# TechPivot > TechPivot is a San Diego technology consultancy: security-first engineering > across AWS cloud, infrastructure, software, and AI, from architecture to > production. Mark Johnson, a security & infrastructure engineer, is the > disclosed principal. Selective by design: reviewing new engagements. ## Services - Security engineering & compliance: hardening, audit readiness, and control design for SOC 2, ISO/IEC 27001 and 42001, HIPAA, GDPR, NIST CSF, PCI DSS, and CIS. Frameworks we build for and audit against. - Cloud & platform engineering: AWS architecture, Terraform, Kubernetes, CI/CD, and platform automation, built to be operated, not just shipped. - AI engineering: production AI systems delivered with the same security-first discipline as the rest of the stack. - Fractional leadership: fractional CISO and fractional CTO engagements for teams that need senior judgment without a full-time hire. ## Identity - [TechPivot](https://www.techpivot.com/): services, engineering practice, and proof of work - [Mark Johnson on GitHub](https://github.com/virgofx): the principal's GitHub profile - [TechPivot on GitHub](https://github.com/techpivot): the organization's GitHub profile - [TechPivot on LinkedIn](https://www.linkedin.com/company/techpivot/): company page - [Contact](mailto:info@techpivot.com): info@techpivot.com ## Open source - [Terraform Module Releaser](https://github.com/techpivot/terraform-module-releaser): a GitHub Action for Terraform monorepos with semantic module versioning, per-module tags and releases, and wiki docs on every pull request. MIT-licensed, GHES-compatible, on the GitHub Marketplace, and in use by dozens of dependent repositories. - [Terraform Module Releaser case study](https://www.techpivot.com/work/terraform-module-releaser): how the Action works — the monorepo problem it solves, the release workflow it automates, and the operational details (tag format, wiki generation, GHES support) ## Markdown Every page on this site has a clean Markdown twin, derived from the same build that emits the HTML, for agents that prefer structured text. Request any page URL with `Accept: text/markdown` and the Markdown variant is returned in place of the HTML, at the same URL. Each page also advertises its twin directly, as a `Link: rel="alternate"; type="text/markdown"` response header. ## Security - [security.txt](https://www.techpivot.com/.well-known/security.txt): RFC 9116 vulnerability disclosure contact