Mullvad VPN
Gothenburg-headquartered founder-owned VPN with RAM-only servers, anonymous account numbers and no US legal entity.
Profile last updated: · View sources
About Mullvad VPN
Mullvad VPN is operated by Mullvad VPN AB (Bolagsverket organisation number 559238-4001, Box 53049, 400 14 Gothenburg, Sweden), wholly owned by parent Amagicom AB (organisation number 5567839807) which is in turn 100% owned by founders Fredrik Strömberg and Daniel Berntsson. The VPN service launched in March 2009 and has never raised venture capital, private equity or taken outside capital.
Sign-up requires no email, no username and no password: Mullvad generates a random 16-digit account number that is the user's sole credential. Pricing is a flat EUR 5 per month, unchanged since 2009. The 578-server fleet runs across 50 countries on a fully RAM-only / diskless infrastructure (migration completed 2023-09-20) booted via Mullvad's stboot bootloader from a signed image -- there is no disk-resident state to seize. Apps for Windows, macOS, Linux, iOS and Android ship under GPL-3.0 at github.com/mullvad/mullvadvpn-app.
Features
- Flat EUR 5/month, unchanged since 2009; pay via cash (9 currencies), Monero, card, PayPal, SEPA or Swish -- 10% discount on crypto
- Anonymous 16-digit account number replaces email / username / password; with cash or Monero, account is anonymous end-to-end
- No-logs policy on traffic / DNS / connection / IP / bandwidth; nginx retains 5-minute access logs with IP excluded
- 578-server VPN fleet across 50 countries; full RAM-only / diskless migration completed 2023-09-20; stboot signed-image boot
- 2023-04-18 Swedish Police raid on the Gothenburg office left empty-handed -- no customer data existed to seize
- DAITA (Defense Against AI-guided Traffic Analysis) on Windows / macOS / Linux / iOS / Android; pads + injects cover traffic
- Post-quantum WireGuard tunnels default on desktop since Jan 2025 -- Classic McEliece + ML-KEM hybrid against store-now-decrypt-later
- Apps open source under GPL-3.0 at github.com/mullvad/mullvadvpn-app; Mullvad Browser (Tor-fork sans Tor Network) free under MPL-2.0
- ~14 published security audits since 2018 (Cure53, Assured AB, Radically Open Security, X41 D-Sec, NCC Group, Leviathan) on apps + infra
- Free encrypted DNS resolver (DoH / DoT) anycasted from DE / UK / SE / SG / US; QNAME minimisation; available to anyone
Sovereignty Scorecard
Procurement-grade signals on data sovereignty, ownership, and EU residency.
We score every European vendor against six sovereignty dimensions captured in the SHIELD acronym. Each card below maps to one letter — read them as a checklist when comparing providers.
The third parties that touch customer data — payment processors, KYC vendors, support chatbots, analytics.
Where the legal entity sits, who controls it, and which subsidiaries operate under the same group.
Where customer data is physically stored, who runs the hosting stack, which CDN sits in front.
Whether the vendor or its subprocessors fall under the US CLOUD Act or other extraterritorial reach.
Public terms, privacy policy, DPA, subprocessor list, impressum, and security or trust pages.
Independent audits and certifications (ISO 27001, BSI C5, TISAX, SOC 2) plus open-source transparency.
Privately held
Mullvad VPN AB (Bolagsverket 559238-4001, Gothenburg) is wholly owned by Amagicom AB (5567839807, same Gothenburg address). Amagicom AB is in turn 100% owned by Swedish founders Fredrik Strömberg (board deputy of Mullvad VPN AB) and Daniel Berntsson (board member). The about page states verbatim: 'Both Mullvad VPN AB and our parent company Amagicom AB are 100% owned by us, the founders Fredrik Strömberg and Daniel Berntsson, who are actively involved in the company.' No outside venture capital, private equity, IPO or foreign holding company has ever entered the cap table. Founded in March 2009; the Mullvad VPN AB legal entity was registered in January 2020 as a carve-out of the VPN operation from Amagicom AB. An Owner's Directive at mullvad.net/en/help/owners-directive-for-mullvad-vpn binds management to the privacy mission.
🇸🇪 Gothenburg, Sweden
Mullvad VPN AB
Fixed region
Account, subscription and inventory data are processed within the EU/EEA -- the privacy policy states there are no transfers to third countries for that data. Card-payment data (Stripe, US) is the exception: users who pay by card have that transaction processed in the US; users who pay by cash, Monero, PayPal (Luxembourg), Swish (Sweden), SEPA or bank wire stay entirely within EU/EEA processors. Transaction IDs are retained 20 days; statutory accounting records up to 7 years per the Swedish Bokföringslagen. The VPN server fleet is geographically distributed across 50 countries because customers choose the exit jurisdiction; each server runs RAM-only with no disk-resident logs, so the residency picture for the VPN traffic is the exit country selected by the customer, not a residency commitment for stored data (because there is no stored traffic data).
Website: Self-hosted on Mullvad-controlled infrastructure behind nginx; HSTS preload enforces HTTPS; CAA restricts certificate issuance to Let's Encrypt; SvelteKit front end. Mullvad moved the customer-facing support email infrastructure to self-hosted RAM-only servers in February 2024 per the 2024 year-in-review.
Application: 578 VPN servers across 50 countries (548 online at observation time), 100% RAM-only / diskless since 2023-09-20. Servers boot via Mullvad's stboot bootloader on the open-source System Transparency project. Each server is publicly labelled Rented or Owned on the servers page; named rental providers include 100TB, Blixnet, Creanova, DataPacket, HostRoyal, iRegister, M247, PrivateLayer, techfutures, Tzulo, Velox, xtom and Zenlayer.
Email: Self-hosted RAM-only mail for customer support since February 2024; Google Workspace remains the inbound MX terminator on mullvad.net for non-support corporate mail (aspmx.l.google.com)
CDN: Mullvad runs its own authoritative DNS for mullvad.net and mullvadvpn.net (ns1-ns4.mullvaddns.net); Bunny CDN is referenced via a DNS TXT verification (bunny:303437)
| Name | Country | Purpose |
|---|---|---|
| Stripe, Inc. | 🇺🇸 United States | Credit-card payment processing; per the privacy policy Mullvad stores Stripe charge ID, expiration date, last 4 card digits, card type and country of origin, with transaction IDs retained 20 days |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | 🇱🇺 Luxembourg | PayPal payment processing for EU customers; Mullvad stores the transaction ID, sender's name, country of origin and email address, retained 20 days |
| Getswish AB (Swish) | 🇸🇪 Sweden | Swedish instant-payment network; identifying (transaction ID, name, phone number); Sweden-domestic |
| Google LLC (Google Workspace) | 🇺🇸 United States | Inbound MX terminator for non-support corporate mail on mullvad.net (aspmx.l.google.com observed). Customer-facing support email was moved to self-hosted RAM-only servers in February 2024 per the 2024 year-in-review. |
| Bunny CDN (BunnyWay d.o.o.) | 🇸🇮 Slovenia | Asset CDN referenced via DNS TXT verification (bunny:303437). EU-domiciled. |
| Colocation providers for VPN server fleet | Multiple | Mullvad publishes the per-server rental provider on the servers page; named providers include 100TB, Blixnet, Creanova, DataPacket, HostRoyal, iRegister, M247, PrivateLayer, techfutures, Tzulo, Velox, xtom and Zenlayer. Each rented server runs Mullvad-provisioned RAM-only OS images; the provider sees the physical hardware and bandwidth, not customer traffic content or logs. |
Pricing
EUR 5/month
- Up to 5 devices per account; 14-day money-back guarantee on card / PayPal / bank wire payments (cash and crypto are non-refundable)
- Anonymous payment methods: physical cash mailed in nine currencies (EUR, USD, GBP, SEK, NOK, CHF, CAD, AUD, NZD) and Monero (Mullvad runs its own XMR node) -- 10% discount on cryptocurrency
- Identifying payment methods: bank wire, credit card (via Stripe), PayPal, Swish, EPS, Bancontact, iDEAL, Wero, Przelewy24, voucher codes -- transaction IDs retained 20 days, statutory accounting retained 7 years per the Swedish Bokföringslagen
Questions & Answers
5 questions
Who owns Mullvad, and where is the company headquartered?
Mullvad VPN AB is registered with Bolagsverket as organisation number 559238-4001 at Box 53049, 400 14 Gothenburg, Sweden, with a visible office at Engelbrektsgatan 28. Its sole shareholder is Amagicom AB (organisation number 5567839807, same Gothenburg address), and Amagicom AB is in turn 100% owned by founders Fredrik Strömberg and Daniel Berntsson, who remain actively involved in the company. The about page states this verbatim: 'Both Mullvad VPN AB and our parent company Amagicom AB are 100% owned by us, the founders Fredrik Strömberg and Daniel Berntsson, who are actively involved in the company.' No venture capital, private-equity money, IPO or foreign holding entity sits above the group -- a distinguishing feature among consumer VPNs, where competitors typically sit under PE-style holding structures.
Is Mullvad subject to the US CLOUD Act?
The Mullvad group has no US-incorporated entity. Mullvad VPN AB and Amagicom AB are both Swedish aktiebolag in Gothenburg, both founder-owned, and no US, UK or other foreign subsidiary is disclosed in any public source. There is therefore no corporate Mullvad entity the US CLOUD Act could compel directly. Mullvad does use two US subprocessors -- Stripe Inc. for credit-card payment processing (card data only; users who pay in cash, Monero or via Swish/SEPA do not touch Stripe) and Google LLC for the inbound MX terminator on non-customer-facing corporate mail (customer-facing support email was self-hosted in 2024) -- both of which are themselves CLOUD-Act-reachable, but neither sees VPN traffic, DNS queries or connection metadata. Mullvad does operate VPN servers physically located in the United States across roughly 19 cities; those are subject to in-country law-enforcement compulsion at the colocation level, but Mullvad's RAM-only / no-logs architecture means there is no historical customer data to hand over, and customers can choose to avoid US (or any other Five-Eyes) exit servers entirely.
What does Mullvad actually log, and how was the no-logs policy stress-tested?
Per the no-logs policy at mullvad.net/en/help/no-logging-data-policy: 'no logging of traffic, no logging of DNS requests, no logging of connections (including when one is made and when it disconnects), no logging of IP addresses, no logging of user bandwidth.' The data Mullvad does retain is limited to the random 16-digit account number, account expiry, the WireGuard public key and tunnel address when WireGuard is in use, short-retention payment metadata (20 days for transaction IDs) and statutory accounting records retained up to 7 years per the Swedish Bokföringslagen. The Swedish Police National Operations Department executed a search warrant on the Gothenburg office on 2023-04-18 -- the first in 14 years of operation -- and left empty-handed because there was no customer data to seize.
How can I sign up without giving Mullvad personal information?
Mullvad generates a random 16-digit account number on demand at mullvad.net/account/create; no email, no username and no password are required. Pay anonymously by mailing physical cash in any of nine currencies (the envelope is destroyed after the cash is counted) or by sending Monero to Mullvad's own XMR wallet. Cash payments are non-refundable per AML rules; Mullvad records only the amount, the currency and the timestamp. Card, PayPal, bank wire and Swish are accepted but link the account to a name; in those cases the transaction ID is deleted after 20 days while statutory accounting records are retained 7 years per the Swedish Bokföringslagen.
What happens if a government compels Mullvad to hand over user data, or to spy on a user?
Mullvad's verbatim stated policy at mullvad.net/en/help/how-we-handle-government-requests-user-data: 'We must -- and do -- make it impossible for us to fulfill any data request. There is simply no data to request, nor confiscate in the case of physical seizure.' On the question of being compelled to spy, the company adds: 'we will cease operation of our service in the affected jurisdiction and only resume it if the legal situation has been remedied.' Swedish law currently does not allow forced surveillance assistance. The 2023-04-18 Gothenburg search warrant is the only real-world stress test on record; Mullvad demonstrated the no-logs architecture, the prosecutor was consulted and no data was seized.
Alternatives
Other European companies in the same category as Mullvad VPN.
Quick facts
Sources & verification
Every fact on this page is backed by a primary or independent source. Most recent verification: May 15, 2026.
Found an error? Report it
Profile content
- primary · about-pagemullvad.net/en/about
- primary · security-pagemullvad.net/en/help/no-logging-data-policy
- primary · about-pagemullvad.net/en/aboutFounder ownership and parent-company structure verbatim
- primary · privacy-policymullvad.net/en/help/privacy-policySelf-declared controller, registration number, postal address verbatim
- primary · about-pagemullvad.net/en/servers578 servers, 50 countries, rental providers
- primary · blogmullvad.net/en/blog/we-have-successfully-completed-our-migration-to-ram-only-vpn-infrastructureRAM-only migration completion 2023-09-20
- primary · pricing-pagemullvad.net/en/pricingEUR 5/month flat since 2009
- primary · othergithub.com/mullvad/mullvadvpn-appGPL-3.0 main repo
- primary · pricing-pagemullvad.net/en/pricing
- primary · termsmullvad.net/en/help/terms-serviceFive devices per account, 14-day money-back guarantee
- primary · security-pagemullvad.net/en/help/no-logging-data-policy20-day transaction-ID retention, 7-year Swedish Bokföringslagen
- primary · about-pagemullvad.net/en/aboutFounder ownership 100%
- registry · otherwww.allabolag.se/foretag/mullvad-vpn-ab/g%C3%B6teborg/konsulter/2KHK741I5YF3IBolagsverket organisation number 559238-4001
- registry · otherwww.northdata.com/Amagicom%20AB,%20G%C3%B6teborg/ON%205567839807Amagicom AB parent organisation number
- primary · security-pagemullvad.net/en/help/no-logging-data-policyVerbatim no-logs list; nginx access-log retention 5 minutes excluding IP
- primary · termsmullvad.net/en/help/terms-serviceAccount-number system
- primary · about-pagemullvad.net/en/servers578 servers, 50 countries, Rented vs Owned labels, named rental providers
- primary · blogmullvad.net/en/blog/we-have-successfully-completed-our-migration-to-ram-only-vpn-infrastructureRAM-only migration completion verbatim
- primary · transparency-reportmullvad.net/en/blog/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised2023-04-18 Swedish Police warrant outcome
- primary · blogmullvad.net/en/blog/introducing-defense-against-ai-guided-traffic-analysis-daitaDAITA launch 2024-05-07 + Maybenot / Karlstad University collaboration
- primary · about-pagemullvad.net/en/vpn/daitaDAITA platform rollout
- primary · blogmullvad.net/en/blog/quantum-resistant-tunnels-are-now-the-default-on-desktopPost-quantum default since 2025-01-09, Classic McEliece + ML-KEM
- primary · othergithub.com/mullvad/mullvadvpn-appGPL-3.0 main repo, language split, release count
- primary · othergithub.com/mullvad/mullvad-browserMullvad Browser MPL-2.0, joint with Tor Project, released 2023-04-03
- primary · cert-pagegithub.com/mullvad/mullvadvpn-app/blob/main/audits/README.mdFull audit ledger PDF list
- primary · about-pagemullvad.net/en/help/dns-over-https-and-dns-over-tlsPublic DNS resolver: anycast regions, endpoints, QNAME minimisation
- primary · about-pagemullvad.net/en/aboutFounder ownership statement verbatim
- registry · otherwww.allabolag.se/foretag/mullvad-vpn-ab/g%C3%B6teborg/konsulter/2KHK741I5YF3IMullvad VPN AB registration details
- primary · security-pagemullvad.net/en/help/no-logging-data-policyVerbatim no-logs list and retention periods
- primary · about-pagemullvad.net/en/serversUS server cities; user-selectable exit jurisdiction
- primary · transparency-reportmullvad.net/en/blog/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised2023-04-18 Swedish Police warrant; no data seized
- primary · privacy-policymullvad.net/en/help/how-we-handle-government-requests-user-dataGovernment-request policy verbatim
- primary · pricing-pagemullvad.net/en/pricingCash and Monero anonymous payment options
- primary · termsmullvad.net/en/help/terms-serviceAnonymous account number sign-up; Swedish Bokföringslagen 7-year retention
- primary · privacy-policymullvad.net/en/help/privacy-policyMullvad privacy policy -- enumerates Stripe (US, card processing) and Google Workspace (US, corporate MX) as the US subprocessors named in qa[1] (CLOUD Act answer)
- primary · dns-recordsmxtoolbox.com/SuperTool.aspxDNS MX evidence for the Google Workspace inbound-mail terminator on mullvad.net cited in qa[1]
Sovereignty (SHIELD)
- primary · privacy-policymullvad.net/en/help/privacy-policyStripe charge ID, PayPal transaction details, Swish enumerated
- primary · pricing-pagemullvad.net/en/pricingAccepted payment methods
- primary · about-pagemullvad.net/en/serversNamed rental providers per-server
- primary · dns-recordsmullvad.netdig MX mullvad.net = Google Workspace; bunny:303437 TXT for Bunny CDN
- primary · privacy-policymullvad.net/en/help/privacy-policyRegistered office and organisation number verbatim
- registry · otherwww.allabolag.se/foretag/mullvad-vpn-ab/g%C3%B6teborg/konsulter/2KHK741I5YF3I
- primary · about-pagemullvad.net/en/about100% founder ownership verbatim
- registry · otherwww.allabolag.se/foretag/mullvad-vpn-ab/g%C3%B6teborg/konsulter/2KHK741I5YF3IBolagsverket organisation number, board roles, financials
- registry · otherwww.northdata.com/Amagicom%20AB,%20G%C3%B6teborg/ON%205567839807
- primary · about-pagemullvad.net/en/help/owners-directive-for-mullvad-vpnOwner's Directive page
- primary · otherwww.allabolag.se/55923840-01/mullvad-vpn-abSwedish company register (Bolagsverket via allabolag.se). Swedish company register entry for Mullvad VPN AB; no subsidiary entries; sole parent is Amagicom AB (separately documented under ownership)
- primary · privacy-policymullvad.net/en/help/privacy-policyNo transfers to third countries; EU/EEA processing
- primary · security-pagemullvad.net/en/help/no-logging-data-policyRetention periods: 20 days transaction IDs, 7-year Swedish Bokföringslagen
- primary · about-pagemullvad.net/en/serversRental providers named per-server
- primary · blogmullvad.net/en/blog/mullvad-review-of-2024Support-email move to self-hosted RAM-only servers, February 2024
- primary · dns-recordsmullvad.netdig MX/NS/A/TXT/CAA: ns1-ns4.mullvaddns.net authoritative; Bunny CDN bunny:303437 TXT
- primary · about-pagemullvad.net/en/aboutNo US, UK or other foreign legal entity disclosed
- primary · privacy-policymullvad.net/en/help/how-we-handle-government-requests-user-dataSwedish jurisdiction stance verbatim
- primary · about-pagemullvad.net/en/serversUS server cities -- physical exposure mitigated by RAM-only + customer choice
- primary · termsmullvad.net/en/help/terms-serviceSwedish governing law; ARN consumer disputes; Gothenburg district court
- primary · privacy-policymullvad.net/en/help/privacy-policy
- primary · security-pagemullvad.net/en/help/no-logging-data-policy
- primary · privacy-policymullvad.net/en/help/how-we-handle-government-requests-user-dataGovernment-request stance
- primary · privacy-policymullvad.net/en/help/privacy-policyNo ISO 27001 / SOC 2 / other public certifications attributable to Mullvad VPN AB or Amagicom AB; security-audit reports are published per audit cycle (Assured AB, Cure53, Radically Open Security) but those are point-in-time audits, not standing certifications
- primary · othergithub.com/mullvad/mullvadvpn-appGPL-3.0 main repo
- primary · cert-pagegithub.com/mullvad/mullvadvpn-app/blob/main/audits/README.mdAudit ledger directory
- primary · othergithub.com/mullvad/mullvad-browserMullvad Browser MPL-2.0