F-Secure FREEDOME VPN vs Mullvad

Compare F-Secure FREEDOME VPN and Mullvad on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: ExpressVPN

Logo: F-Secure FREEDOME VPN

F-Secure FREEDOME VPN

Finland· VPN Services

Needs review

Shortlist when you want a simple Finnish consumer VPN from an established security vendor (now branded F-Secure VPN), multi-device apps, and suite packaging. Skip when you need audited no-logs, anonymous accounts, or an infrastructure path free of US-linked VPN partners—consider Mullvad or Proton VPN instead.

Finnish HQ (Nasdaq Helsinki)Consumer multi-device VPNAuto public Wi-Fi protectionKill switch (Win/Mac/Android)WireGuard on new stackISO 27001 (company, claimed)
Logo: Mullvad

Mullvad

Sweden· VPN Services

Needs review

Shortlist when you need a Swedish founder-owned privacy VPN with numbered accounts, GPL clients, RAM-only relays, and a dense public audit trail. Skip when you need dedicated IPs, remote port forwarding, or productized enterprise SSO/ISO packaging—consider Proton VPN for suite/free-tier onboarding or AirVPN for inbound ports.

EU-operated (Sweden)Numbered accountsGPL-3 clientsWireGuard + multihopPublic security auditsRAM-only relays
F-Secure FREEDOME VPN vs Mullvad: Snapshot
FeatureLogo: F-Secure FREEDOME VPNF-Secure FREEDOME VPNLogo: MullvadMullvad
Country of originFinlandSweden
CategoryVPN ServicesVPN Services
Open sourceNoYes
Self-hostedNoNo
HeadquartersFinlandSweden
Legal entityF-Secure Corporation (F-Secure Oyj), Tammasaarenkatu 7, 00180 Helsinki, FinlandMullvad VPN AB (reg. no. 559238-4001); parent Amagicom AB
Governing lawNot listedSwedish / EU law (GDPR); see Swedish legislation help page
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyFinnish consumer controller (F-Secure Corporation). New VPN feature delivered with third-party Pango (US-based Pango Group / Point Wild family; also related non-US entities). Older OpenVPN/IPSec path described separately. Sensitive customer data stated as stored in Finland/EEA under F-Secure control where applicable; global operations, SCCs, and EU–U.S. Data Privacy Framework also described. E-store reseller Cleverbridge GmbH. Full public gateway subprocessor/region matrix not published.Multi-region VPN exits (EU and outside EU, including USA) on owned and rented colo (public provider list: e.g. M247, DataPacket, xtom, Zenlayer, Blix). RAM-only VPN OS. Account/payment personal data claimed stored only in EU/EEA. Payment subprocessors include Stripe and PayPal (US-group) plus SEB for bank/Swish when those methods are used; support email self-hosted by Mullvad since 2024.
Summary

Finnish consumer VPN (historically FREEDOME, now F-Secure VPN) for encrypted browsing, IP hiding, and automatic public Wi-Fi protection from F-Secure Corporation in Helsinki.

Swedish privacy VPN with numbered accounts (no email), GPL-3 clients, RAM-only relays, and repeated third-party security audits—built for anonymity over enterprise packaging.

Tags
At a glance: F-Secure FREEDOME VPN vs Mullvad
At a glanceLogo: F-Secure FREEDOME VPNF-Secure FREEDOME VPNLogo: MullvadMullvad
HQHelsinki, FinlandNot listed
Legal entityF-Secure Corporation (F-Secure Oyj)Not listed
Product statusFREEDOME rebranded to F-Secure VPN; still soldNot listed
DeploymentConsumer SaaS apps (not self-hosted)Not listed
Account modelMy F-Secure registration requiredNot listed
Server footprintVirtual locations in 20+ countries (vendor claim)Not listed
New VPN partnerPango / Point Wild group (US-linked)Not listed
Commercial modelPaid multi-device subscription + trial/money-backPrepaid access; no free tier; cash/crypto/card/PayPal (see site)
HQ / entityNot listedGothenburg, Sweden — Mullvad VPN AB (parent Amagicom AB)
OwnershipNot listed100% founders Fredrik Stromberg and Daniel Berntsson
ProtocolsNot listedWireGuard (primary), OpenVPN; bridges/obfuscation
ClientsNot listedGPL-3 apps (Win/macOS/Linux/Android/iOS); WireGuard configs + CLI
SessionsNot listedFive simultaneous connections; shared exits only
InfrastructureNot listedRAM-only VPN relays; multi-region colo (owned + rented)
Independent auditsNot listedMultiple public app/infra audits (Cure53, ROS, Assured, X41, …)
B2B packagingNot listedSelf-serve consumer ToS; no productized enterprise pack found
Key capabilities: F-Secure FREEDOME VPN vs Mullvad
Key capabilitiesLogo: F-Secure FREEDOME VPNF-Secure FREEDOME VPNLogo: MullvadMullvad
Finnish HQ (Nasdaq Helsinki)YesNot listed
Consumer multi-device VPNYesNot listed
Auto public Wi-Fi protectionYesNot listed
Kill switch (Win/Mac/Android)YesNot listed
WireGuard on new stackYesNot listed
ISO 27001 (company, claimed)YesNot listed
EU-operated (Sweden)Not listedYes
Numbered accountsNot listedYes
GPL-3 clientsNot listedYes
WireGuard + multihopNot listedYes
Public security auditsNot listedYes
RAM-only relaysNot listedYes

F-Secure FREEDOME VPN

  • One-click personal VPN with unlimited data

    Consumer apps connect with a single control and market unlimited bandwidth for browsing, downloads, and general use. Aimed at non-technical households rather than admin-tunable gateway fleets. Requires a My F-Secure account to activate and manage devices.

  • Automatic public Wi-Fi protection and trusted-network bypass

    Detects untrusted/public Wi-Fi and can secure traffic without manual per-hotspot setup. On Android and Windows, trusted networks can bypass the tunnel so home/LAN devices stay reachable. Best for travelers and café users, not for policy-managed corporate SSIDs.

  • Kill switch on Windows, Mac, and Android

    When enabled, the kill switch can block internet access if the VPN drops, reducing clearnet IP/DNS leaks during reconnects. Availability is platform-specific (documented for Windows, Mac, Android—not presented as universal across every OS feature parity).

  • Virtual locations in 20+ countries

    Choose gateways in more than twenty countries, sometimes with multiple cities, to change apparent IP location for privacy and basic geo-access. Server footprint is smaller than mega-VPN networks; treat streaming reliability as verify-yourself, not a guaranteed specialty.

  • Protocol stacks including WireGuard on the new VPN

    Privacy docs describe an older path (OpenVPN, IPSec/IKEv2) and a newer path (Hydra, WireGuard, IPSec). The new path is delivered with third-party provider Pango—confirm which stack your app build uses under Settings before assuming F-Secure-only infrastructure.

Mullvad

  • Numbered accounts (no email required)

    Signup generates a random account number with prepaid time remaining—no username, password, or email by default. Multiple people can share a number; recovery without the number is intentionally hard. Best when identity linkage is a risk; use cash or self-hosted crypto payments if you also want to avoid card/PayPal trails.

  • WireGuard-first apps with multihop and obfuscation

    Official clients for Windows, macOS, Linux, Android, and iOS use WireGuard with multihop, quantum-resistant tunnel options, DAITA traffic-analysis resistance, and bridge/obfuscation modes (Shadowsocks, UDP-over-TCP, QUIC, LWO on selected servers) for censored networks. Kill switch and tunnel DNS are on by default. Up to five simultaneous connections per account.

  • GPL-3 open-source clients

    Desktop and mobile client code is published under GPL-3 (github.com/mullvad/mullvadvpn-app) with public audit reports in-repo. WireGuard config export and a CLI support non-GUI deployments. iOS App Store distribution uses Apple's EULA rather than GPL for the shipped binary.

  • RAM-only relays and public audit trail

    VPN infrastructure completed migration to diskless/RAM-only operation so reboots discard volatile state. Multiple independent infrastructure and app assessments (Cure53, Radically Open Security, Assured, X41, and others) publish findings; Cure53's work explicitly looked for privacy-impacting flaws on sample relays.

  • DAITA and quantum-resistant tunnels

    DAITA (Defense Against AI-guided Traffic Analysis) adds padding/cover traffic patterns against modern traffic-analysis models. Quantum-resistant WireGuard tunnel modes are available across platforms and were rolled out as defaults on supported clients—useful for long-lived confidentiality threat models, at some performance cost.

Assurance & compliance: F-Secure FREEDOME VPN vs Mullvad
Assurance & complianceLogo: F-Secure FREEDOME VPNF-Secure FREEDOME VPNLogo: MullvadMullvad
Independent security / no-logs audit
Not found

Vendor privacy notice describes no destination-connection logs plus 90-day operational session logs; no public third-party no-logs audit PDF found for this VPN.

Verified

Public Cure53 infrastructure reports (e.g. 2021, 2024) and other third-party app/infra audits; Cure53 stated no PII on assessed systems and no anonymity compromise found in 2024 sample. April 2023 Swedish police search reported no customer data seized.

ISO 27001
Vendor claimed

Company financial/sustainability materials state F-Secure received ISO 27001 covering company operations (reported from late 2024). Re-verify certificate scope for the VPN service.

Not found
SOC 2 / SOC 3
Not found

No public SOC 2/3 report located for the consumer VPN service during research.

Not found
GDPR / EU data protection
Vendor claimed

Finnish EU controller; privacy notices reference GDPR, SCCs, and DPF. Consumer product—confirm processing roles for any B2B resale.

Vendor claimed

Swedish EU entity; privacy policy addresses GDPR rights and states personal data stored/processed only in EU/EEA.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but new VPN stack uses US-linked third party Pango; global transfers and DPF described. Not a clean EU-only path. Not legal advice.

Partial

EU entity, founder-owned, no known US parent. Partial residual exposure: Stripe and PayPal as payment processors (US-group) when those methods are chosen; multi-region exits include US colo. Not legal advice.

Data processing agreement (B2B)
Not found

Consumer VPN/store terms dominate public materials; no clear self-serve B2B DPA for VPN-only enterprise procurement found.

Not found

Consumer privacy policy and ToS published; no productized enterprise DPA flow found on primary pages.

EU AI Act
Not applicable

Core product is a consumer VPN; AI features exist elsewhere in the F-Secure suite (e.g. scam tools) but are not the VPN evaluation core.

Not applicable

VPN connectivity product; not an AI system under typical procurement framing (DAITA is a traffic-defense feature, not a general-purpose AI product).

Considerations & known limitations: F-Secure FREEDOME VPN vs Mullvad
Considerations & known limitationsLogo: F-Secure FREEDOME VPNF-Secure FREEDOME VPNLogo: MullvadMullvad
Operational logs include source IP for ~90 days
Medium

Despite no destination-traffic logs, session metadata (including source public IP and device ID) is retained for abuse handling. Law-enforcement process can still target what exists; historical Finnish FREEDOME log disputes illustrate the residual risk.

Not listed
New VPN path shares infrastructure with US-linked Pango
Medium

Privacy notice discloses a third-party provider for the new VPN feature and links Pango. US CLOUD Act / transfer diligence must include that partner—not only F-Secure’s Finnish HQ.

Not listed
No public independent no-logs audit found
Medium

Trust rests on first-party privacy wording and brand reputation. Privacy-maximizing buyers often require third-party audits that were not published for this VPN at research time.

Not listed
Consumer product, not enterprise VPN platform
Low

My F-Secure account, multi-device household packs, and suite bundling fit consumers. Lack of self-host, limited advanced networking, and thin B2B contracting artifacts limit enterprise remote-access use cases.

Not listed
FREEDOME brand retirement can confuse inventories
Low

Legacy app names and store listings still say FREEDOME while the commercial product is F-Secure VPN. Asset inventories and MDM allowlists may need cleanup after the 2024 migration.

Not listed
Consumer packaging, not enterprise control planeNot listed
Medium

Self-serve numbered accounts without productized SSO/MDM org admin, ISO/SOC claims, or click-through DPA. Procurement that requires those artifacts needs offline negotiation or another vendor.

US payment processors when card/PayPal usedNot listed
Medium

Stripe and PayPal process identity-bearing payment data outside the pure numbered-account model. Cash or self-hosted crypto reduces that trail; card/PayPal does not.

Multi-region exit nodes including non-EUNot listed
Medium

Traffic can leave the tunnel outside the EU depending on server choice. Strict residency policies need operational EU-only exit controls, not HQ branding alone.

No new port forwarding; no dedicated IPNot listed
Low

Remote port forwarding was disabled for new ports in 2023; dedicated IPs are not offered by design. Choose AirVPN or self-hosted WireGuard if inbound reachability is required.

Weak recovery without the account numberNot listed
Low

No email-based reset by default. Losing the number can mean losing access; treat it as a secret in team runbooks.

US CLOUD Act residual path (indicative)Not listed
Low

No known US parent. Residual exposure mainly via US payment SaaS and optional US exits—not ownership. Not a guarantee against other LE cooperation.

Fit

F-Secure FREEDOME VPN

Best fit when

  • Households wanting a one-click VPN from a known Finnish security brand
  • Users already on F-Secure Total who need the VPN module under My F-Secure
  • Travelers who prioritize automatic public Wi-Fi protection over advanced routing
  • Buyers who accept registered accounts and multi-device consumer subscriptions
  • Teams okay with partial operational logging documented in the privacy notice

Poor fit when

  • Evaluations that require a public independent no-logs / infrastructure audit
  • Anonymous or cash/crypto signup with no email account
  • Self-hosted or fully operator-controlled VPN gateways
  • Enterprise remote-access / ZTNA procurement (this is a consumer product)
  • Strict EU-only data-path requirements that forbid US-linked VPN OEM partners

Consider instead when

  • When: You need a privacy-hardened specialist VPN with anonymous accounts and strong transparency

    Consider: Mullvad

    Swedish pure-play VPN; different UX and no antivirus suite bundling.

  • When: You want a European privacy suite with VPN-first positioning and broader privacy product line

    Consider: Proton VPN

    Swiss Proton ecosystem; compare free-tier limits and audit publications separately.

  • When: You need advanced enthusiast networking controls rather than a consumer suite VPN

    Consider: AirVPN

    More power-user oriented; steeper than F-Secure’s one-click consumer apps.

Mullvad

Best fit when

  • You want accountless signup (no email) and optional cash/crypto payment trails
  • Open-source (GPL-3) clients and public infrastructure audit reports are procurement requirements
  • Threat model includes traffic analysis or long-term confidentiality (DAITA, quantum-resistant tunnels)
  • Users face VPN blocking and need bridge/obfuscation (Shadowsocks, QUIC, LWO, UDP-over-TCP)
  • European legal entity with no known US corporate parent is a hard filter

Poor fit when

  • You need remote port forwarding or dedicated IPs (port forwarding disabled; no dedicated IP product)
  • Security policy requires ISO 27001 or SOC 2 from the VPN vendor on day one
  • You need enterprise fleet controls (SSO/SAML, MDM org console) as the primary packaging
  • Primary goal is commercial streaming unblocking at maximum server count rather than anonymity
  • Staff cannot reliably store a 16-digit account number (weak recovery without email)

Consider instead when

  • When: You need inbound remote port forwarding or Dynamic DNS

    Consider: AirVPN

    Mullvad disabled new port forwards in 2023; AirVPN remains port-forward oriented.

  • When: You want a free tier plus mail/drive in one European privacy suite

    Consider: Proton VPN

    Proton is account-based with a broader product suite; Mullvad optimizes for minimal identity.

  • When: You need maximum consumer server footprint and streaming-oriented features

    Consider: NordVPN or Surfshark

    Trade a denser feature catalog for weaker accountless/audit differentiation vs Mullvad.

  • When: You need enterprise zero-trust mesh or org-wide device VPN with SSO

    Consider: Self-hosted WireGuard, Tailscale, or NetBird

    Different product class than consumer privacy VPN.

Open questions for due diligence

F-Secure FREEDOME VPN

  • Which app builds still use the old OpenVPN/IPSec stack versus the Pango-backed new stack (Hydra/WireGuard/IPSec) on each OS?
  • Will F-Secure publish a full VPN subprocessor and hosting-region list suitable for procurement files?
  • Is a formal B2B DPA available for organizations buying VPN seats outside pure consumer checkout?
  • Is there a current independent audit of the no-destination-log claim and session-log retention controls?
  • What gateway capacity and streaming/P2P acceptable-use limits apply in practice beyond marketing claims?

Mullvad

  • Will Mullvad sign a B2B DPA and provide a written subprocessors schedule for a company purchase?
  • Can your org enforce EU-only exits (and block US/other regions) via MDM/config for all devices?
  • Is payment restricted to cash/crypto acceptable so Stripe/PayPal never see staff identity?
  • Does vendor risk accept public third-party audits in lieu of ISO 27001/SOC 2?