I predict a bold new operational exercise/publicity stunt for Mullvad or some other provider: every week they randomly pick a server/storage pod and send it to law enforcement.
That's how you get illegally compromised hardware. Better send the bootdisk image (which should be small given that their servers are diskless (Netboot?)