I heard about this from the team a few weeks ago, and am excited to take it for a test drive with BCC sometime after my development schedule gets less nuts. Basically, instead of doing the traditional "send people off to Paypal to pay" routine, you have a form on your site which posts to a Spreedly server. Spreedly then redirects the user to you. You validate the token (similar to catching someone from an OpenID prov…
> Since the data never touches your servers, you never need to go through PCI compliance work. Is that actually true? My understanding is that since the HTML form is still served up by your site, you'll still need to go through PCI compliance (although it will be easier with no data stored), since a compromise of your server would compromise card data.
And trust me, you definitely want to fill out SAQ-A.