CyberGhost VPN vs Mullvad

Compare CyberGhost VPN and Mullvad on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: ExpressVPN

Logo: CyberGhost VPN

CyberGhost VPN

Romania· VPN Services

Needs review

Shortlist CyberGhost when you want a Romanian-entity consumer VPN with polished multi-device apps, streaming/P2P server profiles, NoSpy HQ servers, and repeated Deloitte no-logs assurance. Skip when you need holding-company independence, a published B2B DPA/subprocessor pack, or minimal US SaaS in the account path—consider Mullvad or Proton VPN instead.

Romanian entityWireGuard + OpenVPNNoSpy HQ serversDeloitte no-logs (claimed)7 simultaneous devicesStreaming/P2P profiles
Logo: Mullvad

Mullvad

Sweden· VPN Services

Needs review

Shortlist when you need a Swedish founder-owned privacy VPN with numbered accounts, GPL clients, RAM-only relays, and a dense public audit trail. Skip when you need dedicated IPs, remote port forwarding, or productized enterprise SSO/ISO packaging—consider Proton VPN for suite/free-tier onboarding or AirVPN for inbound ports.

EU-operated (Sweden)Numbered accountsGPL-3 clientsWireGuard + multihopPublic security auditsRAM-only relays
CyberGhost VPN vs Mullvad: Snapshot
FeatureLogo: CyberGhost VPNCyberGhost VPNLogo: MullvadMullvad
Country of originRomaniaSweden
CategoryVPN ServicesVPN Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersRomaniaSweden
Legal entityCyberGhost S.R.L. (J40/1278/2011; 68 Polona St., District 1, Bucharest)Mullvad VPN AB (reg. no. 559238-4001); parent Amagicom AB
Governing lawRomania / EU (entity); group policies under Kape Technologies PLC (UK)Swedish / EU law (GDPR); see Swedish legislation help page
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVPN egress: vendor-operated NoSpy servers at Romanian HQ plus self-owned colocated servers in third-party data centers worldwide (100 countries marketed). Account/billing/support/analytics path per privacy policy includes Cleverbridge (DE), Stripe, PayPal/Braintree, Zendesk, Google Analytics, AppsFlyer, Mouseflow, Iterable, and related processors—several US-group. Full infra subprocessor register not published as a single procurement table.Multi-region VPN exits (EU and outside EU, including USA) on owned and rented colo (public provider list: e.g. M247, DataPacket, xtom, Zenlayer, Blix). RAM-only VPN OS. Account/payment personal data claimed stored only in EU/EEA. Payment subprocessors include Stripe and PayPal (US-group) plus SEB for bank/Swish when those methods are used; support email self-hosted by Mullvad since 2024.
Summary

Romanian consumer VPN from CyberGhost S.R.L. with WireGuard/OpenVPN, NoSpy HQ servers, streaming/P2P profiles, and Deloitte no-logs audits—under Kape Technologies PLC.

Swedish privacy VPN with numbered accounts (no email), GPL-3 clients, RAM-only relays, and repeated third-party security audits—built for anonymity over enterprise packaging.

Tags
At a glance: CyberGhost VPN vs Mullvad
At a glanceLogo: CyberGhost VPNCyberGhost VPNLogo: MullvadMullvad
HQ / entityCyberGhost S.R.L., Bucharest, RomaniaGothenburg, Sweden — Mullvad VPN AB (parent Amagicom AB)
Parent groupKape Technologies PLC (UK)Not listed
ProtocolsWireGuard, OpenVPN, IKEv2WireGuard (primary), OpenVPN; bridges/obfuscation
Network (vendor)100 countries, 120+ locationsNot listed
DevicesUp to 7 simultaneousNot listed
Open source / self-hostNo (proprietary apps; not self-hosted)Not listed
Commercial modelSubscription; optional Dedicated IP; money-back window on long-term plansPrepaid access; no free tier; cash/crypto/card/PayPal (see site)
OwnershipNot listed100% founders Fredrik Stromberg and Daniel Berntsson
ClientsNot listedGPL-3 apps (Win/macOS/Linux/Android/iOS); WireGuard configs + CLI
SessionsNot listedFive simultaneous connections; shared exits only
InfrastructureNot listedRAM-only VPN relays; multi-region colo (owned + rented)
Independent auditsNot listedMultiple public app/infra audits (Cure53, ROS, Assured, X41, …)
B2B packagingNot listedSelf-serve consumer ToS; no productized enterprise pack found
Key capabilities: CyberGhost VPN vs Mullvad
Key capabilitiesLogo: CyberGhost VPNCyberGhost VPNLogo: MullvadMullvad
Romanian entityYesNot listed
WireGuard + OpenVPNYesYes
NoSpy HQ serversYesNot listed
Deloitte no-logs (claimed)YesNot listed
7 simultaneous devicesYesNot listed
Streaming/P2P profilesYesNot listed
EU-operated (Sweden)Not listedYes
Numbered accountsNot listedYes
GPL-3 clientsNot listedYes
Public security auditsNot listedYes
RAM-only relaysNot listedYes

CyberGhost VPN

  • NoSpy servers inside Romanian HQ

    Self-owned servers CyberGhost says it operates end-to-end at its Bucharest headquarters with staff-only physical access—for higher physical-control privacy than third-party facilities. Colocated self-owned servers elsewhere cover non-RO egress. NoSpy access may depend on plan length (not monthly-only).

  • Streaming, P2P, and gaming server profiles

    Labeled optimized servers for streaming, torrenting, and gaming across a network marketed at 100 countries and 120+ locations. Reduces trial-and-error for households; unblocking success still varies by platform and changes over time.

  • WireGuard, OpenVPN, and IKEv2 with kill switch

    Choose WireGuard for speed, OpenVPN for flexibility, or IKEv2 on supported platforms. Automatic kill switch, DNS leak protection, RAM-only server claims, and split tunneling address common tunnel-failure and mixed-app workflows.

  • Multi-platform apps and seven simultaneous devices

    Native apps for major desktops and mobiles, extensions, selected TVs/Fire Stick, and router setup. One subscription covers up to seven concurrent connections—fit for mixed family fleets, not unlimited-device competitors.

  • Token-based Dedicated IP add-on

    Optional static IP sold separately; company describes a token design so operational systems do not map the fixed address to the account the way naive dedicated-IP setups do. Useful against CAPTCHA-heavy sites; still a paid add-on, not core anonymity.

  • Published Deloitte no-logs audits and transparency reports

    Repeated Deloitte Audit Romania ISAE 3000-style reviews of no-logs configuration (including dedicated-IP token handling), with public report links, plus quarterly legal-request transparency reports. Assurance scope is configuration/operations—not a guarantee of absolute anonymity.

Mullvad

  • Numbered accounts (no email required)

    Signup generates a random account number with prepaid time remaining—no username, password, or email by default. Multiple people can share a number; recovery without the number is intentionally hard. Best when identity linkage is a risk; use cash or self-hosted crypto payments if you also want to avoid card/PayPal trails.

  • WireGuard-first apps with multihop and obfuscation

    Official clients for Windows, macOS, Linux, Android, and iOS use WireGuard with multihop, quantum-resistant tunnel options, DAITA traffic-analysis resistance, and bridge/obfuscation modes (Shadowsocks, UDP-over-TCP, QUIC, LWO on selected servers) for censored networks. Kill switch and tunnel DNS are on by default. Up to five simultaneous connections per account.

  • GPL-3 open-source clients

    Desktop and mobile client code is published under GPL-3 (github.com/mullvad/mullvadvpn-app) with public audit reports in-repo. WireGuard config export and a CLI support non-GUI deployments. iOS App Store distribution uses Apple's EULA rather than GPL for the shipped binary.

  • RAM-only relays and public audit trail

    VPN infrastructure completed migration to diskless/RAM-only operation so reboots discard volatile state. Multiple independent infrastructure and app assessments (Cure53, Radically Open Security, Assured, X41, and others) publish findings; Cure53's work explicitly looked for privacy-impacting flaws on sample relays.

  • DAITA and quantum-resistant tunnels

    DAITA (Defense Against AI-guided Traffic Analysis) adds padding/cover traffic patterns against modern traffic-analysis models. Quantum-resistant WireGuard tunnel modes are available across platforms and were rolled out as defaults on supported clients—useful for long-lived confidentiality threat models, at some performance cost.

Assurance & compliance: CyberGhost VPN vs Mullvad
Assurance & complianceLogo: CyberGhost VPNCyberGhost VPNLogo: MullvadMullvad
Independent no-logs audit (Deloitte)
Vendor claimed

Public Deloitte Audit Romania ISAE 3000-style assurance engagements (2022, 2024; third cycle announced Feb 2026 with downloadable report). Scope: configuration/operations vs no-logs description.

Verified

Public Cure53 infrastructure reports (e.g. 2021, 2024) and other third-party app/infra audits; Cure53 stated no PII on assessed systems and no anonymity compromise found in 2024 sample. April 2023 Swedish police search reported no customer data seized.

ISO 27001
Vendor claimed

Privacy policy states QSCert ISO 27001 (and ISO 9001) ISMS certification since 2012 with yearly renewal. Confirm current certificate validity independently.

Not found
SOC 2 / SOC 3
Not found

No SOC 2/3 report identified on primary trust/legal pages reviewed.

Not found
GDPR / EU data protection
Vendor claimed

EU (Romanian) controller CyberGhost S.R.L.; privacy policy describes GDPR rights, DPO contact, and lawful bases. Not a legal compliance certificate.

Vendor claimed

Swedish EU entity; privacy policy addresses GDPR rights and states personal data stored/processed only in EU/EEA.

US CLOUD Act exposure (indicative)
Partial

Romanian entity, no known US parent; UK group (Kape). Account path uses US-group SaaS (Stripe, Zendesk, Google Analytics, AppsFlyer, etc.). Medium/partial—not low. Not legal advice.

Partial

EU entity, founder-owned, no known US parent. Partial residual exposure: Stripe and PayPal as payment processors (US-group) when those methods are chosen; multi-region exits include US colo. Not legal advice.

Data processing agreement (B2B)
Not found

Consumer-focused public site; no clear self-serve B2B DPA portal found during research. Request under contract if needed.

Not found

Consumer privacy policy and ToS published; no productized enterprise DPA flow found on primary pages.

EU AI Act
Not applicable

Consumer VPN connectivity product; not an AI system offering.

Not applicable

VPN connectivity product; not an AI system under typical procurement framing (DAITA is a traffic-defense feature, not a general-purpose AI product).

Considerations & known limitations: CyberGhost VPN vs Mullvad
Considerations & known limitationsLogo: CyberGhost VPNCyberGhost VPNLogo: MullvadMullvad
Part of multi-brand Kape VPN group
Medium

Ultimate holding company Kape Technologies PLC also operates ExpressVPN and Private Internet Access. Switching among Kape brands does not diversify group-level ownership risk.

Not listed
US-group SaaS for account and support data
Medium

Privacy policy discloses Stripe, Zendesk, Google Analytics, AppsFlyer, and similar processors for non-tunnel data. Separates VPN no-logs claims from account/support transfer risk.

Not listed
Most locations are colocated, not NoSpy
Low

Only NoSpy servers sit in company HQ. Global city coverage relies on third-party data centers even when hardware is self-owned—relevant for physical-access threat models.

Not listed
Thin public enterprise procurement pack
Medium

No public B2B DPA/subprocessor schedule found for fleet buyers. Consumer money-back and app UX do not replace contractual diligence.

Not listed
Streaming unblocking is not guaranteed
Low

Optimized server labels help users, but platform detection changes frequently. Do not treat marketing unblocking claims as durable SLA.

Not listed
Consumer packaging, not enterprise control planeNot listed
Medium

Self-serve numbered accounts without productized SSO/MDM org admin, ISO/SOC claims, or click-through DPA. Procurement that requires those artifacts needs offline negotiation or another vendor.

US payment processors when card/PayPal usedNot listed
Medium

Stripe and PayPal process identity-bearing payment data outside the pure numbered-account model. Cash or self-hosted crypto reduces that trail; card/PayPal does not.

Multi-region exit nodes including non-EUNot listed
Medium

Traffic can leave the tunnel outside the EU depending on server choice. Strict residency policies need operational EU-only exit controls, not HQ branding alone.

No new port forwarding; no dedicated IPNot listed
Low

Remote port forwarding was disabled for new ports in 2023; dedicated IPs are not offered by design. Choose AirVPN or self-hosted WireGuard if inbound reachability is required.

Weak recovery without the account numberNot listed
Low

No email-based reset by default. Losing the number can mean losing access; treat it as a secret in team runbooks.

US CLOUD Act residual path (indicative)Not listed
Low

No known US parent. Residual exposure mainly via US payment SaaS and optional US exits—not ownership. Not a guarantee against other LE cooperation.

Fit

CyberGhost VPN

Best fit when

  • Households and individuals needing easy apps across phones, PCs, TVs, and up to seven concurrent devices
  • Users who prioritize streaming- or P2P-labeled servers over manual protocol tinkering
  • Buyers who want a Romanian operating company plus published Deloitte no-logs assurance and transparency reports
  • Travelers needing kill switch, split tunneling, and quick public-Wi-Fi protection
  • Teams evaluating consumer VPN shortlists where UX and server coverage outweigh pure minimalism

Poor fit when

  • Organizations that require a published B2B DPA, subprocessor schedule, and enterprise fleet controls out of the box
  • Evaluators who reject multi-brand holding groups (Kape also owns ExpressVPN and PIA)
  • Buyers insisting on zero US-group SaaS for payments, support, or analytics
  • Power users who need port forwarding, deep open-source client control, or anonymous no-email accounts (prefer Mullvad/AirVPN-class tools)
  • Procurement policies that disallow UK-group ownership regardless of EU operating entity

Consider instead when

  • When: You want hard privacy minimalism, anonymous accounts, and open-source focus

    Consider: Mullvad

    Swedish VPN; weaker streaming-marketing packaging, stronger anonymity defaults

  • When: You want a Swiss/EU privacy suite with free tier and open-source clients

    Consider: Proton VPN

    Different product family; less multi-brand VPN conglomerate context

  • When: You need technical port forwarding, DDNS, and enthusiast configuration depth

    Consider: AirVPN

    Italian technical VPN; not a consumer streaming specialist

  • When: You specifically want the premium Kape-family brand with different protocol positioning

    Consider: ExpressVPN

    Same ultimate group (Kape); ownership risk is not diversified by switching brands inside the group

Mullvad

Best fit when

  • You want accountless signup (no email) and optional cash/crypto payment trails
  • Open-source (GPL-3) clients and public infrastructure audit reports are procurement requirements
  • Threat model includes traffic analysis or long-term confidentiality (DAITA, quantum-resistant tunnels)
  • Users face VPN blocking and need bridge/obfuscation (Shadowsocks, QUIC, LWO, UDP-over-TCP)
  • European legal entity with no known US corporate parent is a hard filter

Poor fit when

  • You need remote port forwarding or dedicated IPs (port forwarding disabled; no dedicated IP product)
  • Security policy requires ISO 27001 or SOC 2 from the VPN vendor on day one
  • You need enterprise fleet controls (SSO/SAML, MDM org console) as the primary packaging
  • Primary goal is commercial streaming unblocking at maximum server count rather than anonymity
  • Staff cannot reliably store a 16-digit account number (weak recovery without email)

Consider instead when

  • When: You need inbound remote port forwarding or Dynamic DNS

    Consider: AirVPN

    Mullvad disabled new port forwards in 2023; AirVPN remains port-forward oriented.

  • When: You want a free tier plus mail/drive in one European privacy suite

    Consider: Proton VPN

    Proton is account-based with a broader product suite; Mullvad optimizes for minimal identity.

  • When: You need maximum consumer server footprint and streaming-oriented features

    Consider: NordVPN or Surfshark

    Trade a denser feature catalog for weaker accountless/audit differentiation vs Mullvad.

  • When: You need enterprise zero-trust mesh or org-wide device VPN with SSO

    Consider: Self-hosted WireGuard, Tailscale, or NetBird

    Different product class than consumer privacy VPN.

Open questions for due diligence

CyberGhost VPN

  • Will CyberGhost sign a B2B DPA and provide a current subprocessor list with locations for support, billing, and analytics?
  • What is the current ISO 27001 certificate number, scope, and expiry (beyond privacy-policy wording)?
  • Which personal data categories, if any, are accessible to Kape group entities outside CyberGhost S.R.L. in production operations?
  • For NoSpy-only threat models, what fraction of traffic and which use cases still require colocated non-RO egress?

Mullvad

  • Will Mullvad sign a B2B DPA and provide a written subprocessors schedule for a company purchase?
  • Can your org enforce EU-only exits (and block US/other regions) via MDM/config for all devices?
  • Is payment restricted to cash/crypto acceptable so Stripe/PayPal never see staff identity?
  • Does vendor risk accept public third-party audits in lieu of ISO 27001/SOC 2?