Is Mullvad Safe? Security, Privacy & Audit Analysis

Is Mullvad safe? Independent audit results, encryption protocols, jurisdiction analysis, kill switch testing, and no-logs policy verification.

··9 min read
Most Secure VPNs
#1Mullvad VPN700+ servers
#2ProtonVPN20,000+ servers
#3NordVPN7,130 servers
See our methodology

Is Mullvad Safe? A Direct Assessment

Mullvad VPN

Mullvad VPN

Security & privacy

83 out of 100, built from two weighted parts

Trust & Value30% of the score23/30
VPN Performance70% of the score60/70

App store ratings, part of the score

Researched Oct 3, 2026Claims checked: 29Separate source groups: 12Scores updated Oct 8, 2026

#7 / 22 700+ servers 50+ countries 14-day money-back guarantee

Mullvad scores 83/100 on our trust index. It operates under Swedish jurisdiction, charges a flat €5/month with no accounts, and publishes a no-logs policy. Outside audits by Cure53, Assured AB and others found no customer-activity logging on the servers they were given. Mullvad says it stores zero connection logs, traffic data, or personally identifiable information on its servers.

Sweden belongs to the 14 Eyes intelligence-sharing alliance. That sounds alarming at first glance. In practice, the legal framework tells a more nuanced story for VPN providers.

Swedish law does not require VPN companies to retain user data. Mullvad has no mandatory data retention obligation under current Swedish telecommunications regulations. This means authorities can issue requests, but Mullvad has nothing stored to hand over.

In April 2023, Swedish police physically entered Mullvad’s office in Gothenburg with a search warrant. Officers intended to seize computers containing customer data. Mullvad staff explained no customer data existed on any machines, and police left empty-handed. That real-world test proved the no-logs policy holds under legal pressure.

Independent Audit History

Mullvad has published reports from several outside security firms. Each examined different parts of the infrastructure or apps, and Mullvad commissioned all of them.

Cure53 Infrastructure Audit (2020)

Cure53, a Berlin-based penetration testing firm, audited Mullvad’s infrastructure in November and December 2020. It found six vulnerabilities and six miscellaneous issues, up to high severity, and raised concerns about container design and defense in depth. It was unable to discover any personally identifiable information attached to end users. Mullvad says all findings were resolved, and the report is public.

Assured AB Relay Server Audit (2022)

Assured AB audited three Mullvad relay servers (two WireGuard, one OpenVPN) from April to May 2022 and wrote that the configuration is sound and showed no signs of direct customer information. Mullvad’s own account says the audited servers were freshly provisioned machines that no customers connected to.

Radically Open Security Audit (2023)

Radically Open Security tested two RAM-only Mullvad servers in May and June 2023 and found no logging of user activity data. It wrote that it could not validate that real production machines are set up the same way, and it flagged that administrators with SSH access could technically tap production VPN traffic. Mullvad said it was implementing command auditing and investigating removing SSH.

Cure53 Staging Server Audit (2024)

Cure53 audited one OpenVPN and one WireGuard staging server in June 2024, found two issues (one low, one medium) and found no way to compromise user traffic anonymity or integrity.

X41 D-Sec App Audit (2024)

X41 D-Sec audited the Mullvad apps for Android, iOS and desktop from October to November 2024. It found six vulnerabilities (none critical, three high, two medium, one low), concluded the apps have a high security level, and Mullvad fixed them.

Mullvad publishes these reports, which is uncommon in the VPN industry. Every audit was commissioned by Mullvad, covers a point in time, and none examined production servers, so the reports show what auditors found on the machines they were given, not continuous verification.

Logging Policy: What Mullvad Stores and Doesn’t Store

Data Mullvad Does Not Collect

Mullvad does not log traffic data, connection timestamps, session durations, or IP addresses. It stores no DNS queries, bandwidth usage records, or VPN server assignments. Account activity remains completely unlinked to browsing behavior or connection metadata.

Data Mullvad Does Process

Mullvad processes the total number of simultaneous connections per account (capped at 5). This counter exists in real time and is not written to any persistent storage. The moment you disconnect, that counter decrements. No historical record persists.

Mullvad also processes short-term aggregate server load data for performance optimization. This data contains zero user-identifiable information and rotates automatically.

The Account System

Mullvad generates a random 16-digit account number. No email, no name, no password required. You can pay with cash mailed in an envelope, Bitcoin, or Monero. This design eliminates personally identifiable information from the signup process entirely.

Encryption Standards and Protocols

Mullvad supports two protocols: WireGuard and OpenVPN. Both implementations use strong, well-reviewed cryptographic standards.

WireGuard Implementation

WireGuard uses ChaCha20 for symmetric encryption, Curve25519 for key exchange, and BLAKE2s for hashing. Mullvad defaults to WireGuard on all platforms. Connection handshakes complete in under 100 milliseconds on most networks.

OpenVPN Implementation

OpenVPN connections use AES-256-GCM for data channel encryption. Key exchange relies on RSA-4096 certificates with SHA-512 authentication. Mullvad configures OpenVPN with tls-auth to prevent fingerprinting and DDoS attacks on the VPN tunnel.

Quantum-Resistant Tunnels

Mullvad added post-quantum key exchange to WireGuard tunnels in 2023. This feature layers Classic McEliece and Kyber key encapsulation on top of standard WireGuard cryptography. Mullvad was the first commercial VPN to ship this feature across desktop platforms.

Kill Switch and DNS Leak Protection

Kill Switch Behavior

Mullvad’s kill switch activates by default on all platforms. It blocks all internet traffic when the VPN tunnel drops unexpectedly. The implementation operates at the firewall level, not the application level. This prevents leaks even if the Mullvad app crashes entirely.

On Linux, Mullvad uses nftables rules to enforce traffic blocking. On Windows, it modifies the Windows Filtering Platform. On macOS, it uses packet filter rules. Each implementation prevents both IPv4 and IPv6 leaks simultaneously.

DNS Leak Protection

Mullvad routes all DNS queries through its own encrypted DNS servers. The app blocks system DNS requests that attempt to bypass the tunnel. Mullvad operates DNS servers on every VPN server location, resolving queries locally without forwarding to third parties.

Users can also configure custom DNS within the app. Even with custom DNS, queries still travel inside the encrypted tunnel. Independent leak tests consistently show zero DNS, WebRTC, or IPv6 leaks across all Mullvad clients.

Past Security Incidents

Police Raid (April 2023)

Six officers from the Swedish National Police entered Mullvad’s Gothenburg office. They carried a district court search warrant seeking customer information. Mullvad’s CEO explained the company stores no customer data. Police seized no equipment and left after Mullvad’s legal team challenged the warrant’s applicability.

No Known Data Breaches

As of the latest audit cycle, Mullvad has reported zero data breaches. No user data has appeared in leaked databases. No credential stuffing attacks apply because Mullvad uses no passwords or email addresses. The 16-digit account number system limits attack surface substantially.

Vulnerability Disclosures

Mullvad maintains an active bug bounty approach and publishes security advisories on its blog. Mullvad says the vulnerabilities found during audits were fixed. The company has not experienced any zero-day exploitation of its production infrastructure.

Unique Security Features

DAITA (Defense Against AI-Guided Traffic Analysis)

Mullvad developed DAITA to counter traffic analysis attacks. This feature pads packets to uniform sizes and injects decoy traffic patterns. It prevents adversaries from identifying which websites users visit based on traffic fingerprints.

Encrypted DNS Over HTTPS (DoH)

Mullvad offers a public DoH service at dns.mullvad.net. Users can encrypt DNS queries even without the VPN running. The service includes optional ad-blocking and tracker-blocking DNS profiles.

Diskless RAM-Only Servers

Mullvad runs its entire server fleet in RAM-only mode. No hard drives exist in the servers. Every reboot wipes all data completely. This architecture ensures that physical server seizures yield zero usable information.

Multihop Routing

Users can route traffic through 2 separate VPN servers in different countries. This adds a second encryption layer and separates the entry point from the exit point. Multihop is configurable directly within the app without manual setup.

The Bottom Line on Mullvad’s Security

Mullvad earns its 83/100 trust score through architecture, not promises. RAM-only servers, account anonymity, published audit reports, and a verified police raid outcome set it apart. The €5/month flat rate with no trials or discounts reflects a company focused on service rather than subscriber volume. For users who prioritize privacy verification over feature count, Mullvad remains one of the strongest options available across its server network.

Resources for this page

Charts and reference images from our research, free to view and share.

  • Mullvad protecting a laptop and phone with audits, no logs, leak controls, kill switch, and RAM-only servers.
    Mullvad combines independently reviewed apps, leak controls, and infrastructure designed to minimize retained session data.

Frequently Asked Questions

Is Mullvad actually safe to use?

Yes. Mullvad scores 83/100 on our trust index, backed by a published no-logs policy, RAM-only servers that wipe on every reboot, and several outside audits. Cure53 audited the infrastructure in 2020 and a staging server in 2024, Assured AB audited relay servers in 2022, and X41 D-Sec audited the apps in 2024. None examined production servers, and Mullvad published the reports.

Does Mullvad’s Swedish jurisdiction expose user data since Sweden is a 14 Eyes member?

Not in practice. Swedish law imposes no mandatory data retention obligation on VPN providers, so Mullvad has nothing to hand over even if authorities request it. That held up in April 2023 when Swedish police entered Mullvad’s Gothenburg office with a search warrant seeking customer records and left without seizing anything, since no such data existed.

What happened during the 2023 Swedish police raid on Mullvad?

Six officers from the Swedish National Police entered Mullvad’s Gothenburg office in April 2023 carrying a district court warrant seeking customer information. Mullvad’s CEO explained the company retains no customer data by design. Police left without seizing equipment or data, a real-world test of the no-logs claim under direct legal pressure.

What did Cure53’s audits of Mullvad find?

Cure53’s 2020 infrastructure audit found six vulnerabilities and six miscellaneous issues, up to high severity, and could not discover any personally identifiable information attached to end users. Mullvad says all findings were resolved. Cure53’s June 2024 audit of two staging servers found two issues (one low, one medium) and no way to compromise user traffic anonymity or integrity. Neither audit examined production servers.

What did the Assured AB audit cover?

Assured AB audited three Mullvad relay servers (two WireGuard, one OpenVPN) from April to May 2022 and wrote that the configuration is sound and showed no signs of direct customer information. The servers were freshly provisioned for the audit, so the result does not cover the production fleet. Together with the Cure53 and Radically Open Security audits of servers and the X41 D-Sec audit of the apps, Mullvad has published outside reviews of both its apps and its server setup.

How does Mullvad’s anonymous account system actually work?

Mullvad generates a random 16-digit account number instead of requiring an email, name, or password. You can pay by card, Bitcoin, Monero, or cash mailed in an envelope. This design strips personally identifiable information from signup entirely, which is part of why its no-logs policy held up during the 2023 police raid on its Gothenburg office.

What encryption does Mullvad use, and is it quantum-resistant?

Mullvad defaults to WireGuard, using ChaCha20 for encryption, Curve25519 for key exchange, and BLAKE2s for hashing. Its OpenVPN option uses AES-256-GCM with RSA-4096 certificates. In 2023, Mullvad added post-quantum key exchange layering Classic McEliece and Kyber on top of standard WireGuard, making it the first commercial VPN to ship this across desktop platforms.

What information does Mullvad actually collect about my account?

Very little. Mullvad tracks only the number of simultaneous connections in real time, capped at 5, which decrements to zero the moment you disconnect and is never written to persistent storage. It also processes short-term aggregate server load data with no user-identifiable information. Traffic, timestamps, DNS queries, and IP addresses are never logged.

Does Mullvad’s kill switch reliably block leaks if the connection drops?

Yes. Mullvad’s kill switch runs at the firewall level rather than the application level, so it keeps blocking traffic even if the app itself crashes. It uses nftables on Linux, the Windows Filtering Platform on Windows, and packet filter rules on macOS, preventing both IPv4 and IPv6 leaks across every implementation.

Does Mullvad offer a free trial or refund if I’m not satisfied?

No, Mullvad runs pay-as-you-go with no free trial period. Instead of a standard refund window, unused days on your account balance are refundable if you decide to stop. This differs from ProtonVPN and NordVPN, which both back paid plans with a 30-day money-back guarantee rather than a pro-rated refund model.

How many devices can I run on one Mullvad account?

A single Mullvad account covers 5 simultaneous connections, less than NordVPN’s 10 and within the 1-10 range ProtonVPN offers depending on plan tier. Mullvad has no per-device account requirement since signup uses only a 16-digit number, so devices connect independently without linking to personal identity.

How does Mullvad’s flat pricing compare to ProtonVPN and NordVPN?

Mullvad charges a single flat rate from $5.50/month with no long-term discount tiers, unlike ProtonVPN (from $3.49/month on its longest plan) and NordVPN (from $3.49/month). On performance, Mullvad ranks #7 of 22 in our Speed Lab, behind NordVPN at #1 but ahead of ProtonVPN at #12.

Can I access Netflix or Disney+ reliably through Mullvad?

Inconsistently. Mullvad doesn’t build dedicated technology to get past streaming geo-blocks, so major platforms like Netflix, Disney+, and Prime Video are often blocked outright. It does support BBC iPlayer, 9Now, and Channel 4, with results varying by server. If dependable major-platform streaming matters most, a provider with dedicated streaming infrastructure is a better fit.

What if Mullvad gets blocked on a restrictive or firewalled network?

Switch to Mullvad’s obfuscation and QUIC settings, built specifically to disguise VPN traffic and get past network-level blocking. Multihop routing, which sends traffic through two separate servers in different countries, can also help if a single exit point is being filtered. Test these settings before you rely on the connection in a restrictive environment.