Logo: Mullvad

Mullvad

Swedish privacy VPN with numbered accounts (no email), GPL-3 clients, RAM-only relays, and repeated third-party security audits—built for anonymity over enterprise packaging.

Open source

Mullvad is a commercial VPN operated by Mullvad VPN AB in Gothenburg, Sweden (parent Amagicom AB). It encrypts device traffic and exits it from a shared IP on Mullvad's multi-region relay network so your ISP cannot see destinations and destination sites do not see your home IP. The service launched in 2009 and remains founder-owned, not a US-group or private-equity consumer VPN brand.

It exists for people who treat identity linkage as the purchase filter. Signup does not ask for an email, phone, or name. The app or website generates a random numbered account. That number plus remaining prepaid time is what you need to connect.

The concrete differentiator is that numbered-account model, with optional cash-by-post or self-hosted cryptocurrency payments if you also want to avoid card processors. Official desktop and mobile clients are published under GPL-3, and the company publishes a per-relay ownership list on a RAM-only network.

EU-operated (Sweden)Numbered accountsGPL-3 clientsWireGuard + multihopPublic security auditsRAM-only relays

Shortlist when you need a Swedish founder-owned privacy VPN with numbered accounts, GPL clients, RAM-only relays, and a dense public audit trail. Skip when you need dedicated IPs, remote port forwarding, or productized enterprise SSO/ISO packaging—consider Proton VPN for suite/free-tier onboarding or AirVPN for inbound ports.

Key capabilities

Signup generates a random account number with prepaid time remaining—no username, password, or email by default. Multiple people can share a number; recovery without the number is intentionally hard. Best when identity linkage is a risk; use cash or self-hosted crypto payments if you also want to avoid card/PayPal trails.

Official clients for Windows, macOS, Linux, Android, and iOS use WireGuard with multihop, quantum-resistant tunnel options, DAITA traffic-analysis resistance, and bridge/obfuscation modes (Shadowsocks, UDP-over-TCP, QUIC, LWO on selected servers) for censored networks. Kill switch and tunnel DNS are on by default. Up to five simultaneous connections per account.

Desktop and mobile client code is published under GPL-3 (github.com/mullvad/mullvadvpn-app) with public audit reports in-repo. WireGuard config export and a CLI support non-GUI deployments. iOS App Store distribution uses Apple's EULA rather than GPL for the shipped binary.

VPN infrastructure completed migration to diskless/RAM-only operation so reboots discard volatile state. Multiple independent infrastructure and app assessments (Cure53, Radically Open Security, Assured, X41, and others) publish findings; Cure53's work explicitly looked for privacy-impacting flaws on sample relays.

DAITA (Defense Against AI-guided Traffic Analysis) adds padding/cover traffic patterns against modern traffic-analysis models. Quantum-resistant WireGuard tunnel modes are available across platforms and were rolled out as defaults on supported clients—useful for long-lived confidentiality threat models, at some performance cost.

At a glance

HQ / entity
Gothenburg, Sweden — Mullvad VPN AB (parent Amagicom AB)
Ownership
100% founders Fredrik Stromberg and Daniel Berntsson
Protocols
WireGuard (primary), OpenVPN; bridges/obfuscation
Clients
GPL-3 apps (Win/macOS/Linux/Android/iOS); WireGuard configs + CLI
Sessions
Five simultaneous connections; shared exits only
Commercial model
Prepaid access; no free tier; cash/crypto/card/PayPal (see site)
Infrastructure
RAM-only VPN relays; multi-region colo (owned + rented)
Independent audits
Multiple public app/infra audits (Cure53, ROS, Assured, X41, …)
B2B packaging
Self-serve consumer ToS; no productized enterprise pack found

Best fit when

  • You want accountless signup (no email) and optional cash/crypto payment trails
  • Open-source (GPL-3) clients and public infrastructure audit reports are procurement requirements
  • Threat model includes traffic analysis or long-term confidentiality (DAITA, quantum-resistant tunnels)
  • Users face VPN blocking and need bridge/obfuscation (Shadowsocks, QUIC, LWO, UDP-over-TCP)
  • European legal entity with no known US corporate parent is a hard filter

Poor fit when

  • You need remote port forwarding or dedicated IPs (port forwarding disabled; no dedicated IP product)
  • Security policy requires ISO 27001 or SOC 2 from the VPN vendor on day one
  • You need enterprise fleet controls (SSO/SAML, MDM org console) as the primary packaging
  • Primary goal is commercial streaming unblocking at maximum server count rather than anonymity
  • Staff cannot reliably store a 16-digit account number (weak recovery without email)

Consider instead when

  • When: You need inbound remote port forwarding or Dynamic DNS

    Consider: AirVPN

    Mullvad disabled new port forwards in 2023; AirVPN remains port-forward oriented.

  • When: You want a free tier plus mail/drive in one European privacy suite

    Consider: Proton VPN

    Proton is account-based with a broader product suite; Mullvad optimizes for minimal identity.

  • When: You need maximum consumer server footprint and streaming-oriented features

    Consider: NordVPN or Surfshark

    Trade a denser feature catalog for weaker accountless/audit differentiation vs Mullvad.

  • When: You need enterprise zero-trust mesh or org-wide device VPN with SSO

    Consider: Self-hosted WireGuard, Tailscale, or NetBird

    Different product class than consumer privacy VPN.

Jurisdiction & ownership

Legal entity
Mullvad VPN AB (reg. no. 559238-4001); parent Amagicom AB
Governing law
Swedish / EU law (GDPR); see Swedish legislation help page
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Multi-region VPN exits (EU and outside EU, including USA) on owned and rented colo (public provider list: e.g. M247, DataPacket, xtom, Zenlayer, Blix). RAM-only VPN OS. Account/payment personal data claimed stored only in EU/EEA. Payment subprocessors include Stripe and PayPal (US-group) plus SEB for bank/Swish when those methods are used; support email self-hosted by Mullvad since 2024.

No known US parent. CLOUD Act path is residual via US payment SaaS when card/PayPal is used and via non-EU exit selection—not via US corporate ownership. Indicative only; not legal advice.

  • Independent security / no-logs auditVerified
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumConsumer packaging, not enterprise control plane

    Self-serve numbered accounts without productized SSO/MDM org admin, ISO/SOC claims, or click-through DPA. Procurement that requires those artifacts needs offline negotiation or another vendor.

  • MediumUS payment processors when card/PayPal used

    Stripe and PayPal process identity-bearing payment data outside the pure numbered-account model. Cash or self-hosted crypto reduces that trail; card/PayPal does not.

  • MediumMulti-region exit nodes including non-EU

    Traffic can leave the tunnel outside the EU depending on server choice. Strict residency policies need operational EU-only exit controls, not HQ branding alone.

  • LowNo new port forwarding; no dedicated IP

    Remote port forwarding was disabled for new ports in 2023; dedicated IPs are not offered by design. Choose AirVPN or self-hosted WireGuard if inbound reachability is required.

  • LowWeak recovery without the account number

    No email-based reset by default. Losing the number can mean losing access; treat it as a secret in team runbooks.

  • LowUS CLOUD Act residual path (indicative)

    No known US parent. Residual exposure mainly via US payment SaaS and optional US exits—not ownership. Not a guarantee against other LE cooperation.

Open questions for due diligence

  • Will Mullvad sign a B2B DPA and provide a written subprocessors schedule for a company purchase?
  • Can your org enforce EU-only exits (and block US/other regions) via MDM/config for all devices?
  • Is payment restricted to cash/crypto acceptable so Stripe/PayPal never see staff identity?
  • Does vendor risk accept public third-party audits in lieu of ISO 27001/SOC 2?

Frequently Asked Questions

Accounts are random numbers without email by default. If you lose the number, recovery is limited (payment-based recovery paths may exist depending on method). For high-risk users this is a feature; for IT desks used to password reset flows it is operational friction—store the number offline like a secret.

Five simultaneous connections per account; shared exit IPs only (no dedicated IP product). New remote port forwarding was disabled in 2023. Outbound SMTP port 25 and several Windows file-sharing ports are blocked on the network. Split tunneling exists on major platforms but inverse split tunneling (VPN only selected apps) is not supported in the official app.

Public materials describe a self-serve consumer VPN with privacy policies and terms—not a full enterprise control plane with SSO/SAML fleet admin. FAQ states they operate as a consumer retailer for VAT purposes. No productized click-through B2B DPA or ISO 27001/SOC 2 claims were found on primary pages; ask support offline if procurement requires a signed DPA.

The published policy states no traffic, DNS, connection, IP, or bandwidth activity logs. Architecture uses RAM-only VPN servers and in-memory connection accounting. Independent infrastructure audits (e.g. Cure53) reported no customer PII on assessed systems, and Mullvad's April 2023 Gothenburg search-warrant account states police left without customer data. Payment and support channels can still process personal data if you use identity-bearing methods.

You choose country/city exits from a multi-region map that includes EU and non-EU locations (including the USA). Account and payment personal data are stated to stay in the EU/EEA, but exit-node choice still determines where your traffic leaves the tunnel. Enforce EU-only exits operationally if policy requires it—HQ location alone does not pin egress.