A separate Linux boundary
CacheCLEAR runs on a purpose-built Raspberry Pi appliance so the final decision is independently controlled rather than hidden inside the offload software.

HARDWARE SAFETY APPLIANCE
The Raspberry Pi appliance adds a separate hardware-controlled decision point. It validates organisation trust and live card facts, fails closed whenever a gate disagrees, removes only authorised filesystem contents—never formatting or repartitioning the card—and proves the permitted empty state before writing signed receipts.

Hardware safety appliance
CacheCLEAR is currently available to approved testing organisations through the Rooiko Client Portal.
The hardware barrier
CacheCLEAR treats clearing as a separate, fail-closed workflow. Signed evidence begins the check, but live media, cache and immediate pre-clear state must still agree.
Check the CardFLOW signature, organisation certificate, trust state and current card facts.
Copy authorised media to local storage and verify it in full against the signed BLAKE3 proof.
Confirm the uninterrupted cache seal and the same physical card immediately before clearing.
Remove only authorised contents, prove the permitted empty state and write matching signed receipts.
CacheCLEAR runs on a purpose-built Raspberry Pi appliance so the final decision is independently controlled rather than hidden inside the offload software.
The local cache is verified against the signed source record before any clear can become eligible, then its seal is checked again at the final barrier.
Certificate, revocation, signature, card identity, cache or empty-state disagreement stops the workflow and preserves an explicit audit result.
BLAKE3 answers: do these bytes match?
ED25519Ed25519 answers: did this trusted signer produce this unchanged record?
Portable workflow evidence
The knkt.ko evidence layeris Rooiko's canonical, portable record of what existed, what completed, where verified data belongs and which exact source version the result describes.
BLAKE3 binds the record to the content. Ed25519 signatures let another trusted Rooiko tool verify who produced it and whether it has changed. The evidence is readable and portable—it is not an encrypted database, a copy of the media or a remote-control channel.
CacheCLEAR still validates organisation trust, the current physical media and its own cache before acting. A signed handoff carries proof forward; it never bypasses the next product's safety checks.
Because the record is canonical, signed and portable, it can support future indexing, server ingestion, operational dashboards and audit reporting—even when normal cloud services are unavailable.
Start a project
Bring the operating constraint. We will help turn it into a clear, useful first system.
Contact Rooiko