I mean, that's what Certificate Authorities are.
...Though, that being said, the original idea behind X.509 certificates was quite different: you [the domain sysop] would use your critical thinking to pick a root CA you trust, and configure your machines to only use that single root CA; and then that root CA would either directly sign [code, server, client] certs they trust, or would cross-sign other CAs' root certs to indicate that they trust them to delegate to them. Essentially, a domain (like a corporation or university) would have a business relationship with a particular CA, who would "do their critical thinking for them" (and would also be legally liable if they failed to do that critical thinking.)
For X.509, we pretty much immediately moved away from that world, though, to a world where each application (e.g. OS HTTP API, third-party web browser, etc.) is acting as a root CA, you endorse that root CA by installing/using the app, and then the app devs make decisions on what to trust/delegate trust to.
Which is kind of what's happening here: you use your critical thinking to install an app/OS, whose devs are then your "truth source." Sadly, though, this isn't a business relationship where they can be sued for failure to deliver quality content through that channel. (For contrast, where a customer is paying a business for "truth", see: investment newsletters.)