We distribute bitcoin geographically in safe deposit boxes and vaults around the world. We hash passwords stored in the database (using bcrypt with a cost factor of 12). We check for strong passwords on account creation and password reset. Application credentials are kept separate from the database and code base. In cryptography, HMAC (Hash-based Message Authentication Code) is a specific construction for calculating a message authentication code (MAC) involving a cryptographic hash function in combination with a secret key.

