial portion of our revenues from a limited number of customers and within a limited number of industries, such as media and entertainment. Our 10 largest customers generated an aggregate of 32% and 33% of our revenue in the trailing 12 months ended December 31, 2025 and 2024, respectively. Affiliated customers that are business units of a single company generated an aggregate of 10% of the Company’s revenue for the year ended December 31, 2025. No affiliated customers that are business units of a single company generated more than 10% of our revenue for the year ended December 31, 2024. In addition, in April 2024, the former administration signed into law a bill that would effectively ban TikTok in the United States if ByteDance, its China-based parent company, did not sell its stake in TikTok within a set time frame. Following a series of executive orders in 2025 that suspended enforcement of this law, on January 22, 2026, ByteDance announced the establishment of TikTok USDS Joint Venture LLC in compliance with the law to secure United States user data, apps, and the algorithm through data privacy and cybersecurity measures. TikTok was one of our largest customers for the year ended December 31, 2025 and remains a customer of ours. We do not know how the restructuring may impact our traffic levels. It is likely that we will continue to be dependent upon a limited number of customers for a significant portion of our revenues for the foreseeable future and, in some cases, the portion of our revenues attributable to individual customers may increase in the future. In addition, changes to our customers’ businesses may contribute to further customer concentration, including any impact from acquisition activities, internal business reorganizations leading to operational and decision making changes, and corporate structure changes such as subsidiary consolidation and reorganization that may arise in the future. The loss of one or more key customers or a reduction in usage by any major customers would reduce our revenues. If we fail to maintain existing customers or develop relationships with new customers and across different industries, our business would be harmed.
Component delays, shortages, or price increases could interrupt our ability to complete the construction of our servers or POPs and to meet the usage needs of our customers. Our operating results could be materially harmed if we are unable to adequately manage our infrastructure needs.
Our business depends on the timely supply of certain parts and components to construct our servers or POPs. We rely on a limited number of suppliers for several components of the equipment we use to operate our network and provide products to our customers. Our reliance on these suppliers exposes us to risks including reduced control over production costs and constraints based on the then current availability, terms, and pricing of these components, including pricing changes as a result
27
of inflationary pressures. Moreover, international trade disputes may disrupt or delay our supply chain for these components or lead to pricing increases. For example, the United States has imposed or indicated an intention to impose tariffs on certain countries which may lead to retaliatory actions such as counter-tariffs and increase production costs and disruptions in our supply chain. The United States and other jurisdictions have also leveraged various trade and value chain requirements, including on environmental and social criteria, which may make sourcing more costly, require us to change suppliers, or otherwise adversely impact our operations. Further, it is possible that government policy changes, including policy changes made with little to no advance notice, and related uncertainty about policy changes could increase market volatility. If our supply of certain components is further disrupted or delayed, there can be no assurance that we will be able to obtain adequate replacements for the existing components or that supplies will be available on terms and prices that are favorable to us, if at all. Any disruption or delay in the supply of our hardware components has in the past and may in the future limit capacity expansion or replacement of defective or obsolete equipment or cause other constraints on our operations that could damage our customer relationships and harm our business.
To ensure adequate supply of parts and components, we must forecast server needs and expenses and place orders sufficiently in advance with our suppliers based on estimates of future demand for network capacity. As we continue to experience growth, we may face challenges managing adequate server capacity due to potential component delays, shortages, price increases, hardware efficiencies gained through internal development, or any potential changes in server architecture including due to technological advances or obsolescence. We may incur charges in future periods related to server management or incorrectly forecast our network capacity needs in future periods. If we have excess server capacity, we have in the past needed to, and may in the future need to, write-down or write-off server assets, which may materially harm our operating results. For example, in the year ended December 31, 2025, we recognized certain equipment, internal-use software project and right-of-use asset related write-off charges of $0.4 million. Conversely, if we underestimate network capacity needs, we may in future periods be unable to meet demand and be required to incur higher costs to secure necessary parts and components of our servers, which could adversely affect our customer relationships and harm our business.
Our history of operating losses makes it difficult to evaluate our current business and prospects and may increase the risks associated with your investment.
We were founded in 2011 and have experienced net losses since inception. We have encountered and will continue to encounter risks and difficulties frequently experienced by growth companies in constantly evolving industries, including companies in the technology sector, including the risks described in this Annual Report on Form 10-K. If we do not address these risks successfully, our business may be harmed.
We generated a net loss of $121.7 million for the year ended December 31, 2025 and we had an accumulated deficit of $1,114.5 million. We will need to generate and sustain increased revenue levels and manage costs in future periods in order to become profitable; even if we achieve profitability, we may not be able to maintain or increase our level of profitability. We intend to continue to expend significant funds to support further growth and further develop our platform, including expanding the functionality of our platform, expanding our technology infrastructure and business systems to meet the needs of our customers, expanding our direct sales force and partner ecosystem, increasing our marketing activities, and growing our international operations. We have in the past faced, and will continue to face, increased compliance costs associated with growth and expansion of our customer base. Our efforts to grow our business may be costlier than we expect, and we may not be able to increase our revenue enough to offset our increased operating expenses. We may incur significant losses in the future for a number of reasons, including the other risks described herein, and unforeseen expenses, difficulties, complications and delays, and other unknown events. If we are unable to achieve and sustain profitability, our business may be harmed.
If our IT Systems or data, or those of third parties upon which we rely, are compromised, limited, or fail, our business could experience materially adverse consequences, including but not limited to regulatory investigations or actions, litigation, fines and penalties, disruptions of our business operations, loss of revenue or profits, loss of customers or sales, reputational harm, and other adverse consequences.
Our business depends on providing our customers with fast, efficient, and reliable distribution of applications and content over the Internet, and we rely on IT Systems to provide our products and services, including for internal and external operations that are critical to our business. “IT Systems” includes computer systems, hardware, software, technology infrastructure and websites and networks. In the ordinary course of business, we and the third parties upon which we rely, collect, receive, store, process, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, transmit, and share Sensitive Information. "Sensitive Information" includes our, our customers', and our customers' end users' proprietary, confidential, and sensitive data, including personal information, intellectual property, trade secrets, and encryption keys.
28
Maintaining the security and availability of our platform, IT Systems, and Sensitive Information is a critical issue for us and our customers, and we expend significant resources, and may need to fundamentally change our business activities and modify our practices and operations, in an effort to protect against security incidents and to mitigate, detect, and remediate actual and potential vulnerabilities.
Cyber-attacks, malicious Internet-based activity, online and offline fraud, and other similar activities threaten the confidentiality, integrity, and availability of our Sensitive Information and IT Systems, and those of the third parties upon which we rely. Such threats are prevalent and continue to become more so. They are difficult to detect, and come from a variety of sources and threat actors, including “hacktivists,” personnel (such as through theft or misuse), sophisticated nation states, and nation-state-supported actors.
Some threat actors engage in cyber-attacks for geopolitical reasons and in conjunction with military conflicts and defense activities. We have in the past been subject to cyber-attacks from third parties, including parties who we believe are sponsored by government actors. Since our customers share our multi-tenant architecture, cyber-attacks on any one of our customers could have a negative effect on our other customers. In the past, these attacks have significantly increased the bandwidth used on our platform and have strained our network. During times of war and other major conflicts, we, the third parties upon which we rely, and our customers may be vulnerable to a heightened risk of these attacks, including retaliatory cyber-attacks, that could materially disrupt our IT Systems and operations, supply chain, and ability to produce, sell, and distribute our services.
We and the third parties upon which we rely are subject to a variety of evolving threats, including but not limited to social-engineering attacks (including through deep fakes, which may be increasingly more difficult to identify as fake, and phishing attacks), malicious code, malware (including as a result of advanced persistent threat intrusions), DDoS attacks, account takeover attacks, credential harvesting, personnel misconduct or error, ransomware attacks, supply-chain attacks, software bugs, server malfunctions, software or hardware failures, attacks facilitated or enhanced by artificial intelligence (“AI”) such as prompt injection or AI model inversion attacks, loss of data or other information technology assets, adware, telecommunications failures, natural disasters, and other similar threats. For example, we have experienced DDoS attacks of significant size and severity that caused us to invest resources into improving our systems, and we expect to continue to be subject to DDoS and other forms of attacks in the future, particularly as they have become more prevalent in our industry. Similarly, we have been the target of phishing and social engineering schemes that may be designed to, among other things, improperly gain access to our Sensitive Information or fraudulently obtain payments or funds from us. Further, we are not immune from the possibility of a malicious insider compromising our IT Systems or misappropriating our Sensitive Information.
In particular, severe ransomware attacks are becoming increasingly prevalent, and can lead to significant interruptions in our operations, compromise of our or our service providers’ IT Systems, loss of Sensitive Information and revenue, reputational harm, and diversion of funds. Extortion payments may alleviate the negative impact of a ransomware attack, but we may be unwilling or unable to make such payments due to a number of factors, including applicable laws or regulations prohibiting such payments.
We are incorporated into the supply chain of a number of companies worldwide and, as a result, if our services are compromised, a significant number or, in some instances, all of our customers and their data could be simultaneously affected. In addition, supply-chain attacks have increased in frequency and severity, and we cannot guarantee that third parties’ infrastructure in our supply chain or our third-party partners’ supply chains have not been compromised. The potential liability and associated consequences we could suffer as a result of such a large-scale event could be catastrophic and result in irreparable harm.
Future or past business transactions (such as acquisitions or integrations) could expose us to additional cybersecurity risks and vulnerabilities, as our IT Systems could be negatively affected by vulnerabilities present in acquired or integrated entities’ systems and technologies. Furthermore, we may discover security issues that were not found during due diligence of such acquired or integrated entities, and it may be difficult to integrate companies into our IT Systems and security program.
We rely on third-party service providers and technologies to operate critical IT Systems and to process Sensitive Information in a variety of contexts, including, without limitation, cloud-based infrastructure, data center facilities, encryption and authentication technology, content delivery to customers, and other functions. Like many other companies, our ability to monitor third parties’ information security practices is limited, and these third parties may not have adequate information security measures in place. If our third-party service providers experience a security incident or other interruption, we could experience adverse consequences. While we may be entitled to damages if our third-party service providers fail to satisfy their
29
privacy and data security-related obligations to us, any award may be insufficient to cover our damages, or we may be unable to recover such award.
Any adverse impact to the availability, integrity, or confidentiality of our Sensitive Information or IT Systems, including as a result of the previously identified or similar threats, could cause a security incident or other interruption that could result in unauthorized, unlawful, or accidental acquisition, modification, destruction, loss, alteration, encryption, disclosure of, or access to our Sensitive Information or our IT Systems, or those of the third parties upon whom we rely. A security incident or other interruption could disrupt our ability (and that of third parties upon whom we rely) to provide our platform, products and services.
In addition, as we expand our emphasis on selling security-related products, we may become a more attractive target for attacks on our infrastructure intended to destabilize, overwhelm, or shut down our platform. For example, we have had security incidents in the past that have tested the limits of our infrastructure and impacted the performance of our platform.
In addition to experiencing a security incident, third parties may gather, collect, or infer Sensitive Information about us from public sources, data brokers, or other means that reveals competitively sensitive details about our organization and could be used to undermine our competitive advantage or market position. Further, Sensitive Information of the Company or our customers could be leaked, disclosed, or revealed as a result of or in connection with our employees’, personnel’s, or vendors’ use of generative AI technologies.
Moreover, certain privacy and data security obligations may require us to implement and maintain specific or industry-standard or reasonable security measures to protect our IT Systems and Sensitive Information, and a failure to do so could result in material financial penalties and other materially adverse consequences.
While we have implemented security measures designed to protect against security incidents, there can be no assurance that these measures will be effective. Additionally, we may not be able to detect and remediate all vulnerabilities because the threats and techniques used to exploit the vulnerability change frequently and are often sophisticated in nature. Therefore, such vulnerabilities could be exploited but may not be detected until after a security incident has occurred. These vulnerabilities pose material risks to our business. Further, we may experience delays in developing and deploying remedial measures designed to address any such identified vulnerabilities.
Applicable privacy and data security obligations may require us to notify relevant stakeholders, including affected individuals, customers, regulators, and investors of security incidents. For example, SEC rules require disclosure on Form 8-K of the nature, scope and timing of any material cybersecurity incident and the reasonably likely impact of such incident. Compliance with such disclosure efforts is costly, and the disclosure or the failure to comply with such requirements could lead to adverse consequences. If we (or a third party upon whom we rely) experience any adverse impact to the availability, integrity, or confidentiality of our IT Systems or Sensitive Information, we may experience adverse consequences, such as government enforcement actions (for example, investigations, fines, penalties, audits, and inspections); additional reporting requirements and/or oversight, restrictions on processing Sensitive Information (including personal data); litigation (including class action claims); indemnification obligations; negative publicity; reputational harm; monetary fund diversions; diversion of management attention; interruptions or degradation of performance in our services (including availability of data); financial loss; and other similar harms. Security incidents and attendant consequences may also impact customers’ systems and data, and cause customers to stop using our platform, products, and services, cause us to offer pricing and other concessions, deter new customers from using our platform, products, and services, result in litigation, and negatively impact our ability to grow and operate our business.
Our contracts may not contain limitations of liability, and even where they do, there can be no assurance that limitations of liability in our contracts are sufficient to protect us from liabilities, damages, or claims related to our privacy and data security obligations. We cannot be sure that our insurance coverage will be adequate or sufficient to protect us from or to mitigate liabilities arising out of our privacy and data security practices, that such coverage will continue to be available on commercially reasonable terms or at all, or that such coverage will pay future claims.
If we fail to efficiently develop and sell new products and respond effectively to rapidly changing technology, evolving industry standards, changing regulations, and changing customer needs, requirements, or preferences, our products may become less competitive.
The market in which we compete is relatively new and subject to rapid technological change, evolving industry standards and regulatory changes, as well as changing customer needs, requirements, and preferences. The success of our business will
30
depend, in part, on our ability to adapt and respond effectively to these changes on a timely basis. If we are unable to develop and sell new products that satisfy and are adopted by our customers and provide enhancements, new features, and capabilities to our platform that keep pace with rapid technological and industry change, our revenue and operating results could be adversely affected. Further, some of our prospective customers may require custom development of features as part of their purchase decision, or our existing customers may require us to develop custom features. If we are unable to meet their requirements, they may look to our competitors or internal solutions that eliminate reliance on third-party providers, and our revenue and operating results could be adversely affected. Further, prioritizing such custom features can be difficult to adapt to other customers and may require significant engineering resources. If new technologies emerge that enable large Internet platform companies to utilize their own data centers and implement delivery approaches that limit or eliminate reliance on third-party providers like us, or that enable our competitors to deliver competitive products and applications at lower prices, more efficiently, more conveniently, or more securely, such technologies could adversely impact our ability to compete. If our platform does not allow us or our customers to comply with the latest regulatory requirements, our existing customers may decrease their usage on our platform or leave our platform and new customers will be less likely to adopt our platform.
Our platform must also integrate with a variety of network, hardware, mobile, and software platforms and technologies, and we need to continuously modify and enhance our products and platform capabilities to adapt to changes and innovation in these technologies. If developers widely adopt new software platforms, we would have to attempt to develop new versions of our products and enhance our platform’s capabilities to work with those new platforms. These development efforts may require significant engineering, marketing, and sales resources, all of which would affect our business and operating results. Any failure of our platform’s capabilities to operate effectively with future infrastructure platforms, technologies, and software platforms could reduce the demand for our platform. If we are unable to respond to these changes in a cost-effective manner, our products may become less marketable and less competitive or obsolete, and our business may be harmed.
In particular, the market for AI solutions is evolving rapidly. We may not be successful in our AI initiatives or our competitors may incorporate AI into their products or market their AI solutions more successfully than us, which could adversely affect our business (such as by impairing our ability to compete effectively against our competitors), reputation, or financial results. For example, we may encounter challenges such as a lack of talented personnel, inability to secure necessary infrastructure, or the possibility that the AI tools we utilize may not deliver their intended value. Each of these challenges would adversely impact our ability to effectively execute our strategy of leveraging AI in our products and to enhance our business operations.
In addition to ongoing investments to use AI to enhance our business operations, we are enabling AI workloads for our customers and leveraging AI in a manner that is designed to enhance our platform's usability and capabilities. However, our AI-focused products and services may not be successful or may fail to meet customer expectations, which could impair our ability to compete effectively and adversely affect our financial results. If we are unable to use AI effectively or use AI less successfully than our competitors, it could impair our ability to compete effectively against our competitors, adversely affect our business and result in competitive disadvantages.
Moreover, our platform is highly technical and complex. For example, our delivery products may rely on knowledge of Varnish Configuration Language (“VCL”) to utilize certain features. Potential developers may be unfamiliar or opposed to working with VCL and therefore decide to not adopt our platform, which may harm our business.
If we fail to forecast our revenue accurately, or if we fail to manage our expenditures, our operating results could be adversely affected.
We cannot accurately predict customers’ usage or renewal rates given the diversity of our customer base across industries, geographies and size, and ability of customers to allocate usage, among other factors. Accordingly, we may be unable to accurately forecast our revenues. Notwithstanding our substantial investments in sales and marketing, infrastructure, and research and development in anticipation of growth in our business, if we do not realize returns on these investments in our growth, our results of operations could differ materially from our forecasts, which would adversely affect our results of operations and could disappoint analysts and investors, causing our stock price to decline. In addition, we have experienced, and may continue to experience, longer payment cycles in collecting accounts receivable from certain of our customers, difficulty in detecting potentially fraudulent self-service customer accounts in a timely manner, and errors in calculating the number of ongoing self-service customer accounts. If we are unable to timely collect accounts receivable from our customers or detect fraudulent self-service customer accounts in a timely manner, our business will be harmed.
31
Failure to effectively develop and expand our marketing and sales capabilities could harm our ability to increase our customer base and achieve broader market acceptance of our platform.
We have historically benefited from word-of-mouth and other organic marketing to attract new customers. Through this word-of-mouth marketing, we have been able to build our brand with relatively low marketing and sales costs. This strategy has allowed us to build a substantial customer base and community of users who use our products and act as advocates for our brand and our platform, often within their own corporate organizations. However, our ability to further increase our customer base and achieve broader market acceptance of our products will significantly depend on our ability to expand our marketing and sales operations. We plan to continue expanding our sales force and strategic partners, both domestically and internationally. We also plan to continue to dedicate significant resources to sales, marketing, and demand-generation programs, including various online marketing activities as well as targeted account-based marketing. The effectiveness of our targeted account-based marketing has varied over time and may vary in the future. All of these efforts will require us to invest significant financial and other resources and if they fail to attract additional customers, our business will be harmed. We have also used a strategy of offering free accounts on our platform in order to strengthen our relationship and reputation within the developer community by providing these developers with the ability to familiarize themselves with our platform without first becoming a paying customer. However, these developers may not perceive value in the additional benefits and services we offer beyond the free accounts and may choose not to pay for those additional benefits. In addition, we may be subject to potential liabilities, including litigation, as a result of our free account users' use of our network. Moreover, some existing paying customers may choose not to renew their commitment with us in favor of relying on the free version of our platform. Most free accounts do not convert to paid versions of our platform, and to date, only a few users who have converted to paying customers have gone on to generate meaningful revenue. If our other lead generation methods do not result in broader market acceptance of our platform and the users of free versions of our platform do not become, or are unable to convince their organizations to become, paying customers, or if paying customers choose to convert to the free versions of our platform, we will not realize the intended benefits of this strategy, and our business will be harmed.
We believe that there is significant competition for sales personnel, including sales representatives, sales managers, and sales engineers, with the skills and technical knowledge that we require. Our ability to achieve significant revenue growth will depend, in large part, on our success in recruiting, training, incentivizing, and retaining sufficient numbers of sales personnel to support our growth. New hires require significant training and may take significant time before they achieve full productivity. Our recent hires may not become productive as quickly as we expect, if at all, and we may be unable to hire or retain sufficient numbers of qualified individuals in the markets where we do business or plan to do business. In addition, particularly if we continue to grow rapidly, new members of our sales force will have relatively little experience working with us, our platform, and our business model. If we are unable to hire and train sufficient numbers of effective sales personnel, our sales personnel do not reach significant levels of productivity in a timely manner, our sales personnel are not effectively incentivized, or our sales personnel are not successful in acquiring new customers or expanding usage by existing customers, our business will be harmed.
The markets in which we participate are competitive, and if we do not compete effectively, our business will be harmed.
The market for cloud computing platforms, particularly enterprise grade products, is highly fragmented, competitive, and constantly evolving. With the introduction of new technologies and market entrants, we expect that the competitive environment in which we compete will remain intense going forward. Legacy CDN platform solutions like Akamai, application and API security vendors like Akamai, Cloudflare, F5, and Thales (Imperva), and Point CDN players like Bunny CDN, CDNetworks, CDN77, and Qwilt offer products that compete with ours. We also compete with CDN providers that also offer serverless edge compute functionality like Akamai and Cloudflare, public cloud providers that have added CDN and WAF capabilities like Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft (Azure), and traditional on-premise data center appliance vendors for load balancing, WAF, and/or DDoS like F5, Thales (Imperva), and Radware. Some of our competitors have made or may make acquisitions or may enter into partnerships or other strategic relationships that may provide more comprehensive offerings than they individually had offered. Such acquisitions or partnerships may help competitors achieve greater economies of scale than us. In addition, new entrants not currently considered to be competitors may enter the market through acquisitions, partnerships, or strategic relationships. We compete on the basis of a number of factors, including:
•our platform’s functionality, scalability, performance, ease of use, ease of integration and programmability, reliability, security availability, and cost effectiveness relative to that of our competitors’ products and services;
•our global network coverage and availability;
32
•our ability to support modern application development processes and utilize new and proprietary technologies to offer services and features previously not available in the marketplace;
•our ability to identify new markets, applications, and technologies;
•our ability to attract and retain customers;
•our brand, reputation, and trustworthiness;
•our credibility with developers;
•the quality of our customer support;
•our ability to recruit software engineers and sales and marketing personnel;
•our ability to protect our intellectual property; and
•our ability to identify opportunities for acquisitions and strategic relationships and successfully execute on them.
We face substantial competition from legacy CDNs, small business-focused CDNs, cloud providers, and traditional data center and appliance vendors. In addition, existing customers have transitioned or notified us of their intent to transition, and existing and potential customers may in the future transition, off of our platform, or may limit their use, because they pursue a “do-it-yourself” approach to develop their own CDN by putting in place equipment, software, and other technology products for content and application delivery within their internal systems; enter into relationships directly with network providers instead of relying on an overlay network like ours; or implement multi-vendor policies to reduce reliance on external providers like us.
Our competitors vary in size and in the breadth and scope of the products and services offered. Many of our competitors and potential competitors have greater name recognition, longer operating histories, more established customer relationships and installed customer bases, larger marketing budgets, and greater resources than we do. While some of our competitors provide a platform with applications to support one or more use cases, many others provide point-solutions that address a single use case. Other potential competitors not currently offering competitive applications may expand their product offerings, and our current customers may develop their own products or features, to compete with our offerings. Our competitors may be able to respond more quickly and effectively than we can to new or changing opportunities, technologies, standards, and customer requirements. An existing competitor or new entrant could introduce new technology that reduces demand for our platform. In addition to application and technology competition, we face pricing competition. Some of our competitors offer their applications or services at a lower price, which has resulted in pricing pressures. Some of our larger competitors have the operating flexibility to bundle competing applications and services with other offerings, including offering them at a lower price or for no additional cost to customers as part of a larger sale of other products. For all of these reasons, we may not be able to compete successfully and competition could result in the failure of our platform to achieve or maintain market acceptance, the market for our edge cloud platform may grow more slowly than we anticipate, any of which could harm our business.
If we fail to maintain and enhance our brand, our ability to expand our customer base will be impaired and our business, results of operations and financial condition may suffer.
We believe that maintaining and enhancing our brand is important to continued market acceptance of our existing and future products, attracting new customers, and retaining existing customers. We also believe that the importance of brand recognition will increase as competition in our market increases. Successfully maintaining and enhancing our brand will depend largely on the effectiveness of our marketing efforts, our ability to provide reliable products that continue to meet the needs of our customers at competitive prices, our ability to maintain our customers’ trust, our ability to continue to develop new functionality and products, and our ability to successfully differentiate our platform from competitive products and services. Additionally, our brand and reputation may be affected if customers do not have a positive experience with our partners’ services. Our brand promotion activities may not generate customer awareness or yield increased revenue, and even if they do, any increased revenue may not offset the expenses we incurred in building our brand. If we fail to successfully promote and maintain our brand, our business may be harmed.
33
Acquisitions, strategic investments, partnerships, or alliances could be difficult to identify and integrate, divert the attention of management, disrupt our business, and dilute stockholder value.
We have in the past acquired, and we may in the future seek to acquire or invest in, businesses, products, or technologies that we believe could complement or expand our platform, enhance our technical capabilities, or otherwise offer growth opportunities. The pursuit of potential acquisitions may divert the attention of management and cause us to incur various expenses in identifying, investigating, and pursuing acquisitions, whether or not such acquisitions are completed. In addition, we have limited experience in acquiring other businesses, and we may not successfully identify desirable acquisition targets or, when we acquire additional businesses, we may not be able to integrate them effectively following the acquisition. Acquisitions could also result in dilutive issuances of equity securities or the incurrence of debt, which could adversely affect our operating results, may cause unfavorable accounting treatment, may expose us to claims and disputes by third parties, including intellectual property claims, and may not generate sufficient financial returns to offset additional costs and expenses related to the acquisitions. We may also incur significant, and sometimes unanticipated costs in connection with these acquisitions or in integration with our business. In addition, if an acquired business fails to meet our expectations or we do not realize sufficient value, our business may be harmed.
Further, it is possible that there could be a loss of our existing or any acquired company’s key employees and customers, disruption of either company’s or both companies’ ongoing businesses or unexpected issues, higher than expected costs and an overall post-completion process that takes longer than originally anticipated. Specifically, the following issues, among others, must be addressed in combining any company’s operations with ours in order to realize the anticipated benefits of the acquisition so the combined company performs as the parties hope:
•combining the companies’ corporate functions;
•combining their business with our business in a manner that permits us to achieve the synergies anticipated to result from the acquisition, the failure of which would result in the anticipated benefits of the acquisition not being realized in the time frame currently anticipated or at all;
•maintaining existing and new agreements with customers, service providers, and vendors;
•determining whether and how to address possible differences in corporate cultures, management philosophies and strategies relating to channels, resellers, and partners;
•integrating the companies’ administrative and information technology infrastructure;
•developing products and technology that allow value to be unlocked in the future; and
•evaluating and forecasting the financial impact of the acquisition transaction, including accounting impacts.
Failure to address any of the above listed issues could have a material adverse effect on our business, results of operations and financial position. In addition, at times the attention of certain members of our management and resources may be focused on completion of the acquisition and integration planning of the businesses of the two companies and diverted from day-to-day business operations, which may disrupt our ongoing business and the business of the combined company.
We are, and may in the future be, involved in class-action lawsuits and other litigation matters that are expensive and time-consuming. If resolved adversely, lawsuits and other litigation matters could seriously harm our business.
We are, and may in the future be, subject to litigation such as putative class action and stockholder derivative lawsuits brought by stockholders. For example, on May 24, 2024, we and certain of our officers were named as defendants in putative securities class action filed in the United States District Court for the Northern District of California purportedly brought on behalf of holders of our common stock. On November 1, 2024, the lead plaintiff filed an amended complaint. On June 12, 2024 and July 1, 2024, stockholder derivative complaints were filed in the United States District Court for the Northern District of California against certain of our officers and directors based on substantially similar allegations as those in the putative securities class action. These two shareholder derivative actions have been consolidated and stayed pending resolution of our motion(s) to dismiss in the securities class action. On August 23, 2024 and December 20, 2024, substantially similar stockholder derivative complaints were filed against certain of our officers and directors in the United States District Court for
34
the District of Delaware and the Court of Chancery for the State of Delaware. These two shareholder derivative actions have also been stayed pending resolution of our motion(s) to dismiss in the above-referenced putative securities class action.
Defendants filed a motion to dismiss the putative securities class action on January 15, 2025. The lead plaintiff filed an opposition to defendants’ motion to dismiss on March 17, 2025. Defendants filed a reply in support of the motion to dismiss on April 30, 2025. On September 24, 2025, the court issued an order granting in part and denying in part the motion to dismiss. On October 24, 2025, the lead plaintiff filed a second amended complaint. On December 9, 2025, Defendants filed a motion to dismiss the second amended complaint. On January 26, 2026, Lead Plaintiff filed an opposition. Defendants filed a reply in support of the motion to dismiss the second amended complaint on February 19, 2026. A hearing is scheduled for April 30, 2026 on Defendants’ motion to dismiss the second amended complaint. We anticipate that we may be a target for lawsuits in the future, as we have been in the past. Any litigation to which we are a party may result in an onerous or unfavorable judgment that may not be reversed on appeal, or we may decide to settle lawsuits on similarly unfavorable terms. Any such negative outcome could result in payments of substantial monetary damages and accordingly our business could be seriously harmed. The results of lawsuits and claims cannot be predicted with certainty. Regardless of the final outcome, defending these claims, and associated indemnification obligations, are costly and can impose a significant burden on management and employees, and we may receive unfavorable preliminary, interim, or final rulings in the course of litigation, which could seriously harm our business.
We may not be able to scale our business quickly enough to meet our customers’ growing needs. If we are not able to grow efficiently, our business could be harmed.
As usage of our edge cloud computing platform grows and as the breadth of use cases for our platform expands, we will need to devote additional resources to improving our platform architecture, integrating with third-party applications and maintaining infrastructure performance. In addition, we will need to appropriately scale our processes and procedures that support our growing customer base, including increasing our number of POPs around the world and investments in systems, training, and customer support.
Any failure of or delay in these efforts could cause impaired system performance and reduced customer satisfaction. These issues could reduce the attractiveness of our platform to customers, resulting in decreased sales to new customers, lower renewal rates by existing customers, the issuance of service credits, or requested refunds, which would hurt our revenue growth and our reputation. Even if we are able to upgrade our systems and expand our staff, any such expansion will be expensive and complex, and require the dedication of significant management time and attention. We could also face inefficiencies or operational failures as a result of our efforts to scale our cloud infrastructure, such as by over investing in systems and equipment to support anticipated growth in our platform. We cannot be sure that the expansion and improvements to our cloud infrastructure will be effectively implemented on a timely basis, if at all, and such failures would harm our business.
We may have insufficient transmission bandwidth and colocation space, which could result in disruptions to our platform and loss of revenue.
Our operations are dependent in part upon transmission bandwidth provided by third-party telecommunications network providers and access to colocation facilities to house our servers. There can be no assurance that we are adequately prepared for unexpected increases in bandwidth demands by our customers, particularly when customers experience cyber-attacks. The bandwidth we have contracted to purchase may become unavailable for a variety of reasons, including service outages, payment disputes, network providers going out of business, natural disasters, extreme weather events, networks imposing traffic limits, or governments adopting regulations that impact network operations. In some regions, bandwidth providers have their own services that compete with us, or they may choose to develop their own services that will compete with us. These bandwidth providers may become unwilling to sell us adequate transmission bandwidth at fair market prices, if at all. This risk is heightened where market power is concentrated with one or a few major networks. We also may be unable to move quickly enough to augment capacity to reflect growing traffic or security demands. Failure to put in place the capacity we require could result in a reduction in, or disruption of, service to our customers and ultimately a loss of those customers. Such a failure could result in our inability to acquire new customers demanding capacity not available on our platform.
The nature of our business exposes us to inherent liability risks.
Our platform and related applications, including our security solutions, are designed to provide rapid protection against web application vulnerabilities and cyber-attacks. However, no security product can provide absolute protection against all
35
vulnerabilities and cyber-attacks. Our platform is subject to cyber-attacks, and the failure of our platform and related applications to adequately protect against these cyber-attacks may allow our customers to be attacked. Any adverse consequences of these attacks, and our failure to meet our customers’ expectations as they relate to such attacks, could harm our business.
Due to the nature of our applications, we are potentially exposed to greater risks of liability for product or system failures than may be inherent in other businesses. Although substantially all of our customer agreements contain provisions that limit our liability to our customers, these limitations may not be sufficient, and we cannot assure you that these limitations will be enforced or the costs of any litigation related to actual or alleged omissions or failures would not have a material adverse effect on us even if we prevail.
Our dedication to our values may negatively influence our financial results.
We have taken, and may continue to take, actions that we believe are in the best interests of our customers, our employees, and our business, even if those actions do not maximize financial results in the short term. For instance, we do not knowingly allow our platform to be used by organizations with a primary objective to promote violence or hate speech, and that conflict with our values, including principles of integrity and trustworthiness, among others. In the past, we have removed customers from our platform who we believed took positions conflicting with these values, and we may continue to do so in the future. While we believe this is beneficial to the long term performance of our business, this approach may not result in the benefits that we expect, and our employees or third parties may disagree with our interpretation of our values, or take issue with how we execute on our values, which may result in us becoming a target for negative publicity, increased scrutiny, lawsuits, or network attacks, in which case our business could be harmed.
Our growth depends in large part on the success of our partner relationships.