Rooiko software and purpose-built hardware working together in a field data workflow

HARDWARE SAFETY APPLIANCE

CacheCLEAR
Hardware meets software at the final barrier.

CacheCLEAR independently validates signed CardFLOW evidence, creates and proves a local cache, and rechecks the same physical card immediately before an authorised clear.

The Raspberry Pi appliance adds a separate hardware-controlled decision point. It validates organisation trust and live card facts, fails closed whenever a gate disagrees, removes only authorised filesystem contents—never formatting or repartitioning the card—and proves the permitted empty state before writing signed receipts.

Hardware safety appliance

Cache. Verify.
Control the clear.

  • Independent signed-evidence validation
  • BLAKE3-verified local cache
  • Immediate physical-card revalidation
  • Signed receipts and independent ledger

CacheCLEAR is currently available to approved testing organisations through the Rooiko Client Portal.

The hardware barrier

Every gate must
agree.

CacheCLEAR treats clearing as a separate, fail-closed workflow. Signed evidence begins the check, but live media, cache and immediate pre-clear state must still agree.

  1. 01

    Validate the ticket

    Check the CardFLOW signature, organisation certificate, trust state and current card facts.

  2. 02

    Build the cache

    Copy authorised media to local storage and verify it in full against the signed BLAKE3 proof.

  3. 03

    Recheck the barrier

    Confirm the uninterrupted cache seal and the same physical card immediately before clearing.

  4. 04

    Clear + receipt

    Remove only authorised contents, prove the permitted empty state and write matching signed receipts.

DEDICATED APPLIANCE

A separate Linux boundary

CacheCLEAR runs on a purpose-built Raspberry Pi appliance so the final decision is independently controlled rather than hidden inside the offload software.

CONTENT INTEGRITY

Full BLAKE3 cache proof

The local cache is verified against the signed source record before any clear can become eligible, then its seal is checked again at the final barrier.

FAIL-CLOSED CONTROL

Trust, media + receipt gates

Certificate, revocation, signature, card identity, cache or empty-state disagreement stops the workflow and preserves an explicit audit result.

BLAKE3

BLAKE3 answers: do these bytes match?

ED25519

Ed25519 answers: did this trusted signer produce this unchanged record?

Portable workflow evidence

Proof that travels
with the work.

The knkt.ko evidence layeris Rooiko's canonical, portable record of what existed, what completed, where verified data belongs and which exact source version the result describes.

BLAKE3 binds the record to the content. Ed25519 signatures let another trusted Rooiko tool verify who produced it and whether it has changed. The evidence is readable and portable—it is not an encrypted database, a copy of the media or a remote-control channel.

CacheCLEAR still validates organisation trust, the current physical media and its own cache before acting. A signed handoff carries proof forward; it never bypasses the next product's safety checks.

BUILT TO EXTEND

Because the record is canonical, signed and portable, it can support future indexing, server ingestion, operational dashboards and audit reporting—even when normal cloud services are unavailable.

Start a project

Let's build what
the job needs.

Bring the operating constraint. We will help turn it into a clear, useful first system.

Contact Rooiko