Part of what PCI attempts to address is limiting legitimate access to servers, as well as preventative measures against compromise.
I personally think that Stripe may be within the letter of the law, but not necessarily the spirit.