As a researcher studying VPN security, I have tested a lot of VPN providers, and there are few that stand out as trustworthy. Mullvad is mentioned in this thread several times for a reason. When we publicly disclosed CVE-2019-14899, they had a patch within a day and included it in the release - all within a week. To the best of our knowledge, Mullvad was the only provider and WireGuard was the only protocol to take swift action to mitigate the vulnerability.
This comment is only about the trustworthiness of the provider and not of VPNs in general, which I'm still hesitant about. I'll provide a link for our paper exploring CVE-2019-14899 and attacks we've developed since then:
https://www.usenix.org/system/files/sec21-tolley.pdf
There's also a blog post, which is quicker to read and written for a general tech audience:
https://breakpointingbad.com/2020/05/25/Vintage-Protocol-Non...