It appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convin…
1. ensure that the company isn't misconfiguring things and accidentally breaking their own policies
2. provide a paper trail that would directly implicate people in the event of fraud, removing plausible deniability for the folks involved.