Alby operates on a self-custodial model where users control their own private keys. Alby Hub is explicitly designed so that Alby never has access to user funds - you run your own Lightning node either self-hosted or via Alby Cloud with encrypted keys. All products are open-source, enabling community verification of the codebase across repositories.
The platform implements OAuth 2.0 for API security, GDPR-compliant data handling, and employees are bound by confidentiality agreements. Technical and organizational measures protect against data risks, with log files retained for 60 days for security and incident resolution. The browser extension secures key storage and Nostr interactions with user-controlled backups.
Alby has maintained a positive reputation in the Bitcoin and Nostr communities, with users on BitcoinTalk and app stores affirming its legitimacy for Lightning usage. No security incidents have been reported in public sources.