{
  "slug": "mullvad-vpn",
  "category": "vpns",
  "name": "Mullvad VPN",
  "description": "Flat-priced VPN from Sweden. Accounts are a random number with no email, and payment in cash or Monero is accepted.",
  "website": "https://mullvad.net",
  "source": "https://github.com/mullvad/mullvadvpn-app",
  "license": "GPL-3.0",
  "platforms": [
    "windows",
    "macos",
    "linux",
    "android",
    "ios"
  ],
  "jurisdiction": {
    "code": "SE",
    "name": "Sweden",
    "eyes": "Fourteen Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": true,
  "pick_reason": "No email, no name and no card needed. A stable, flat price, WireGuard on every platform, fully open-source apps, and repeated public audits of both the apps and the server infrastructure.",
  "disclosure": null,
  "grade": "B",
  "score": 79,
  "coverage": 100,
  "summary": "Mullvad VPN scores 79 out of 100 (grade B) on the VPN providers criteria. It meets 8 of 12 criteria: no trackers or telemetry, no ads or data sales, independent audit, TLS configuration, security headers, anonymous payment, open-source apps and modern protocols. It partly meets open source, transparency report and audited no-logs policy. It does not meet tells users about requests. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/vpns/mullvad-vpn/",
  "markdown": "https://privacyratings.com/vpns/mullvad-vpn/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/mullvad/mullvadvpn-app/blob/main/LICENSE.md",
      "note": "All apps are open source under GPL-3.0. Server infrastructure is not fully published."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://mullvad.net/en/help/no-logging-data-policy",
      "note": "The policy states no usage data is sent to external analytics. The Android app has no known trackers on Exodus."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://mullvad.net/en/pricing",
      "note": "One flat monthly price. No ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.x41-dsec.de/static/reports/X41-Mullvad-Audit-Public-Report-2026-01-20.pdf",
      "note": "Full public reports are published, including X41 D-Sec on account and payment services and Cure53 on the relay infrastructure."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://mullvad.net/en/help/swedish-legislation",
      "note": "Explains which Swedish laws allow authorities to request data and what can be disclosed. No request counts are published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mullvad.net&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mullvad.net",
      "note": "Grade A+ (135/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "no_logs_audited": {
      "title": "Audited no-logs policy",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://www.assured.se/publications/Assured_Mullvad_relay_server_audit_report_2022.pdf",
      "note": "The relay audits that checked for logging are older than three years. The no-logging policy is published."
    },
    "anonymous_payment": {
      "title": "Anonymous payment",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://mullvad.net/en/pricing",
      "note": "Accounts are a generated number. Cash, Monero and Bitcoin are accepted."
    },
    "open_source_clients": {
      "title": "Open-source apps",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://github.com/mullvad/mullvadvpn-app",
      "note": "Apps for every platform are open source under GPL-3.0."
    },
    "modern_protocols": {
      "title": "Modern protocols",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://mullvad.net/en/help/wireguard-and-mullvad-vpn",
      "note": "WireGuard is the default protocol."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:13:54.823Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}