# URnetwork vs Mullvad

Mullvad is the most proven datacenter VPN; URnetwork splits the path so the
exit never learns who you are and the operator cannot read the sealed session.

**Choose Mullvad** if you value a long audit record, stable datacenter servers,
and cash payments. **Choose URnetwork** if you want residential exits, city
selection, and a split path. Both support anonymous accounts and post-quantum
encryption. Mullvad is more proven. URnetwork splits visibility between its
operator and a member-run provider.

[Mullvad](https://mullvad.net) is run by Amagicom AB in Gothenburg, Sweden.
Privacy researchers measure other VPNs against it. It has held a flat €5 per
month for its whole life, with no discounts and no free tier.

URnetwork uses member-run exits. The provider does not receive your source IP
on the relayed path. Native apps seal traffic to the provider by default.
[How URnetwork works](/docs/overview) explains the full design. The
[threat model](/docs/threat-model) holds the complete record of what is stored
and enforced.

## Six differences that affect the choice

| | Mullvad | URnetwork |
|---|---|---|
| Trust model | One company, engineered to hold minimal data | Two relay parties; the exit never sees your IP, and the operator cannot read the sealed session |
| Exit address | Datacenter ranges, publicly listed, widely blocked by streaming and retail sites | Residential addresses; ordinary traffic to the sites you visit |
| Coverage and targeting | ~580 servers, 50 countries, 91 cities (live public list, mid-2026); pick a server | Member devices in 90+ countries; browse countries, search for a city |
| External verification | Published audit reports since 2018; a 2023 raid found nothing | Open client and server code; no independent audit of the protocol or server code yet |
| Consistency | Diskless datacenter fleet; predictable | Member uplinks; speed moves with the provider |
| Payment without a trail | Cash by post, Monero, vouchers | One-tap account with no email; on-chain USDC |

Caveats below the table:

- Post-quantum encryption is parity, on by default on both sides. Mullvad's
  quantum-resistant tunnels are default on desktop and a setting on mobile.
  URnetwork's X25519MLKEM768 client-to-provider session is default in the
  native apps, skipping any provider it cannot seal to rather than
  downgrading. The browser extension has no sealed session; there, the
  operator's data path logs nothing, pinned by a test in the open code.
- DAITA, Mullvad's cover-traffic defense against traffic analysis, has no
  URnetwork equivalent. It is native on about a fifth of Mullvad's servers and
  reached by automatic multihop from the rest.
- Both cover Android, iOS, macOS, Windows, and Linux, each with an explicit
  kill switch. URnetwork adds a browser extension paired with its web app.
- Mullvad is €5/month, flat. URnetwork Pro is $5/month or $40/year, with a
  free daily data allowance. Current numbers are at
  [ur.io/products](https://ur.io/products).

## Privacy track record

In April 2023, officers of the Swedish police's National Operations Department
arrived at Mullvad's Gothenburg office with a search warrant for customer
data. They left with nothing, because the data sought did not exist. It was
the first warrant in the company's 14-plus years. It remains the industry's
best adversarial, unscheduled test of a no-logs claim.

The audit record is the deepest published in the industry: reports since 2018
from Assured, Cure53, Atredis, X41, NCC Group, and Leviathan. 2026 alone
brought three external assessments. X41 audited the payment and account
backend in January. Assured audited Mullvad's in-house WireGuard
implementation in March. Leviathan ran its standardized MASA assessment of the
Android app in June. All Mullvad apps are open source, and the Android app has
had reproducible builds since 2025. Desktop builds are not reproducible yet,
and the server side is not published.

URnetwork's Android app holds an assessment from the same lab under the same
programme: Leviathan, MASA assurance level AL2, completed May 2025, passed. It
is the same standardized checklist. It carries the same weight for both
products and settles nothing about either operator's servers. URnetwork is the
more open codebase; Mullvad is the more verified one.

Two more dated events belong on the record.

- May 2026: a third-party post showed that exit-IP assignment let sites link
  one device across Mullvad server switches, without identifying it. Mullvad
  published within five days and announced a new assignment scheme to remove
  the correlation.
- July 2026: Mullvad published a statement on a co-owner's personal donation
  of about SEK 5 million to a Swedish political party. It called the donation
  private and said the company "does not condone it, nor condemn it". No user
  data or technical guarantee was involved. It belongs on this list because in
  a single-company model, ownership is part of what you trust.

Audits, industry-wide, are paid, scoped, and point-in-time. The raid is
stronger evidence because it was adversarial and unscheduled, and Mullvad
passed it.

![How you verify a privacy claim — point-in-time audits vs court and raid evidence vs open continuous verification](/docs-assets/infographic-verification.svg)

*Mullvad's 2023 raid is the strongest example of the middle kind of evidence.
URnetwork's is the third kind: open code anyone can check on any day, with no
independent examination of the protocol or the operator's server code yet.*

## Datacenter consistency, residential variance

Mullvad's fleet is the disclosure benchmark of the industry. A live public
page and API list every server's city, hosting company, online status, and an
owned-or-rented flag. About a fifth of servers are owned outright; the rest
are rented from hosts Mullvad names. Every server has run diskless since 2023
on Mullvad's System Transparency stack. The fleet is WireGuard-only; OpenVPN
was removed in January 2026 after fourteen months of notice. There are no
virtual locations, and IPinfo's December 2025 study (updated April 2026)
confirmed that from outside.
Mozilla VPN runs on Mullvad's network, and Tailscale sells Mullvad exit nodes.

![Advertised locations vs measured reality — share of advertised locations measured virtual or unmeasurable per provider (IPinfo, December 2025)](/docs-assets/infographic-virtual-locations.svg)

*Mullvad, IVPN and Windscribe measured 0% virtual. URnetwork appears as a
mechanism rather than a percentage, because a provider is the presence.*

The same fleet is Mullvad's most common everyday failure. Its ranges are
publicly known, so many streaming and retail sites block them wholesale.
URnetwork's exits are residential addresses, and their traffic is ordinary to
the sites that receive it.

Coverage is checked differently on each side. Mullvad's list can be verified
server by server, and has been measured from outside. URnetwork's answer is
structural: a location exists only while a member's device is online in it, so
presence cannot be fabricated the way a registered IP range can. Live counts
are published without a login at api.bringyour.com/stats/last-90. Nobody has
run IPinfo's study on URnetwork.

Consistency runs Mullvad's way. Its servers behave the same every day.
URnetwork's speed moves with each member's uplink; URnetwork puts its average
streaming speed at 40 Mbps+.

## Payments and identity

Mullvad issues numbered accounts with no email and no name. It takes cash by
post, Monero, bitcoin, vouchers, and cards. Its own policy documents what card
and PayPal payments leave behind: PayPal name, email, and country; card type,
country, and last four digits; a transaction-to-account link deleted after
about 20 days; bookkeeping kept seven years under Swedish law. That trail
exists at any VPN that takes cards, URnetwork included. Cash and Monero leave
no such trail.

URnetwork's Instant Account is created in one tap with no email. A recovery
seed phrase, issued once and stored only as hashes, restores the account after
a reinstall. The phrase is a URnetwork credential. URnetwork never asks for a
crypto wallet's seed phrase or private key. Sign-in by Solana or Bittensor
wallet signature is an alternative, and Pro can be paid in on-chain USDC. USDC
is pseudonymous; its anonymity depends on your wallet's history.

One difference runs each way. Only Mullvad takes cash in an envelope, which
appears on no ledger. Only URnetwork opens an account with nothing typed at
all, and adds wallet-native identity.

## Where Mullvad wins

- Payment with no trail at all. Posted cash and Monero appear on no ledger.
  URnetwork's USDC lives on a public chain.
- Proof under pressure. The 2023 raid found nothing. URnetwork's storage
  design is open code, but no court or raid has tested it.
- External verification. Published audit reports since 2018, three assessments
  in 2026 alone, and reproducible Android builds. URnetwork has no audit of
  its protocol or server code.
- Fleet disclosure. A live server list names each server's city, hosting
  company, and ownership, with no virtual locations.
- Traffic-analysis defense. DAITA has no URnetwork equivalent.

## Where URnetwork wins

- The split. The exit never learns who you are, and the operator cannot read
  the sealed session. No single party holds identity and destinations
  together.
- The exit address. Residential IPs work where Mullvad's known ranges are
  blocked outright.
- Reach and aim. Exits in more than 90 countries versus 50, searchable down to
  a city.
- One-tap anonymity. An Instant Account with no email, restored on a new
  device by its recovery phrase.
- Price. $40/year against €60/year, plus a free tier with a daily data
  allowance.
- Whole-stack source. The server code is public, not only the apps.
- The supply side. Members can share their connection as participants in the
  [UR protocol](https://ur.xyz). Mullvad has no equivalent role.

## Limits and evidence

URnetwork's main limits:

- No independent audit covers the protocol, the connect engine, or the
  operator's server code. Two 2025 third-party assessments cover other
  surfaces: a penetration test of the web application and API (April–May
  2025), and the Leviathan MASA AL2 assessment of the Android app, which
  passed. Leviathan writes that its assessment "should not be read as a
  holistic security evaluation or comprehensive penetration test." Neither
  examined logging, retention, or the data path.
- The split assumes the operator and the providers in your window are
  independent. Nothing in the system attests that independence, and no outside
  party has measured the fleet. See the [threat model](/docs/threat-model),
  §6.1.
- The WireGuard-compatible fallback endpoint assigns one stable tunnel
  address, so several providers could recognize the same client across
  sessions. The native tunnel is the recommended path.
- Coverage counts are self-published. Mullvad's zero-virtual-location result
  was measured from outside; URnetwork's has not been.

Mullvad's limit is structural. Its server terminates your tunnel, so one
position can see your real IP and your destinations together. Its own multihop
chains two Mullvad servers, which is cover against a network observer, not
against Mullvad. Everything else in the design works to keep that position
empty, and the raid is the evidence that it has.

Trying URnetwork costs nothing: the Instant Account takes one tap and no
email, so you can test it against your own sites before paying for either
product. More questions are answered in the [FAQ](/docs/faq).
