The data store itself does not necessarily provide authenticity verification natively, so certification authorities would be required to validate the authenticity of the users, which in turn validates its input data, much like the root CAs, intermediate certs and server certs in a X.509-based PKI.
The competitor would have its identity tied to the data it inputs, so it wouldn't be able to impersonate the target company.