I guess it's handled by this finding in the audit:
“VPN servers accept remote logins from administrators, who technically have the ability to tap into production users' VPN traffic”
https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec...
In short, they immediately and helpfully complied with police... by letting them know they did not store any data about customers whatsoever.
https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec...
In short, they immediately and helpfully complied with police... by letting them know they did not store any data about customers whatsoever.