App accounts
Passwords hashed with bcrypt
TooBloom app account passwords are hashed with the bcrypt algorithm (12 rounds) and are never stored or readable in clear text. The marketing site does not manage public user accounts; the only area with credentials is the internal showcase area, protected by a signed (HMAC), httpOnly session cookie not readable from JavaScript.