Agreed. The real work is making the check actually run, and run before you need it. On my side that's a daily canary: it re-walks a random sample of already-confirmed daily anchors, recomputing each day's Merkle root from its stored leaves and comparing it to the anchored root — so one altered byte anywhere under that day breaks the match — plus a sibling that re-verifies a sample of the RFC 3161 timestamp tokens with openssl. Any discrepancy alarms me via Sentry. The point is to surface silent rot (at-rest corruption, a bad migration — the stuff fresh-fixture unit tests can't catch) while it's cheap, not the afternoon a customer pulls a proof. Honest limit: it samples rather than re-walking all of history nightly, so rot in an unsampled day sits until someone verifies a note from it.
But the check that actually matters doesn't run on my infrastructure at all. Each proof is self-contained — it carries the content preimages, the hash chain, and the Merkle path — so anyone (the /verify page, the in-browser verifier, or you offline) can re-derive that the content is intact and folds to the anchored root without trusting me, and the RFC 3161 token verifies against the TSA's public CA the same way. The one thing I don't vouch for is that the root is genuinely in Bitcoin: you confirm that yourself by running ots verify on the proof against the chain — which is the whole point, that for the part carrying the weight you check Bitcoin's word, not mine. What none of it claims is that the bytes were true when written; it proves unchanged-since, not honest-at-source.