Timestamps are embedded in the event payload which is great as it’s tamper proof - this is assuming you trust the pubkey, which in the case of user metadata is not a big risk.
Discussion
There is a NIP for opentimestamp integration but I’ve yet to hear of anyone using it.