AirVPN vs Mullvad

Compare AirVPN and Mullvad on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: ExpressVPN, IVPN, Private Internet Access

Logo: AirVPN

AirVPN

Italy· VPN Services

Needs review

Strong European option when you need remote port forwarding, Dynamic DNS, and open-source clients. Skip for enterprise fleet VPN or ISO/SOC-led vendor risk — consider WireGuard mesh (e.g. Tailscale/NetBird) or audited privacy VPNs such as Mullvad.

EU-operatedOpen-source client (GPLv3)Remote port forwardingWireGuard + OpenVPNPrepaid access
Logo: Mullvad

Mullvad

Sweden· VPN Services

Needs review

Shortlist when you need a Swedish founder-owned privacy VPN with numbered accounts, GPL clients, RAM-only relays, and a dense public audit trail. Skip when you need dedicated IPs, remote port forwarding, or productized enterprise SSO/ISO packaging—consider Proton VPN for suite/free-tier onboarding or AirVPN for inbound ports.

EU-operated (Sweden)Numbered accountsGPL-3 clientsWireGuard + multihopPublic security auditsRAM-only relays
AirVPN vs Mullvad: Snapshot
FeatureLogo: AirVPNAirVPNLogo: MullvadMullvad
Country of originItalySweden
CategoryVPN ServicesVPN Services
Open sourceYesYes
Self-hostedNoNo
HeadquartersItalySweden
Legal entityAirVPN di Paolo Brini (also Air di Paolo Brini), PerugiaMullvad VPN AB (reg. no. 559238-4001); parent Amagicom AB
Governing lawItalian courts / EU private international law framing (per ToS)Swedish / EU law (GDPR); see Swedish legislation help page
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyMulti-region servers (EU and outside EU). Confirm exit-node policy if you need EU-only traffic.Multi-region VPN exits (EU and outside EU, including USA) on owned and rented colo (public provider list: e.g. M247, DataPacket, xtom, Zenlayer, Blix). RAM-only VPN OS. Account/payment personal data claimed stored only in EU/EEA. Payment subprocessors include Stripe and PayPal (US-group) plus SEB for bank/Swish when those methods are used; support email self-hosted by Mullvad since 2024.
Summary

Italian OpenVPN/WireGuard VPN with remote port forwarding, Dynamic DNS, and open-source Eddie clients—strong for technical privacy use, not enterprise fleet VPN.

Swedish privacy VPN with numbered accounts (no email), GPL-3 clients, RAM-only relays, and repeated third-party security audits—built for anonymity over enterprise packaging.

Tags
At a glance: AirVPN vs Mullvad
At a glanceLogo: AirVPNAirVPNLogo: MullvadMullvad
HQ / entityPerugia, Italy — AirVPN di Paolo Brini (sole proprietorship)Gothenburg, Sweden — Mullvad VPN AB (parent Amagicom AB)
ProtocolsOpenVPN, WireGuard; OpenVPN over SSH/SSL/TorWireGuard (primary), OpenVPN; bridges/obfuscation
ClientsEddie GPLv3 (desktop + Android); configs without GUIGPL-3 apps (Win/macOS/Linux/Android/iOS); WireGuard configs + CLI
Inbound portsUp to 5 reserved remote ports + optional *.airdns.org DDNSNot listed
SessionsFive simultaneous connections per accountFive simultaneous connections; shared exits only
Commercial modelPrepaid access (see vendor site for current plans)Prepaid access; no free tier; cash/crypto/card/PayPal (see site)
Independent auditNo public no-logs audit foundNot listed
B2B packagingSelf-serve ToS; no productized enterprise pack foundSelf-serve consumer ToS; no productized enterprise pack found
OwnershipNot listed100% founders Fredrik Stromberg and Daniel Berntsson
InfrastructureNot listedRAM-only VPN relays; multi-region colo (owned + rented)
Independent auditsNot listedMultiple public app/infra audits (Cure53, ROS, Assured, X41, …)
Key capabilities: AirVPN vs Mullvad
Key capabilitiesLogo: AirVPNAirVPNLogo: MullvadMullvad
EU-operatedYesYes
Open-source client (GPLv3)YesYes
Remote port forwardingYesNot listed
WireGuard + OpenVPNYesYes
Prepaid accessYesNot listed
Numbered accountsNot listedYes
Public security auditsNot listedYes
RAM-only relaysNot listedYes

AirVPN

  • Remote port forwarding and airdns.org DDNS

    Reserve up to five inbound remote ports (TCP/UDP) while a plan is active, optionally map to different local ports, and attach optional *.airdns.org names that follow the VPN exit IP—useful for P2P, seedboxes, and self-hosted services.

  • Open-source Eddie client with Network Lock

    Official GPLv3 client for major desktops and Android with firewall-based Network Lock (blocks traffic outside the tunnel), CLI, multi-provider mode, and hostile-network layering (SSH/SSL/Tor with AirVPN).

  • OpenVPN, WireGuard, and layered entry

    Choose WireGuard or OpenVPN; OpenVPN is available on multiple ports and can run over SSH, SSL, or Tor when middleboxes block or throttle plain VPN handshakes. Dual-stack IPv4/IPv6 and internal VPN DNS with optional block lists.

  • Minimal identity requirements

    Signup does not require real identity fields; email is optional for support. Payment processors handle their own data when used.

  • Transparent capacity and multi-session use

    Five simultaneous connections, free server switches, public live server load, and a stated minimum allocated bandwidth per session. Commercial access is prepaid—see the vendor site for current plans.

Mullvad

  • Numbered accounts (no email required)

    Signup generates a random account number with prepaid time remaining—no username, password, or email by default. Multiple people can share a number; recovery without the number is intentionally hard. Best when identity linkage is a risk; use cash or self-hosted crypto payments if you also want to avoid card/PayPal trails.

  • WireGuard-first apps with multihop and obfuscation

    Official clients for Windows, macOS, Linux, Android, and iOS use WireGuard with multihop, quantum-resistant tunnel options, DAITA traffic-analysis resistance, and bridge/obfuscation modes (Shadowsocks, UDP-over-TCP, QUIC, LWO on selected servers) for censored networks. Kill switch and tunnel DNS are on by default. Up to five simultaneous connections per account.

  • GPL-3 open-source clients

    Desktop and mobile client code is published under GPL-3 (github.com/mullvad/mullvadvpn-app) with public audit reports in-repo. WireGuard config export and a CLI support non-GUI deployments. iOS App Store distribution uses Apple's EULA rather than GPL for the shipped binary.

  • RAM-only relays and public audit trail

    VPN infrastructure completed migration to diskless/RAM-only operation so reboots discard volatile state. Multiple independent infrastructure and app assessments (Cure53, Radically Open Security, Assured, X41, and others) publish findings; Cure53's work explicitly looked for privacy-impacting flaws on sample relays.

  • DAITA and quantum-resistant tunnels

    DAITA (Defense Against AI-guided Traffic Analysis) adds padding/cover traffic patterns against modern traffic-analysis models. Quantum-resistant WireGuard tunnel modes are available across platforms and were rolled out as defaults on supported clients—useful for long-lived confidentiality threat models, at some performance cost.

Assurance & compliance: AirVPN vs Mullvad
Assurance & complianceLogo: AirVPNAirVPNLogo: MullvadMullvad
Independent no-logs / security audit
Not found

Privacy notice describes no mass-storage activity/IP logs; architecture claims are first-party only.

Verified

Public Cure53 infrastructure reports (e.g. 2021, 2024) and other third-party app/infra audits; Cure53 stated no PII on assessed systems and no anonymity compromise found in 2024 sample. April 2023 Swedish police search reported no customer data seized.

ISO 27001
Not found
Not found
SOC 2 / SOC 3
Not found
Not found
GDPR / EU data protection
Vendor claimed

EU (Italian) operator; privacy notice cites GDPR and related EU directives.

Vendor claimed

Swedish EU entity; privacy policy addresses GDPR rights and states personal data stored/processed only in EU/EEA.

US CLOUD Act exposure (indicative)
Vendor claimed

No known US parent from public research — indicative exposure low vs US-owned brands; multi-region exits still matter.

Partial

EU entity, founder-owned, no known US parent. Partial residual exposure: Stripe and PayPal as payment processors (US-group) when those methods are chosen; multi-region exits include US colo. Not legal advice.

Data processing agreement (B2B)
Not found

No productized enterprise DPA flow found; consumer ToS/privacy notice only.

Not found

Consumer privacy policy and ToS published; no productized enterprise DPA flow found on primary pages.

EU AI Act
Not applicable

VPN connectivity product; not an AI system under typical procurement framing.

Not applicable

VPN connectivity product; not an AI system under typical procurement framing (DAITA is a traffic-defense feature, not a general-purpose AI product).

Considerations & known limitations: AirVPN vs Mullvad
Considerations & known limitationsLogo: AirVPNAirVPNLogo: MullvadMullvad
Italian resident restriction
High

ToS and footer ban residents of Italy. Orgs with Italian-based staff cannot use AirVPN as a universal approved VPN; exclude that population or choose another vendor.

Not listed
No public independent no-logs audit
Medium

If vendor risk requires ISO/SOC or a no-logs audit letter, treat this as a gap until evidence is obtained offline.

Not listed
Multi-region exit nodes
Medium

Traffic can exit outside the EU depending on server choice. Strict residency policies need operational controls, not just EU HQ.

Not listed
Small operator / sole proprietorship
Medium

Long-running activist project with a small operating structure; set continuity and support expectations accordingly.

Not listed
US CLOUD Act (indicative)
Low

No known US parent from public research. Not a guarantee against other LE cooperation or non-EU exits.

Low

No known US parent. Residual exposure mainly via US payment SaaS and optional US exits—not ownership. Not a guarantee against other LE cooperation.

Consumer packaging, not enterprise control planeNot listed
Medium

Self-serve numbered accounts without productized SSO/MDM org admin, ISO/SOC claims, or click-through DPA. Procurement that requires those artifacts needs offline negotiation or another vendor.

US payment processors when card/PayPal usedNot listed
Medium

Stripe and PayPal process identity-bearing payment data outside the pure numbered-account model. Cash or self-hosted crypto reduces that trail; card/PayPal does not.

Multi-region exit nodes including non-EUNot listed
Medium

Traffic can leave the tunnel outside the EU depending on server choice. Strict residency policies need operational EU-only exit controls, not HQ branding alone.

No new port forwarding; no dedicated IPNot listed
Low

Remote port forwarding was disabled for new ports in 2023; dedicated IPs are not offered by design. Choose AirVPN or self-hosted WireGuard if inbound reachability is required.

Weak recovery without the account numberNot listed
Low

No email-based reset by default. Losing the number can mean losing access; treat it as a secret in team runbooks.

Fit

AirVPN

Best fit when

  • You need remote port forwarding and Dynamic DNS through a European-operated VPN
  • Open-source (GPLv3) clients and inspectable tunnel configs are a hard requirement
  • Users face ISP or state-level OpenVPN blocking and need SSH/SSL/Tor layering
  • Small technical teams or individuals comfortable with prepaid self-serve onboarding

Poor fit when

  • Italian-resident staff or contractors must use the service (contractually prohibited)
  • Security policy requires independent no-logs audit, ISO 27001, or SOC 2 from the VPN vendor
  • You need enterprise fleet controls (SSO/SAML, MDM-managed client, org-wide admin console)
  • Primary goal is streaming polish and maximum server footprint rather than inbound reachability

Consider instead when

  • When: You need enterprise fleet / zero-trust mesh connectivity

    Consider: Tailscale, NetBird, or self-hosted WireGuard

    Different product class: org network access vs consumer privacy VPN with inbound ports.

  • When: You prioritise audited no-logs / accountless anonymity over inbound ports

    Consider: Mullvad

    Mullvad is stronger on the public no-logs narrative; weaker on multi-port forwarding / airdns.org-style DDNS.

  • When: You want a free tier and a broader consumer privacy suite

    Consider: Proton VPN

Mullvad

Best fit when

  • You want accountless signup (no email) and optional cash/crypto payment trails
  • Open-source (GPL-3) clients and public infrastructure audit reports are procurement requirements
  • Threat model includes traffic analysis or long-term confidentiality (DAITA, quantum-resistant tunnels)
  • Users face VPN blocking and need bridge/obfuscation (Shadowsocks, QUIC, LWO, UDP-over-TCP)
  • European legal entity with no known US corporate parent is a hard filter

Poor fit when

  • You need remote port forwarding or dedicated IPs (port forwarding disabled; no dedicated IP product)
  • Security policy requires ISO 27001 or SOC 2 from the VPN vendor on day one
  • You need enterprise fleet controls (SSO/SAML, MDM org console) as the primary packaging
  • Primary goal is commercial streaming unblocking at maximum server count rather than anonymity
  • Staff cannot reliably store a 16-digit account number (weak recovery without email)

Consider instead when

  • When: You need inbound remote port forwarding or Dynamic DNS

    Consider: AirVPN

    Mullvad disabled new port forwards in 2023; AirVPN remains port-forward oriented.

  • When: You want a free tier plus mail/drive in one European privacy suite

    Consider: Proton VPN

    Proton is account-based with a broader product suite; Mullvad optimizes for minimal identity.

  • When: You need maximum consumer server footprint and streaming-oriented features

    Consider: NordVPN or Surfshark

    Trade a denser feature catalog for weaker accountless/audit differentiation vs Mullvad.

  • When: You need enterprise zero-trust mesh or org-wide device VPN with SSO

    Consider: Self-hosted WireGuard, Tailscale, or NetBird

    Different product class than consumer privacy VPN.

Open questions for due diligence

AirVPN

  • Can exit nodes be constrained to EU-only for all org devices, and how is that enforced?
  • Will the operator sign a DPA and provide a subprocessors list for a company account?
  • Is any independent security or no-logs assessment available under NDA?
  • Which payment processors receive identity data, and can crypto-only reduce that footprint for your policy?

Mullvad

  • Will Mullvad sign a B2B DPA and provide a written subprocessors schedule for a company purchase?
  • Can your org enforce EU-only exits (and block US/other regions) via MDM/config for all devices?
  • Is payment restricted to cash/crypto acceptable so Stripe/PayPal never see staff identity?
  • Does vendor risk accept public third-party audits in lieu of ISO 27001/SOC 2?