The major advantage of the transparent redirect and similar implementations at other providers is that the data doesn't pass through my server at all. To me this always seemed like a bit of a loophole in PCI compliance. My server that serves up the form which, if hacked, could easily be modified to send credit card details to an attacker is out of scope because it doesn't technically, "accept, transmit or receive" as worded in the PCI docs. Does receiving the data in encrypted format still afford me use of the loophole or are the PCI requirements more stringent than when using transparent redirect?