Sources agree
Cure53 audited Mullvad's infrastructure in November-December 2020 (first infrastructure audit) and was unable to discover any personally identifiable information attached to end-users; the report is public on cure53.de.
2 separate sources: Cure53 and Mullvad VPN
Sources and caveats (2)
As expected, Cure53 was unable to discover any leaks of Personally identifiable information (PII) attached to the Mullvad’s end-users.
Counts toward the two-source rule
Conflict of interest: Commissioned and paid for by Mullvad
Mullvad VPN (mullvad.net blog)
Cure53 did not find any Personally Identifiable Information (PII) or potentially privacy-compromising information.
Counts toward the two-source rule
Researcher notes
Two groups: Cure53's report (read raw) and Mullvad's blog. The same report found six vulnerabilities from informational to high severity and raised container and defense-in-depth concerns (see T4-03). Cure53 is paid by Mullvad.