Zum Inhalt springen
Unabhängig verifiziert · Quartalsweises Re-Audit
EU VETTED

Mullvad VPN

VERIFIZIERT
VPN · Sweden
Founded 2009 · mullvad.net ↗

Swedish founder-owned VPN (Mullvad VPN AB / Amagicom AB, Gothenburg, 2009), anonymous numbered accounts, Cure53-audited, flat €5/month.

Warum diese Bewertung?

Mullvad VPN, operated by Mullvad VPN AB (parent Amagicom AB) in Gothenburg, Sweden, founded March 2009 by Fredrik Strömberg and Daniel Berntsson and 100% founder-owned with no PE/VC/parent-company on record — anonymous numbered accounts (no email, no username, no personal data), Cure53-audited no-logs policy (2018 apps, 2020 infrastructure, 2024 apps + WireGuard/OpenVPN relay code), flat €5/month price unchanged since 2009, open-source apps, cash/Monero accepted. Rated 3/5: an otherwise gold-standard privacy profile under Swedish EU jurisdiction, but Mullvad does not publish a publicly accessible DPA — the anonymous-account architecture means no traditional controller-to-processor relationship is established, and only a privacy policy and no-logging data policy are available; under EU Vetted''s rubric a DPA that small EU buyers cannot self-serve caps the score at 3/5.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About Mullvad VPN

Mullvad VPN is one of the most-cited privacy-maximalist VPN providers in the world, operated by Mullvad VPN AB and parent **Amagicom AB** in Gothenburg, Sweden (Box 53049, 400 14 Gothenburg). Launched in March 2009 by Fredrik Strömberg and Daniel Berntsson, the company remains **100% founder-owned** — there is no private equity, no venture-capital backing, no parent conglomerate, and no acquisition pressure. Mullvad's product philosophy is built on a single radical idea: a VPN can be useful without ever collecting customer identity. The account system reflects this — accounts are random numbered tokens; there is no email address, no username, no password recovery, no personal-data field at signup. Users can generate as many accounts as they wish on the website at any time. The no-logs commitment is more rigorous than most competitors and externally verified. Mullvad does not log activity, traffic, DNS queries, connection events, IP addresses, bandwidth, or timestamps. **Cure53 — the German cybersecurity firm — has audited Mullvad multiple times**: a 2018 penetration test of the macOS / Windows / Linux apps; a 2020 infrastructure audit; a 2024 desktop-application audit that rated security "high"; and a 2024 audit of the WireGuard and OpenVPN relay-code that found no PII retention or privacy leaks (only two low- and medium-severity issues, both unrelated to logging). Nginx access logs on web infrastructure are deleted after 5 minutes without IPs; support emails are auto-deleted after 70 days; cash-payment envelopes are shredded after processing; cryptocurrency transaction records are deleted after 20 days. All apps are open-source on GitHub. Pricing is famously simple and never-changing: **€5/month flat, regardless of commitment length** — 1 month, 1 year, or 1 decade, all the same monthly rate. The company explicitly does not run sales, holiday promotions, "Black Friday" discounts, or affiliate programmes — these are excluded as a matter of principle to avoid marketing-influence bias. Payment methods include cash (mail), cryptocurrencies (Bitcoin, Bitcoin Cash, Monero with a 10% discount), credit cards, PayPal, and regional bank transfers. 14-day money-back guarantee (except cash payments). 5 simultaneous devices. No port forwarding. Best fit: privacy-maximalist users worldwide who specifically want anonymous-account architecture and a Swedish-EU-jurisdiction founder-owned provider — and any procurement-grade buyer for whom "ownership simplicity + audited no-logs" beats feature breadth.
SUB-PROCESSORS

Unterauftragsverarbeiter-Karte · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Rahmenwerke & Zertifizierungen · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-18).
FEATURES

Funktionsmatrix

INTEGRATION & ACCESS
REST API No
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Preise & Tarife

KOSTENPFLICHTIG
ab €5/Monat
Preisseite ansehen ↗
PUBLIC DOCUMENTS

Öffentliche Dokumente

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    mullvad.net/en…
    Open ↗
  • Terms of Service
    mullvad.net/en…
    Open ↗
ALTERNATIVES

Alternativen in dieser Kategorie