Are there any safeguards against malicious users? Say a single person signs up for 10000 active accounts?

What is Kinvey's policy towards malicious users using up my caps? Eg a user signs up for 10000 accounts and makes 1 API call on every one and thus accounting for 10000 Active Users or someone spams a bunch of push notifications, etc. 

There aren't any restrictions hard-coded, but there's nothing preventing you from writing that logic in on your own.

