Mullvad vs Xeovo

Compare Mullvad and Xeovo on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: ExpressVPN, IVPN

Logo: Mullvad

Mullvad

Sweden· VPN Services

Needs review

Shortlist when you need a Swedish founder-owned privacy VPN with numbered accounts, GPL clients, RAM-only relays, and a dense public audit trail. Skip when you need dedicated IPs, remote port forwarding, or productized enterprise SSO/ISO packaging—consider Proton VPN for suite/free-tier onboarding or AirVPN for inbound ports.

EU-operated (Sweden)Numbered accountsGPL-3 clientsWireGuard + multihopPublic security auditsRAM-only relays
Logo: Xeovo

Xeovo

Finland· VPN Services

Needs review

Shortlist Xeovo when you need a Finnish EU operator with WireGuard/OpenVPN plus a real stealth-proxy toolkit (AmneziaWG, multi-protocol obfuscation, Hysteria 2) and cash/crypto payment options. Skip when you require independent no-logs audits, port forwarding, dedicated IPs, or streaming reliability—prefer Mullvad or Proton VPN instead.

Finnish Xeovo OyWireGuard + OpenVPNStealth proxies + AmneziaWGCash & crypto paymentsAnnual transparency reports
Mullvad vs Xeovo: Snapshot
FeatureLogo: MullvadMullvadLogo: XeovoXeovo
Country of originSwedenFinland
CategoryVPN ServicesVPN Services
Open sourceYesNo
Self-hostedNoNo
HeadquartersSwedenFinland
Legal entityMullvad VPN AB (reg. no. 559238-4001); parent Amagicom ABXeovo Oy (reg. no. 3233901-7), Rautiontie 5G 30, 00640 Helsinki, Finland
Governing lawSwedish / EU law (GDPR); see Swedish legislation help pageFinnish courts for unresolved disputes (terms of service)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyMulti-region VPN exits (EU and outside EU, including USA) on owned and rented colo (public provider list: e.g. M247, DataPacket, xtom, Zenlayer, Blix). RAM-only VPN OS. Account/payment personal data claimed stored only in EU/EEA. Payment subprocessors include Stripe and PayPal (US-group) plus SEB for bank/Swish when those methods are used; support email self-hosted by Mullvad since 2024.No public infrastructure/subprocessor register. Privacy policy claims stored personal data is not transferred outside the EEA. VPN and stealth exit nodes on status.xeovo.com include EU/EEA locations plus Australia, Brazil, Canada, Japan, Singapore, South Korea, and multiple US cities. Payment rails include global card networks, PayPal, and crypto; Xeovo states it does not store full card data.
Summary

Swedish privacy VPN with numbered accounts (no email), GPL-3 clients, RAM-only relays, and repeated third-party security audits—built for anonymity over enterprise packaging.

Finland-based Xeovo Oy VPN with WireGuard/OpenVPN plus stealth proxies (Shadowsocks, AmneziaWG, VLESS/VMess/Trojan, Hysteria) for censorship resistance, no-logs policy claims, and privacy-friendly payments.

Tags
At a glance: Mullvad vs Xeovo
At a glanceLogo: MullvadMullvadLogo: XeovoXeovo
HQ / entityGothenburg, Sweden — Mullvad VPN AB (parent Amagicom AB)Not listed
Ownership100% founders Fredrik Stromberg and Daniel BerntssonNot listed
ProtocolsWireGuard (primary), OpenVPN; bridges/obfuscationWireGuard, OpenVPN, AmneziaWG, Shadowsocks, VLESS/VMess, Trojan, Hysteria 2
ClientsGPL-3 apps (Win/macOS/Linux/Android/iOS); WireGuard configs + CLINot listed
SessionsFive simultaneous connections; shared exits onlyNot listed
Commercial modelPrepaid access; no free tier; cash/crypto/card/PayPal (see site)Prepaid subscription; 5 devices; 30-day refund (limits apply)
InfrastructureRAM-only VPN relays; multi-region colo (owned + rented)Not listed
Independent auditsMultiple public app/infra audits (Cure53, ROS, Assured, X41, …)Not listed
B2B packagingSelf-serve consumer ToS; no productized enterprise pack foundNot listed
HQNot listedHelsinki, Finland (Xeovo Oy)
Legal entityNot listedXeovo Oy, reg. 3233901-7
TimelineNot listedPublic product history from April 2016
NetworkNot listed~27 countries / ~60 servers (vendor); live status map
Open sourceNot listedNo (uses open protocols; service not OSS)
Self-hostNot listedNo (SaaS VPN)
Key capabilities: Mullvad vs Xeovo
Key capabilitiesLogo: MullvadMullvadLogo: XeovoXeovo
EU-operated (Sweden)YesNot listed
Numbered accountsYesNot listed
GPL-3 clientsYesNot listed
WireGuard + multihopYesNot listed
Public security auditsYesNot listed
RAM-only relaysYesNot listed
Finnish Xeovo OyNot listedYes
WireGuard + OpenVPNNot listedYes
Stealth proxies + AmneziaWGNot listedYes
Cash & crypto paymentsNot listedYes
Annual transparency reportsNot listedYes

Mullvad

  • Numbered accounts (no email required)

    Signup generates a random account number with prepaid time remaining—no username, password, or email by default. Multiple people can share a number; recovery without the number is intentionally hard. Best when identity linkage is a risk; use cash or self-hosted crypto payments if you also want to avoid card/PayPal trails.

  • WireGuard-first apps with multihop and obfuscation

    Official clients for Windows, macOS, Linux, Android, and iOS use WireGuard with multihop, quantum-resistant tunnel options, DAITA traffic-analysis resistance, and bridge/obfuscation modes (Shadowsocks, UDP-over-TCP, QUIC, LWO on selected servers) for censored networks. Kill switch and tunnel DNS are on by default. Up to five simultaneous connections per account.

  • GPL-3 open-source clients

    Desktop and mobile client code is published under GPL-3 (github.com/mullvad/mullvadvpn-app) with public audit reports in-repo. WireGuard config export and a CLI support non-GUI deployments. iOS App Store distribution uses Apple's EULA rather than GPL for the shipped binary.

  • RAM-only relays and public audit trail

    VPN infrastructure completed migration to diskless/RAM-only operation so reboots discard volatile state. Multiple independent infrastructure and app assessments (Cure53, Radically Open Security, Assured, X41, and others) publish findings; Cure53's work explicitly looked for privacy-impacting flaws on sample relays.

  • DAITA and quantum-resistant tunnels

    DAITA (Defense Against AI-guided Traffic Analysis) adds padding/cover traffic patterns against modern traffic-analysis models. Quantum-resistant WireGuard tunnel modes are available across platforms and were rolled out as defaults on supported clients—useful for long-lived confidentiality threat models, at some performance cost.

Xeovo

  • WireGuard and OpenVPN with published crypto details

    Official features page documents WireGuard (ChaCha20/Poly1305, Curve25519; ports 51280/53/80/443, AmneziaWG configs) and OpenVPN (AES-256-GCM, TLS 1.3, TCP 443 and UDP 1196). Suits teams that want modern defaults without proprietary tunnels—still validate leaks on your OS stack.

  • Stealth proxies for DPI and censorship resistance

    Shadowsocks (+ v2ray plugin), VLESS/VMess (WS+TLS), Trojan (TLS/WS+TLS), AmneziaWG, and Hub-announced Hysteria 2.0 for networks that block plain VPN. Subscription generators target tested third-party clients; no SOCKS5. Availability claims for restricted countries are vendor status-matrix based.

  • Config generator, custom DNS, optional ad/tracker block lists

    Built-in generators produce VPN and stealth subscription configs. WireGuard/AmneziaWG/OpenVPN can use custom DNS or Xeovo’s ad/tracker-blocking DNS (lists such as pgl.yoyo.org, AdAway, oisd). Useful for power users; block lists may break some sites.

  • Compact multi-region map with live P2P labels

    Marketing cites ~27 countries / ~60 servers with quality-over-quantity positioning. status.xeovo.com shows per-node health and which VPN/stealth locations allow P2P. Five concurrent devices, unlimited bandwidth marketing, IPv6, WireGuard kill-switch—no port forwarding or dedicated IPs.

  • Privacy-oriented payments and optional email accounts

    Accepts cash, Monero, Bitcoin, and Litecoin alongside cards and PayPal. Registration needs a username/password; email is optional for recovery and billing notices. Prepaid plans with a one-time 30-day money-back window (crypto refunds excluded per terms).

Assurance & compliance: Mullvad vs Xeovo
Assurance & complianceLogo: MullvadMullvadLogo: XeovoXeovo
Independent security / no-logs audit
Verified

Public Cure53 infrastructure reports (e.g. 2021, 2024) and other third-party app/infra audits; Cure53 stated no PII on assessed systems and no anonymity compromise found in 2024 sample. April 2023 Swedish police search reported no customer data seized.

Not found

Privacy policy claims detailed no-logs; annual Hub transparency reports are first-party only. No public third-party audit PDF located.

ISO 27001
Not found
Not found
SOC 2 / SOC 3
Not found
Not found
GDPR / EU data protection
Vendor claimed

Swedish EU entity; privacy policy addresses GDPR rights and states personal data stored/processed only in EU/EEA.

Vendor claimed

Finnish controller Xeovo Oy; privacy policy cites GDPR and Finnish DPA (tietosuoja.fi); claims no transfer of stored personal data outside EEA.

US CLOUD Act exposure (indicative)
Partial

EU entity, founder-owned, no known US parent. Partial residual exposure: Stripe and PayPal as payment processors (US-group) when those methods are chosen; multi-region exits include US colo. Not legal advice.

Partial

EU entity / no known US parent and claimed EEA storage for account data, but no public hosting/subprocessor list and public US exit locations. Residual exposure medium. Not legal advice.

Data processing agreement (B2B)
Not found

Consumer privacy policy and ToS published; no productized enterprise DPA flow found on primary pages.

Not found

No public B2B DPA download or subprocessor schedule found; privacy policy is consumer-oriented.

EU AI Act
Not applicable

VPN connectivity product; not an AI system under typical procurement framing (DAITA is a traffic-defense feature, not a general-purpose AI product).

Not applicable

Consumer VPN/stealth-proxy service, not an AI system offering under typical AI Act scoping.

Considerations & known limitations: Mullvad vs Xeovo
Considerations & known limitationsLogo: MullvadMullvadLogo: XeovoXeovo
Consumer packaging, not enterprise control plane
Medium

Self-serve numbered accounts without productized SSO/MDM org admin, ISO/SOC claims, or click-through DPA. Procurement that requires those artifacts needs offline negotiation or another vendor.

Not listed
US payment processors when card/PayPal used
Medium

Stripe and PayPal process identity-bearing payment data outside the pure numbered-account model. Cash or self-hosted crypto reduces that trail; card/PayPal does not.

Not listed
Multi-region exit nodes including non-EU
Medium

Traffic can leave the tunnel outside the EU depending on server choice. Strict residency policies need operational EU-only exit controls, not HQ branding alone.

Not listed
No new port forwarding; no dedicated IP
Low

Remote port forwarding was disabled for new ports in 2023; dedicated IPs are not offered by design. Choose AirVPN or self-hosted WireGuard if inbound reachability is required.

Not listed
Weak recovery without the account number
Low

No email-based reset by default. Losing the number can mean losing access; treat it as a secret in team runbooks.

Not listed
US CLOUD Act residual path (indicative)
Low

No known US parent. Residual exposure mainly via US payment SaaS and optional US exits—not ownership. Not a guarantee against other LE cooperation.

Not listed
No public independent no-logs auditNot listed
High

High-sensitivity buyers must treat no-logs and transparency reports as first-party claims. Demand external evidence or shortlist an audited peer.

Infrastructure and subprocessors not publishedNot listed
Medium

Without a DC/payment/email/hosting register, residual transfer and CLOUD Act analysis stays incomplete even with Finnish HQ and EEA storage claims for account data.

Optional US and other non-EU exit nodesNot listed
Medium

Status map includes multiple US cities and other non-EU locations. Choose EU exits deliberately when residency of tunnel egress matters.

No port forwarding or dedicated IPs; streaming weakNot listed
Medium

FAQ denies port forwarding and dedicated/residential IPs; major streaming services likely blocked. Hard blockers for some use cases.

Five concurrent devices; personal accountsNot listed
Low

Five simultaneous connections and terms against multi-person account sharing constrain household or team rollouts.

Fit

Mullvad

Best fit when

  • You want accountless signup (no email) and optional cash/crypto payment trails
  • Open-source (GPL-3) clients and public infrastructure audit reports are procurement requirements
  • Threat model includes traffic analysis or long-term confidentiality (DAITA, quantum-resistant tunnels)
  • Users face VPN blocking and need bridge/obfuscation (Shadowsocks, QUIC, LWO, UDP-over-TCP)
  • European legal entity with no known US corporate parent is a hard filter

Poor fit when

  • You need remote port forwarding or dedicated IPs (port forwarding disabled; no dedicated IP product)
  • Security policy requires ISO 27001 or SOC 2 from the VPN vendor on day one
  • You need enterprise fleet controls (SSO/SAML, MDM org console) as the primary packaging
  • Primary goal is commercial streaming unblocking at maximum server count rather than anonymity
  • Staff cannot reliably store a 16-digit account number (weak recovery without email)

Consider instead when

  • When: You need inbound remote port forwarding or Dynamic DNS

    Consider: AirVPN

    Mullvad disabled new port forwards in 2023; AirVPN remains port-forward oriented.

  • When: You want a free tier plus mail/drive in one European privacy suite

    Consider: Proton VPN

    Proton is account-based with a broader product suite; Mullvad optimizes for minimal identity.

  • When: You need maximum consumer server footprint and streaming-oriented features

    Consider: NordVPN or Surfshark

    Trade a denser feature catalog for weaker accountless/audit differentiation vs Mullvad.

  • When: You need enterprise zero-trust mesh or org-wide device VPN with SSO

    Consider: Self-hosted WireGuard, Tailscale, or NetBird

    Different product class than consumer privacy VPN.

Xeovo

Best fit when

  • Users under active DPI/censorship who need Shadowsocks, AmneziaWG, VLESS/VMess/Trojan, or Hysteria—not only plain WireGuard
  • Buyers who want a Finnish EU legal entity and GDPR-framed privacy policy with claimed EEA storage for account data
  • Privacy-oriented individuals who value optional email, cash/Monero/BTC/LTC payments, and prepaid subscriptions
  • Power users comfortable with config generators and third-party stealth clients rather than a single mega-app
  • Teams fine with a compact ~27-country map and live status/P2P labels instead of thousands of cities

Poor fit when

  • Procurement that requires independent no-logs audits, ISO 27001/SOC 2 evidence, and a public B2B DPA with subprocessors
  • Users who need port forwarding, dedicated/residential IPs, or reliable access to major streaming catalogues
  • Organisations standardising only on audited multi-hop or RAM-only infrastructure claims Xeovo does not publish
  • Households seeking a free tier or free trial (only prepaid + limited money-back)
  • Anyone who will treat vendor no-logs claims as verified without third-party evidence

Consider instead when

  • When: You need stronger anonymous-account culture and long-standing independent reputation

    Consider: Mullvad

    Better default when stealth protocols are secondary to audited privacy ops

  • When: You want a larger EU brand suite, free tier options, and deeper corporate security programme material

    Consider: Proton VPN

    Prefer for broader product integration and procurement packaging

  • When: You want simple Dutch consumer apps and lifetime packaging more than censorship tooling

    Consider: GOOSE VPN

    Different protocol story; fewer stealth-focused features

Open questions for due diligence

Mullvad

  • Will Mullvad sign a B2B DPA and provide a written subprocessors schedule for a company purchase?
  • Can your org enforce EU-only exits (and block US/other regions) via MDM/config for all devices?
  • Is payment restricted to cash/crypto acceptable so Stripe/PayPal never see staff identity?
  • Does vendor risk accept public third-party audits in lieu of ISO 27001/SOC 2?

Xeovo

  • Will Xeovo publish or provide under NDA a current infrastructure and subprocessor list (DCs, payment processors, email, CDN for stealth)?
  • Is an independent no-logs or application security audit planned or available on request?
  • For B2B: will Xeovo Oy sign a GDPR DPA with a named subprocessor schedule?
  • What exact retention periods apply to payment metadata, tickets, and WireGuard/proxy keys after account deletion?
  • Which official first-party apps (if any) ship kill-switch and DNS controls vs config import only per platform?