TrustZero by CertiPath offers enterprise-level continuous validation for Physical Access Control Systems (PACS) with continuous monitoring. It works with CertiPath’s TrustMonitor credential validation platform, performing 24/7 monitoring for the Public Key Infrastructure (PKI) trust fabric. TrustZero provides a single network location to handle validation queries for all credentials within a trust federation. When paired with TrustMonitor Enterprise, TrustZero validates credentials from local trust Certification Authorities (CAs) for intranets, internal networks, VPNs, non-person entities, IoT devices, and other items with certificates from private CAs. TrustZero consolidates all validation responses for PACS authentication, handling credentials from public, private, or both types of CAs. TrustZero meets the requirements of Executive Order 14028, which mandates civilian agencies to adopt cloud technology and Zero Trust Architecture. It communicates with every CA and checks its Certificate Revocation List (CRL) every 60 seconds. TrustZero complies with HSPD-12, FIPS 201, Federal Common Certificate Policy, PKIX Path Building, EO 14028/OMB 22-09/Zero Trust Configuration Options. TrustZero can be configured to support various business logic use cases. The VIP setting allows organizations to finely tune validation to match their risk tolerance for specific populations. The Extended Validity setting increases the duration a credential remains valid during network outages. Degraded Mode allows an organization to continue operations during widespread network or validation outages, treating certain credentials as valid based on their last known status.