Europe Alternatives
Mullvad VPN logo

Mullvad VPN

Gothenburg-headquartered founder-owned VPN with RAM-only servers, anonymous account numbers and no US legal entity.

🇸🇪 Sweden

Profile last updated: · View sources

About Mullvad VPN

Mullvad VPN is operated by Mullvad VPN AB (Bolagsverket organisation number 559238-4001, Box 53049, 400 14 Gothenburg, Sweden), wholly owned by parent Amagicom AB (organisation number 5567839807) which is in turn 100% owned by founders Fredrik Strömberg and Daniel Berntsson. The VPN service launched in March 2009 and has never raised venture capital, private equity or taken outside capital.

Sign-up requires no email, no username and no password: Mullvad generates a random 16-digit account number that is the user's sole credential. Pricing is a flat EUR 5 per month, unchanged since 2009. The 578-server fleet runs across 50 countries on a fully RAM-only / diskless infrastructure (migration completed 2023-09-20) booted via Mullvad's stboot bootloader from a signed image -- there is no disk-resident state to seize. Apps for Windows, macOS, Linux, iOS and Android ship under GPL-3.0 at github.com/mullvad/mullvadvpn-app.

Features

  • Flat EUR 5/month, unchanged since 2009; pay via cash (9 currencies), Monero, card, PayPal, SEPA or Swish -- 10% discount on crypto
  • Anonymous 16-digit account number replaces email / username / password; with cash or Monero, account is anonymous end-to-end
  • No-logs policy on traffic / DNS / connection / IP / bandwidth; nginx retains 5-minute access logs with IP excluded
  • 578-server VPN fleet across 50 countries; full RAM-only / diskless migration completed 2023-09-20; stboot signed-image boot
  • 2023-04-18 Swedish Police raid on the Gothenburg office left empty-handed -- no customer data existed to seize
  • DAITA (Defense Against AI-guided Traffic Analysis) on Windows / macOS / Linux / iOS / Android; pads + injects cover traffic
  • Post-quantum WireGuard tunnels default on desktop since Jan 2025 -- Classic McEliece + ML-KEM hybrid against store-now-decrypt-later
  • Apps open source under GPL-3.0 at github.com/mullvad/mullvadvpn-app; Mullvad Browser (Tor-fork sans Tor Network) free under MPL-2.0
  • ~14 published security audits since 2018 (Cure53, Assured AB, Radically Open Security, X41 D-Sec, NCC Group, Leviathan) on apps + infra
  • Free encrypted DNS resolver (DoH / DoT) anycasted from DE / UK / SE / SG / US; QNAME minimisation; available to anyone

Sovereignty Scorecard

Procurement-grade signals on data sovereignty, ownership, and EU residency.

The SHIELD framework

We score every European vendor against six sovereignty dimensions captured in the SHIELD acronym. Each card below maps to one letter — read them as a checklist when comparing providers.

S
Subprocessors

The third parties that touch customer data — payment processors, KYC vendors, support chatbots, analytics.

H
Headquarters & ownership

Where the legal entity sits, who controls it, and which subsidiaries operate under the same group.

I
Infrastructure & residency

Where customer data is physically stored, who runs the hosting stack, which CDN sits in front.

E
Exposure

Whether the vendor or its subprocessors fall under the US CLOUD Act or other extraterritorial reach.

L
Legal documents

Public terms, privacy policy, DPA, subprocessor list, impressum, and security or trust pages.

D
Diligence

Independent audits and certifications (ISO 27001, BSI C5, TISAX, SOC 2) plus open-source transparency.

Ownership

Privately held

Full European control

Mullvad VPN AB (Bolagsverket 559238-4001, Gothenburg) is wholly owned by Amagicom AB (5567839807, same Gothenburg address). Amagicom AB is in turn 100% owned by Swedish founders Fredrik Strömberg (board deputy of Mullvad VPN AB) and Daniel Berntsson (board member). The about page states verbatim: 'Both Mullvad VPN AB and our parent company Amagicom AB are 100% owned by us, the founders Fredrik Strömberg and Daniel Berntsson, who are actively involved in the company.' No outside venture capital, private equity, IPO or foreign holding company has ever entered the cap table. Founded in March 2009; the Mullvad VPN AB legal entity was registered in January 2020 as a carve-out of the VPN operation from Amagicom AB. An Owner's Directive at mullvad.net/en/help/owners-directive-for-mullvad-vpn binds management to the privacy mission.

Headquarters

🇸🇪 Gothenburg, Sweden

Mullvad VPN AB

Data residency
SE
EEA

Fixed region

Account, subscription and inventory data are processed within the EU/EEA -- the privacy policy states there are no transfers to third countries for that data. Card-payment data (Stripe, US) is the exception: users who pay by card have that transaction processed in the US; users who pay by cash, Monero, PayPal (Luxembourg), Swish (Sweden), SEPA or bank wire stay entirely within EU/EEA processors. Transaction IDs are retained 20 days; statutory accounting records up to 7 years per the Swedish Bokföringslagen. The VPN server fleet is geographically distributed across 50 countries because customers choose the exit jurisdiction; each server runs RAM-only with no disk-resident logs, so the residency picture for the VPN traffic is the exit country selected by the customer, not a residency commitment for stored data (because there is no stored traffic data).

Hosting infrastructure

Website: Self-hosted on Mullvad-controlled infrastructure behind nginx; HSTS preload enforces HTTPS; CAA restricts certificate issuance to Let's Encrypt; SvelteKit front end. Mullvad moved the customer-facing support email infrastructure to self-hosted RAM-only servers in February 2024 per the 2024 year-in-review.

Application: 578 VPN servers across 50 countries (548 online at observation time), 100% RAM-only / diskless since 2023-09-20. Servers boot via Mullvad's stboot bootloader on the open-source System Transparency project. Each server is publicly labelled Rented or Owned on the servers page; named rental providers include 100TB, Blixnet, Creanova, DataPacket, HostRoyal, iRegister, M247, PrivateLayer, techfutures, Tzulo, Velox, xtom and Zenlayer.

Email: Self-hosted RAM-only mail for customer support since February 2024; Google Workspace remains the inbound MX terminator on mullvad.net for non-support corporate mail (aspmx.l.google.com)

CDN: Mullvad runs its own authoritative DNS for mullvad.net and mullvadvpn.net (ns1-ns4.mullvaddns.net); Bunny CDN is referenced via a DNS TXT verification (bunny:303437)

Subprocessors
NameCountryPurpose
Stripe, Inc.🇺🇸 United StatesCredit-card payment processing; per the privacy policy Mullvad stores Stripe charge ID, expiration date, last 4 card digits, card type and country of origin, with transaction IDs retained 20 days
PayPal (Europe) S.à r.l. et Cie, S.C.A.🇱🇺 LuxembourgPayPal payment processing for EU customers; Mullvad stores the transaction ID, sender's name, country of origin and email address, retained 20 days
Getswish AB (Swish)🇸🇪 SwedenSwedish instant-payment network; identifying (transaction ID, name, phone number); Sweden-domestic
Google LLC (Google Workspace)🇺🇸 United StatesInbound MX terminator for non-support corporate mail on mullvad.net (aspmx.l.google.com observed). Customer-facing support email was moved to self-hosted RAM-only servers in February 2024 per the 2024 year-in-review.
Bunny CDN (BunnyWay d.o.o.)🇸🇮 SloveniaAsset CDN referenced via DNS TXT verification (bunny:303437). EU-domiciled.
Colocation providers for VPN server fleet MultipleMullvad publishes the per-server rental provider on the servers page; named providers include 100TB, Blixnet, Creanova, DataPacket, HostRoyal, iRegister, M247, PrivateLayer, techfutures, Tzulo, Velox, xtom and Zenlayer. Each rented server runs Mullvad-provisioned RAM-only OS images; the provider sees the physical hardware and bandwidth, not customer traffic content or logs.
Legal documents
Terms of ServicePrivacy Policy
Data Processing AgreementNot published
ImpressumNot published
Security
US CLOUD Act exposure
Partial, via US subprocessors
Open source
Has open components
View source

Pricing

Mullvad VPN

EUR 5/month

flat, monthly, unchanged since 2009
  • Up to 5 devices per account; 14-day money-back guarantee on card / PayPal / bank wire payments (cash and crypto are non-refundable)
  • Anonymous payment methods: physical cash mailed in nine currencies (EUR, USD, GBP, SEK, NOK, CHF, CAD, AUD, NZD) and Monero (Mullvad runs its own XMR node) -- 10% discount on cryptocurrency
  • Identifying payment methods: bank wire, credit card (via Stripe), PayPal, Swish, EPS, Bancontact, iDEAL, Wero, Przelewy24, voucher codes -- transaction IDs retained 20 days, statutory accounting retained 7 years per the Swedish Bokföringslagen

Questions & Answers

5 questions

Who owns Mullvad, and where is the company headquartered?

Mullvad VPN AB is registered with Bolagsverket as organisation number 559238-4001 at Box 53049, 400 14 Gothenburg, Sweden, with a visible office at Engelbrektsgatan 28. Its sole shareholder is Amagicom AB (organisation number 5567839807, same Gothenburg address), and Amagicom AB is in turn 100% owned by founders Fredrik Strömberg and Daniel Berntsson, who remain actively involved in the company. The about page states this verbatim: 'Both Mullvad VPN AB and our parent company Amagicom AB are 100% owned by us, the founders Fredrik Strömberg and Daniel Berntsson, who are actively involved in the company.' No venture capital, private-equity money, IPO or foreign holding entity sits above the group -- a distinguishing feature among consumer VPNs, where competitors typically sit under PE-style holding structures.

Is Mullvad subject to the US CLOUD Act?

The Mullvad group has no US-incorporated entity. Mullvad VPN AB and Amagicom AB are both Swedish aktiebolag in Gothenburg, both founder-owned, and no US, UK or other foreign subsidiary is disclosed in any public source. There is therefore no corporate Mullvad entity the US CLOUD Act could compel directly. Mullvad does use two US subprocessors -- Stripe Inc. for credit-card payment processing (card data only; users who pay in cash, Monero or via Swish/SEPA do not touch Stripe) and Google LLC for the inbound MX terminator on non-customer-facing corporate mail (customer-facing support email was self-hosted in 2024) -- both of which are themselves CLOUD-Act-reachable, but neither sees VPN traffic, DNS queries or connection metadata. Mullvad does operate VPN servers physically located in the United States across roughly 19 cities; those are subject to in-country law-enforcement compulsion at the colocation level, but Mullvad's RAM-only / no-logs architecture means there is no historical customer data to hand over, and customers can choose to avoid US (or any other Five-Eyes) exit servers entirely.

What does Mullvad actually log, and how was the no-logs policy stress-tested?

Per the no-logs policy at mullvad.net/en/help/no-logging-data-policy: 'no logging of traffic, no logging of DNS requests, no logging of connections (including when one is made and when it disconnects), no logging of IP addresses, no logging of user bandwidth.' The data Mullvad does retain is limited to the random 16-digit account number, account expiry, the WireGuard public key and tunnel address when WireGuard is in use, short-retention payment metadata (20 days for transaction IDs) and statutory accounting records retained up to 7 years per the Swedish Bokföringslagen. The Swedish Police National Operations Department executed a search warrant on the Gothenburg office on 2023-04-18 -- the first in 14 years of operation -- and left empty-handed because there was no customer data to seize.

How can I sign up without giving Mullvad personal information?

Mullvad generates a random 16-digit account number on demand at mullvad.net/account/create; no email, no username and no password are required. Pay anonymously by mailing physical cash in any of nine currencies (the envelope is destroyed after the cash is counted) or by sending Monero to Mullvad's own XMR wallet. Cash payments are non-refundable per AML rules; Mullvad records only the amount, the currency and the timestamp. Card, PayPal, bank wire and Swish are accepted but link the account to a name; in those cases the transaction ID is deleted after 20 days while statutory accounting records are retained 7 years per the Swedish Bokföringslagen.

What happens if a government compels Mullvad to hand over user data, or to spy on a user?

Mullvad's verbatim stated policy at mullvad.net/en/help/how-we-handle-government-requests-user-data: 'We must -- and do -- make it impossible for us to fulfill any data request. There is simply no data to request, nor confiscate in the case of physical seizure.' On the question of being compelled to spy, the company adds: 'we will cease operation of our service in the affected jurisdiction and only resume it if the legal situation has been remedied.' Swedish law currently does not allow forced surveillance assistance. The 2023-04-18 Gothenburg search warrant is the only real-world stress test on record; Mullvad demonstrated the no-logs architecture, the prosecutor was consulted and no data was seized.

Alternatives

Other European companies in the same category as Mullvad VPN.

Quick facts

Languages supported
AR
Dansk
Deutsch
English
Español
FA
Suomi
Français
Italiano
日本語
KO
Nederlands
Norsk
Polski
Português
RU
Svenska
TH
TR
Українська
中文
Alternative to

Sources & verification

Every fact on this page is backed by a primary or independent source. Most recent verification: May 15, 2026.

Found an error? Report it

Citations

Profile content

Tagline
Description
Pricing
Features
Q&A

Sovereignty (SHIELD)

SSubprocessors
HHeadquarters
HOwnership
HSubsidiaries
  • primary · otherwww.allabolag.se/55923840-01/mullvad-vpn-abSwedish company register (Bolagsverket via allabolag.se). Swedish company register entry for Mullvad VPN AB; no subsidiary entries; sole parent is Amagicom AB (separately documented under ownership)
IData residency
IHosting infrastructure
EUS CLOUD Act exposure
LLegal documents
DCertifications
  • primary · privacy-policymullvad.net/en/help/privacy-policyNo ISO 27001 / SOC 2 / other public certifications attributable to Mullvad VPN AB or Amagicom AB; security-audit reports are published per audit cycle (Assured AB, Cure53, Radically Open Security) but those are point-in-time audits, not standing certifications
DOpen source