If we're talking about using Amber, then yes. That uses either NIP-55 to sign for apps that are locally installed, such as Amethyst, or NIP-46 to sign remotely, usually for web-apps. In both of those cases, Amber has to have the private key stored locally on the device, or "hot" as you put it.