Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info).
Maybe I’m wrong someone pls lmk. But I’m not convinced a test of this calibre demonstrates Mullvads claims of no logging.