Case file · VPN
Obscura VPN
A two-party relay: Obscura runs the entry, Mullvad runs the exit — so neither party can tie your identity to your browsing.
The systematized overview
The bureau vs the internet.
8.2/10 · No-KYC in practice
A genuinely novel design: your traffic enters through Obscura and exits through Mullvad (already 9.7 here), so by architecture no single party holds both who you are and what you do — and its WireGuard tunnel is end-to-end encrypted to the Mullvad exit, so Obscura never sees your traffic (not even SNI). You log in with a random account number, there is no email, and it takes Monero and Lightning. The honest asterisks keep it off the top tier: it is barely a year old, its Cure53 audit covered the client and protocol but not the no-logs infrastructure, its client is source-available (not OSI open-source) with a closed server, it is US/New-York (5-Eyes) jurisdiction, and the whole privacy model rests on Obscura and Mullvad never colluding. Strong at 8.2/10 — credit the design, mind the thin record.
3 recurring praises · 3 recurring gripes
Most praised: widely praised as a genuine architectural step (two-party relay, mullvad exit). Most cited downside: very young (feb 2025); single code-only audit; no-logs infra unaudited.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Specs & jurisdiction.
- Jurisdiction
- United States (New York)
- Intel-sharing
- 5 Eyes member
- Logging
- Does not persist/log IP or activity (by architecture; no-logs infra not yet independently audited)
- Anon. payment
- Monero, Bitcoin Lightning (card via Stripe = non-anonymous)
- Protocols
- WireGuard tunnelled over QUIC (Mullvad WireGuard exit)
- Network
- Obscura entry hop + Mullvad exit network
- Devices
- Multiple (macOS, iOS, Android)
- Kill switch
- Yes
- RAM-only
- Not stated for Obscura's own entry relay
- Open source
- Partial — source-available client (PolyForm NC); server closed
- Audited
- Yes — Cure53 2025 (client/protocol only; not no-logs infra)
- Free tier
- No
The full read
Our analysis, in plain words.
Obscura is the first genuinely new idea in consumer VPNs in a while. Instead of asking you to trust one provider with both your identity and your traffic, it splits the two across two parties: you enter through an Obscura server and exit through a Mullvad server (the same Mullvad rated 9.7 here). The entry hop sees your IP but cannot decrypt your traffic; the exit hop carries your traffic to the internet but never sees your IP or identity — and because the WireGuard tunnel is end-to-end encrypted to Mullvad, Obscura never sees your packets in plaintext, not even the SNI. You log in with a random account number, there is no email, and you can pay with Monero or Lightning. Cure53 independently audited the client and protocol in 2025 and found no major issues.
The reasons it sits at 8.2 rather than up with the leaders are all about maturity and scope, not privacy. It launched in February 2025, so it has barely a year of record and a single audit. That audit covered the app and protocol — not the no-logs infrastructure — so the "impossible for us to log" claim rests on the architecture and code, not on an independent infrastructure audit the way IVPN's or Mullvad's no-logs posture does. Its "open source" is really a source-available client under a noncommercial license with a closed server, so it does not earn full open-source credit. It is US/New-York jurisdiction (Five Eyes). And the whole model rests on Obscura and Mullvad never colluding or being compromised together — a real reduction of trust versus a single provider, but not zero-trust. Credit the design generously; keep the record honest. We rate it Reviewed, not Verified, until a no-logs infrastructure audit or a real-world test exists.
The score, broken down
How the 8.2 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
90 × 50% = 4.5 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
71 × 30% = 2.1 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
80 × 20% = 1.6 of 10
Weighted total 8.2 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
- +9Random account number — no email, name or account identity↗
- +8Two-party relay: entry (Obscura) and exit (Mullvad) are split so neither sees identity + activity together↗
- +5Does not persist or log IP addresses; WireGuard E2E-encrypted to the Mullvad exit (not even SNI visible to Obscura)↗
- +4Accepts Monero and Bitcoin Lightning (card via Stripe is non-anonymous)↗
- +-3No cash option; no independent no-logs audit of the infrastructure yet↗
Trust
- +4Independent Cure53 audit (2025) — but of the client/protocol, not the no-logs infrastructure↗
- +4Credible founder (Carl Dong, ex-Bitcoin Core) and the Mullvad exit partnership↗
- +-3Client is source-available (PolyForm Noncommercial), not OSI open-source; server component closed↗
- +-4Under ~18 months old (launched Feb 2025) — thin track record; US/New York (5 Eyes) jurisdiction↗
The fine print, read for you
The clause they bury.
“We reserve the right, at any time, in our sole discretion, with or without notice, to suspend or terminate your subscription if we reasonably believe you have violated any applicable laws.”
What it meansA sole-discretion suspension clause — but note what it is not: Obscura holds no email, no IP logs and only a random account number, so it has no identity to demand and this cannot morph into surprise-KYC. It is a service-suspension power, not an identity clause, which is why it does not block the no-KYC rating (only the absence of an unconditional "no ID ever" guarantee holds it at level 1 rather than 0).
Read the source →“Obscura operates the 1st hop, and we're proud to partner with Mullvad who operates the 2nd (exit) hop ... neither party can tie your identity to your browsing.”
What it meansThis is the strength and the load-bearing assumption in one clause. The privacy guarantee holds only as long as Obscura and Mullvad do not collude and are not both compromised or compelled at once. It is a genuine reduction of trust versus a single-provider VPN (which sees both sides), but it is not zero-trust — and it depends on the Mullvad partnership continuing, which is a re-review trigger.
Read the source →None in practice — you log in with a random account number, there is no email, name or ID at any stage, and no IP logs are kept. It is rated level 1 rather than 0 only because the terms carry a sole-discretion suspension clause and no unconditional "identity is never required" guarantee, and the exit-side privacy depends on non-collusion with Mullvad.
Policy review — point by point
-
Random-account, no email, no IP logs
Login is a random account number with no email or name, and the legal page states Obscura does not persist, log or store your IP address. ↗
-
Cure53-audited client/protocol
An independent Cure53 audit (2025) of the macOS app, network extension and protocol found no major vulnerabilities — but did not cover the no-logs infrastructure. ↗
-
Source-available, not open-source; closed server
The client is licensed under PolyForm Noncommercial (source-available, forbids commercial use, not OSI-approved) and the server component is not published. ↗
-
Sole-discretion suspension
Reserves the right to suspend or terminate "in our sole discretion" for suspected illegality — a service-suspension clause, not an identity demand (Obscura holds no identity to demand). ↗
Obscura is operated by Sovereign Engineering Inc. in New York, United States, under New York governing law — a Five-Eyes jurisdiction (published on its legal page, not merely inferred). The architectural defence is strong: with no IP logs, a random account and a Mullvad exit that never sees your identity, a lawful US order against Obscura reaches very little. But the model depends on the Obscura + Mullvad partnership continuing and the two parties not colluding, which is a standing re-review condition rather than a one-time check.
We keep watching
Incident & policy timeline.
- Feb 2025
Launched with a Mullvad exit-hop partnership
Obscura launched its two-party relay (Obscura entry + Mullvad WireGuard exit, tunnelled over QUIC), macOS-first, with a random-account login and Monero/Lightning payment. Trade press framed it as a genuine architectural step for the category.
source ↗ - Dec 2025
First independent audit (Cure53)
Cure53 audited the macOS app, network extension and protocol and found no major vulnerabilities. Importantly, the audit covered the client and protocol — not the no-logs infrastructure or servers — so the "can't log" claim rests on the architecture, not yet on an independent infra audit.
source ↗ - 2025-2026
Platform expansion (iOS, Android)
iOS shipped Aug 2025 and Android in May 2026, closing the biggest early complaint (macOS-only). Still a young service with a single code-level audit and a short operating history.
source ↗
The verdict
Where it stands.
Strengths
- Two-party relay splits identity from activity by design (Obscura entry, Mullvad exit)
- Random account number — no email, name or account identity
- Monero and Bitcoin Lightning accepted; Cure53-audited client/protocol
- WireGuard end-to-end encrypted to the Mullvad exit (Obscura never sees your traffic)
Trade-offs
- Under ~18 months old — thin track record; single code-only audit
- No-logs infrastructure not yet independently audited
- "Open source" is overstated — source-available client (PolyForm NC), closed server
- US/New York (5-Eyes) jurisdiction; privacy rests on Obscura + Mullvad not colluding
Across the internet
What reviewers report.
Consistently praised
- Widely praised as a genuine architectural step (two-party relay, Mullvad exit)
- Random-account, no-email signup; Monero and Lightning accepted
- Credible ex-Bitcoin-Core founder; Cure53-audited client/protocol
Recurring complaints
- Very young (Feb 2025); single code-only audit; no-logs infra unaudited
- "Open source" overstated (source-available client, closed server)
- US/5-Eyes jurisdiction; privacy rests on Obscura + Mullvad non-collusion
Reception has been consistently positive-to-enthusiastic, anchored by the Mullvad partnership and the founder's Bitcoin-Core background; the only recurring caveats are the two-party non-collusion assumption and the (now-resolved) macOS-only launch. No freeze, seizure or surprise-KYC incident exists — a no-custody, can't-log VPN. Synthesized from Obscura's own pages, the Cure53 audit post, and trade/community coverage.
Keep exploring
Related lists & categories.
Ask the bureau
Obscura VPN, common questions.
Is Obscura VPN no-KYC?
Yes, in practice — you log in with a random account number, there is no email, name or ID, and it keeps no IP logs. We rate it KYC level 1 (not 0) because the terms include a sole-discretion suspension clause and no unconditional "identity is never required" guarantee. Monero and Lightning are accepted.
What is the two-party relay and what does it protect?
Your traffic enters through an Obscura server and exits through a Mullvad server. The entry sees your IP but cannot decrypt your traffic; the exit sees your traffic but never your IP or identity. So no single party holds both — "neither party can tie your identity to your browsing." The trade-off is that this holds only if Obscura and Mullvad do not collude or get compromised together.
Is it audited and open source?
Partly. Cure53 independently audited the client app and protocol in 2025 (no major issues), but the audit did not cover the no-logs infrastructure. The client is source-available under a noncommercial license (not OSI open-source) and the server is closed — so we credit the audit and the design, but not a fully open, infra-audited no-logs claim. That is why it is Reviewed, not Verified.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.