But say you have a untrustworthy employees (it happens), as long as they have the ability to deploy code, they can compromise your site. So my question is, to what extent can a solution like Slice (or Braintree) truly alleviate the PCI burden, surely you'd still need a record of who has the ability to deploy code, audit trail for deploys etc.
Obviously you should be doing all this stuff anyway. I guess the point I'm making is that solutions like this make great claims about their ability to solve all your PCI woes, and I'm wondering about the extent to which this is actually true. PCI compliance is (normally) quite expensive to achieve, so your solution is obviously very attractive. But is it enough?
No third party could completely protect you from an untrustworthy employee, but that doesn't automatically subject you to every theoretical PCI requirement. If you have a malicious employee, you'll be liable for the damage that employee causes, yes. But using something like Stripe.js reduces even that risk, because it reduces the potential surface area of an internal attack as much as it reduces the possibility of external attacks.
Obviously you should be doing all this stuff anyway. I guess the point I'm making is that solutions like this make great claims about their ability to solve all your PCI woes, and I'm wondering about the extent to which this is actually true. PCI compliance is (normally) quite expensive to achieve, so your solution is obviously very attractive. But is it enough?