We use a combination of manual and automated testing to identify vulnerabilities in web applications. We test for various security concerns such as cross-site scripting (XSS), SQL injection, and broken authentication.