Tide Protocol – “Splintering” passwords for greater security
computerweekly.com
computerweekly.com
Example: bcrypt.hashpw(hashlib.sha512(password + pepper).digest(), bcrypt.gensalt(10))
https://en.wikipedia.org/wiki/Pepper_(cryptography)
Alternately, Dropbox uses AES256 using the pepper as the key as the last step. The benefit there is that you can easily change the pepper if it has been compromised.
https://blogs.dropbox.com/tech/2016/09/how-dropbox-securely-...