The strongest point of a non custodial wallet is also its sharpest edge: the private keys or recovery phrase are yours, so a platform outage, account restriction, or third-party compromise can't directly stop you from moving funds—because nobody else has to approve the transaction.
However, self-custody puts you in direct contact with the two attack classes that ruin real people: phishing and device compromise. If malware reads your clipboard, a fake support rep tricks you into revealing your recovery phrase, or you approve a malicious transaction, self-custody offers no rollback.
Custodial wallets invert that risk. On the one hand, mature custodians can invest in layered security, monitoring, and operational controls that most individuals won't replicate at home. On the other hand, you've accepted counterparty risk: your access is mediated by policies, compliance obligations, and centralized systems.
From a defensive standpoint, the question isn't which is more secure, but which failure mode is more survivable for you: personal key loss, or third-party lockout? Both are real risks; the right answer depends on your operational maturity and risk tolerance.