Mullvad vs NordVPN

Compare Mullvad and NordVPN on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: ExpressVPN, Private Internet Access

Logo: Mullvad

Mullvad

Sweden· VPN Services

Needs review

Shortlist when you need a Swedish founder-owned privacy VPN with numbered accounts, GPL clients, RAM-only relays, and a dense public audit trail. Skip when you need dedicated IPs, remote port forwarding, or productized enterprise SSO/ISO packaging—consider Proton VPN for suite/free-tier onboarding or AirVPN for inbound ports.

EU-operated (Sweden)Numbered accountsGPL-3 clientsWireGuard + multihopPublic security auditsRAM-only relays
Logo: NordVPN

NordVPN

Lithuania· VPN Services

Needs review

Shortlist NordVPN when you want a polished multi-platform VPN with NordLynx performance, a very large RAM-only network, Meshnet, and in-app Threat Protection backed by repeated Big Four no-logs engagements. Skip when you need a pure EU data controller, fully public audit PDFs and subprocessors, anonymous numbered accounts, unlimited devices, or self-host—consider Mullvad or Proton VPN instead (and NordLayer for managed business access).

NordLynx (WireGuard-based)RAM-only serversMeshnetThreat ProtectionNo-logs audits (Big Four)EU group (LT HQ)
Mullvad vs NordVPN: Snapshot
FeatureLogo: MullvadMullvadLogo: NordVPNNordVPN
Country of originSwedenLithuania
CategoryVPN ServicesVPN Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersSwedenLithuania
Legal entityMullvad VPN AB (reg. no. 559238-4001); parent Amagicom ABnordvpn S.A. (Panama) as consumer data controller; NordSec B.V. (Netherlands) EEA representative; Nord Security group HQ Lithuania
Governing lawSwedish / EU law (GDPR); see Swedish legislation help pagePrivacy policy references GDPR and UK DPA among other regimes; confirm Terms of Service for contract law
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyMulti-region VPN exits (EU and outside EU, including USA) on owned and rented colo (public provider list: e.g. M247, DataPacket, xtom, Zenlayer, Blix). RAM-only VPN OS. Account/payment personal data claimed stored only in EU/EEA. Payment subprocessors include Stripe and PayPal (US-group) plus SEB for bank/Swish when those methods are used; support email self-hosted by Mullvad since 2024.Global VPN egress: vendor-stated 8,900+ RAM-only servers across 224+ locations; mix of Nord-managed colocated hardware and partner-hosted servers. Trust Center describes multi-cloud security for operational infrastructure (providers not fully named on public pages reviewed). Account, billing, and support data paths per privacy policy under Panama controller.
Summary

Swedish privacy VPN with numbered accounts (no email), GPL-3 clients, RAM-only relays, and repeated third-party security audits—built for anonymity over enterprise packaging.

Lithuanian Nord Security consumer VPN: NordLynx (WireGuard-based), large RAM-only network, Meshnet, Threat Protection, and audited no-logs claims under a Panama data controller.

Tags
At a glance: Mullvad vs NordVPN
At a glanceLogo: MullvadMullvadLogo: NordVPNNordVPN
HQ / entityGothenburg, Sweden — Mullvad VPN AB (parent Amagicom AB)Not listed
Ownership100% founders Fredrik Stromberg and Daniel BerntssonNot listed
ProtocolsWireGuard (primary), OpenVPN; bridges/obfuscationNot listed
ClientsGPL-3 apps (Win/macOS/Linux/Android/iOS); WireGuard configs + CLINot listed
SessionsFive simultaneous connections; shared exits onlyNot listed
Commercial modelPrepaid access; no free tier; cash/crypto/card/PayPal (see site)Not listed
InfrastructureRAM-only VPN relays; multi-region colo (owned + rented)Not listed
Independent auditsMultiple public app/infra audits (Cure53, ROS, Assured, X41, …)Not listed
B2B packagingSelf-serve consumer ToS; no productized enterprise pack foundNot listed
Group HQNot listedNord Security — Lithuania
Data controller (consumer)Not listednordvpn S.A., Panama
EEA representativeNot listedNordSec B.V., Amsterdam
FoundedNot listed2012
Network (vendor)Not listed8,900+ servers / 224+ locations; RAM-only
Simultaneous devicesNot listedUp to 10 (router = 1 slot)
Self-hostNot listedNo (managed SaaS VPN)
Open sourceNot listedPartial (Linux client components); service proprietary
Key capabilities: Mullvad vs NordVPN
Key capabilitiesLogo: MullvadMullvadLogo: NordVPNNordVPN
EU-operated (Sweden)YesNot listed
Numbered accountsYesNot listed
GPL-3 clientsYesNot listed
WireGuard + multihopYesNot listed
Public security auditsYesNot listed
RAM-only relaysYesYes
NordLynx (WireGuard-based)Not listedYes
MeshnetNot listedYes
Threat ProtectionNot listedYes
No-logs audits (Big Four)Not listedYes
EU group (LT HQ)Not listedYes

Mullvad

  • Numbered accounts (no email required)

    Signup generates a random account number with prepaid time remaining—no username, password, or email by default. Multiple people can share a number; recovery without the number is intentionally hard. Best when identity linkage is a risk; use cash or self-hosted crypto payments if you also want to avoid card/PayPal trails.

  • WireGuard-first apps with multihop and obfuscation

    Official clients for Windows, macOS, Linux, Android, and iOS use WireGuard with multihop, quantum-resistant tunnel options, DAITA traffic-analysis resistance, and bridge/obfuscation modes (Shadowsocks, UDP-over-TCP, QUIC, LWO on selected servers) for censored networks. Kill switch and tunnel DNS are on by default. Up to five simultaneous connections per account.

  • GPL-3 open-source clients

    Desktop and mobile client code is published under GPL-3 (github.com/mullvad/mullvadvpn-app) with public audit reports in-repo. WireGuard config export and a CLI support non-GUI deployments. iOS App Store distribution uses Apple's EULA rather than GPL for the shipped binary.

  • RAM-only relays and public audit trail

    VPN infrastructure completed migration to diskless/RAM-only operation so reboots discard volatile state. Multiple independent infrastructure and app assessments (Cure53, Radically Open Security, Assured, X41, and others) publish findings; Cure53's work explicitly looked for privacy-impacting flaws on sample relays.

  • DAITA and quantum-resistant tunnels

    DAITA (Defense Against AI-guided Traffic Analysis) adds padding/cover traffic patterns against modern traffic-analysis models. Quantum-resistant WireGuard tunnel modes are available across platforms and were rolled out as defaults on supported clients—useful for long-lived confidentiality threat models, at some performance cost.

NordVPN

  • NordLynx (WireGuard-based) plus fallback protocols

    Default high-speed path uses NordLynx, Nord’s WireGuard implementation with a double-NAT design meant to preserve performance while limiting server-side identifiers. OpenVPN and IKEv2 remain available on many clients; NordWhisper targets hard-to-reach networks. Benefits travelers and latency-sensitive users; confirm protocol availability per OS and router firmware.

  • Large RAM-only network with specialty servers

    Trust Center figures cite 8,900+ servers in 224+ locations, RAM-only memory so power-off wipes volatile state, and a mix of Nord-managed colocated hardware plus partner-hosted nodes. Specialty modes include Double VPN, Onion over VPN, obfuscated servers, and P2P nodes—useful when a single hop is not enough or when ISP shaping blocks standard VPN fingerprints.

  • Threat Protection and in-app security extras

    Beyond the tunnel, NordVPN bundles Threat Protection (and Pro variants by plan and platform) to block malicious sites, trackers, ads, and scan downloads for malware, plus Dark Web monitoring and other digital-security tools marketed as an all-in-one app. Ideal when end users will not install a separate browser stack; feature depth still varies by OS and subscription tier.

  • Meshnet encrypted peer networking

    Meshnet creates NordLynx-encrypted links between devices for remote file access, private gaming LANs, and routing traffic through a trusted peer without opening ports on the public internet. Typical limits: about ten devices on your account plus dozens of external peers—evaluate current caps in-app. Complements but does not replace a full site-to-site business VPN product.

  • Ten-device multi-platform coverage with kill switch

    Official apps span desktop, mobile, TV platforms, routers, and browser extensions, with kill switch, split tunneling, and private DNS inside the tunnel on supported clients. One account covers up to ten simultaneous connections (router setup protects the whole LAN as one slot). Suits households and freelancers; teams needing admin policy should look at NordLayer.

Assurance & compliance: Mullvad vs NordVPN
Assurance & complianceLogo: MullvadMullvadLogo: NordVPNNordVPN
Independent security / no-logs audit
Verified

Public Cure53 infrastructure reports (e.g. 2021, 2024) and other third-party app/infra audits; Cure53 stated no PII on assessed systems and no anonymity compromise found in 2024 sample. April 2023 Swedish police search reported no customer data seized.

Vendor claimed

Multiple ISAE 3000-style no-logs assurance engagements announced (PwC AG Switzerland historically; Deloitte Audit Lithuania for recent cycles including end-2024). Full reports typically require Nord Account login; EuropeanStack did not re-download gated PDFs.

ISO 27001
Not found
Not found

No clear public ISO 27001 certificate for the consumer NordVPN service on Trust Center pages reviewed (sibling products may differ).

SOC 2 / SOC 3
Not found
Not found

No public SOC 2/3 report located for consumer NordVPN during this research pass.

GDPR / EU data protection
Vendor claimed

Swedish EU entity; privacy policy addresses GDPR rights and states personal data stored/processed only in EU/EEA.

Partial

Policy asserts GDPR applicability; EEA representative NordSec B.V. (NL); group HQ Lithuania. Controller is nordvpn S.A. (Panama)—document transfers and representative arrangement in your DPIA.

US CLOUD Act exposure (indicative)
Partial

EU entity, founder-owned, no known US parent. Partial residual exposure: Stripe and PayPal as payment processors (US-group) when those methods are chosen; multi-region exits include US colo. Not legal advice.

Partial

No known US parent. Medium/partial assessment: multi-cloud infrastructure (unnamed providers on public Trust Center), global offices including US presence, and Panama controller—VPN no-logs posture does not eliminate account/cloud subprocessor questions. Not legal advice.

Data processing agreement (B2B)
Not found

Consumer privacy policy and ToS published; no productized enterprise DPA flow found on primary pages.

Unknown

Consumer checkout does not surface a standard public DPA the way many B2B SaaS portals do. Request DPA and subprocessors for any organizational use; NordLayer may be the intended business contracting path.

EU AI Act
Not applicable

VPN connectivity product; not an AI system under typical procurement framing (DAITA is a traffic-defense feature, not a general-purpose AI product).

Not applicable

Consumer VPN and digital security app; not marketed as an AI system under the AI Act.

Considerations & known limitations: Mullvad vs NordVPN
Considerations & known limitationsLogo: MullvadMullvadLogo: NordVPNNordVPN
Consumer packaging, not enterprise control plane
Medium

Self-serve numbered accounts without productized SSO/MDM org admin, ISO/SOC claims, or click-through DPA. Procurement that requires those artifacts needs offline negotiation or another vendor.

Not listed
US payment processors when card/PayPal used
Medium

Stripe and PayPal process identity-bearing payment data outside the pure numbered-account model. Cash or self-hosted crypto reduces that trail; card/PayPal does not.

Not listed
Multi-region exit nodes including non-EU
Medium

Traffic can leave the tunnel outside the EU depending on server choice. Strict residency policies need operational EU-only exit controls, not HQ branding alone.

Not listed
No new port forwarding; no dedicated IP
Low

Remote port forwarding was disabled for new ports in 2023; dedicated IPs are not offered by design. Choose AirVPN or self-hosted WireGuard if inbound reachability is required.

Not listed
Weak recovery without the account number
Low

No email-based reset by default. Losing the number can mean losing access; treat it as a secret in team runbooks.

Not listed
US CLOUD Act residual path (indicative)
Low

No known US parent. Residual exposure mainly via US payment SaaS and optional US exits—not ownership. Not a guarantee against other LE cooperation.

Not listed
Panama data controller, not EU entity-as-controllerNot listed
Medium

Privacy policy names nordvpn S.A. (Panama) as controller despite Lithuanian group HQ and Dutch EEA representative. Sovereignty-focused buyers must accept this structure or pick an EU or Swiss controller peer.

Multi-cloud backend; incomplete public subprocessor listNot listed
Medium

Trust Center describes multi-cloud operational security without a clear exhaustive public consumer subprocessor table on pages reviewed. Assume possible US-group cloud SaaS for non-tunnel functions until Nord provides a current list under NDA or DPA.

Full no-logs reports account-gatedNot listed
Low

Assurance engagements are real and repeated, but PDFs are not always public. Procurement may need a login or vendor package to attach evidence to a risk register.

Device caps and best-effort streamingNot listed
Low

Ten simultaneous connections and variable streaming or geo results are practical limits. Not a substitute for a business SD-WAN or guaranteed media CDN.

Public 2018 infrastructure incident historyNot listed
Low

Industry coverage of a 2018 third-party datacenter compromise is part of brand history. Nord has since stressed RAM-only designs, audits, and bounty programs—still relevant for long-memory risk committees.

Fit

Mullvad

Best fit when

  • You want accountless signup (no email) and optional cash/crypto payment trails
  • Open-source (GPL-3) clients and public infrastructure audit reports are procurement requirements
  • Threat model includes traffic analysis or long-term confidentiality (DAITA, quantum-resistant tunnels)
  • Users face VPN blocking and need bridge/obfuscation (Shadowsocks, QUIC, LWO, UDP-over-TCP)
  • European legal entity with no known US corporate parent is a hard filter

Poor fit when

  • You need remote port forwarding or dedicated IPs (port forwarding disabled; no dedicated IP product)
  • Security policy requires ISO 27001 or SOC 2 from the VPN vendor on day one
  • You need enterprise fleet controls (SSO/SAML, MDM org console) as the primary packaging
  • Primary goal is commercial streaming unblocking at maximum server count rather than anonymity
  • Staff cannot reliably store a 16-digit account number (weak recovery without email)

Consider instead when

  • When: You need inbound remote port forwarding or Dynamic DNS

    Consider: AirVPN

    Mullvad disabled new port forwards in 2023; AirVPN remains port-forward oriented.

  • When: You want a free tier plus mail/drive in one European privacy suite

    Consider: Proton VPN

    Proton is account-based with a broader product suite; Mullvad optimizes for minimal identity.

  • When: You need maximum consumer server footprint and streaming-oriented features

    Consider: NordVPN or Surfshark

    Trade a denser feature catalog for weaker accountless/audit differentiation vs Mullvad.

  • When: You need enterprise zero-trust mesh or org-wide device VPN with SSO

    Consider: Self-hosted WireGuard, Tailscale, or NetBird

    Different product class than consumer privacy VPN.

NordVPN

Best fit when

  • Households and freelancers who want one app for VPN plus malware, ad, and tracker blocking
  • Travelers needing broad country coverage, Quick Connect, and multi-OS clients including routers
  • Users who value Meshnet for private peer file share or remote LAN gaming without public port exposure
  • Buyers who want repeated independent no-logs assurance engagements (Deloitte and PwC lineage) even if full PDFs are account-gated
  • Teams already standardizing on other Nord Security consumer tools and accepting a managed SaaS VPN

Poor fit when

  • Organizations requiring the data controller to be an EU company only (controller is nordvpn S.A., Panama)
  • Buyers who need fully open-source clients on every platform, cash or numbered anonymous accounts, or self-hosted relays
  • Enterprises needing centralized SSO, device policy, and B2B contracting on the consumer SKU (use NordLayer or peers)
  • Procurement that must prove EU-only hosting and named non-US subprocessors from a public list alone
  • Users who need unlimited simultaneous devices without a router workaround

Consider instead when

  • When: You want numbered accounts, cash-friendly privacy payments, and fully open clients

    Consider: Mullvad

    Fewer consumer extras (no Meshnet or Threat Protection suite) but stronger anonymity UX

  • When: You want a Swiss privacy-ecosystem VPN with freemium entry and open-source clients

    Consider: Proton VPN

    Different protocol and product mix; compare Secure Core vs Nord specialty servers

  • When: You need unlimited devices on a mass-market plan in the same commercial family

    Consider: Surfshark

    Related market positioning after corporate combination; verify current ownership and plan terms

  • When: You need admin-managed business remote access rather than consumer seats

    Consider: NordLayer (Nord Security business product) or a dedicated business VPN

    Do not stretch consumer NordVPN as an enterprise gateway

Open questions for due diligence

Mullvad

  • Will Mullvad sign a B2B DPA and provide a written subprocessors schedule for a company purchase?
  • Can your org enforce EU-only exits (and block US/other regions) via MDM/config for all devices?
  • Is payment restricted to cash/crypto acceptable so Stripe/PayPal never see staff identity?
  • Does vendor risk accept public third-party audits in lieu of ISO 27001/SOC 2?

NordVPN

  • Will Nord provide a current consumer or B2B subprocessor list naming cloud, email, payments, and support vendors with locations?
  • Can procurement obtain the latest Deloitte or PwC assurance PDF and scope letter without a personal Nord Account?
  • Is a signed DPA available for organizational purchase of consumer seats, or must buyers move to NordLayer?
  • Which account, telemetry, and crash-reporting data leave the VPN tunnel path, and under which transfer tools?
  • What is the current relationship and data-sharing boundary between NordVPN and Surfshark products after corporate combination?